After your computer has installed nt4/win2000, it is not a direct use for Internet servers. Although Microsoft's patch has been a lot of bugs, there are still some loopholes. Now let's talk briefly about how to use IIS to build a server with high security performance.
First, based on the security mechanism of Windows NT
1) NT hit SP6 patch, 2K hit SP2 patch. Convert the disk's file system to NTFS (the partition of the installation system can be converted when the system is installed, or it can be converted by tools after the system is installed). At the same time, the permission to write and modify Everyone in the usage permission is removed, and the key directory: such as Winnt\\Repair read permission is also removed.
2) Modification of sharing permissions. Under NT, go to Start Menu --> Programs --> Administrative Tools --> System Policy Editor, and then open the registry in the File menu of the system policy to modify the Windows NT network to remove it. Under 2K, you can write a net share c$ /delete bat file, put it into the machine's startup task.
3) Rename the system administrator account. At the same time, change the password of the system administrator to strong encryption: the password length is more than 10 digits, and the password should include numbers, letters, and! Wait for various characters.
4) Abolish NetBIOS over TCP/IP. The binding between NetBIOS and TCP/IP is aborted by the binding option of the network attribute.
5) Install other services. You should try not to install other services of the database on the same server. If installed, the main point is that the database password cannot be the same as the login password of the system.
Second, set the security mechanism of IIS
1) IIS5 security issues have been greatly improved on the basis of the previous.
Solve IIS4 and previous versions by D.O.S attacks will stop the service. Run Regedit32.exe at: HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\w3svc\\parameters Add a value: Value Name: MaxClientRequestBuffer Data Type: REG_DWORD Set to decimal The specific value is set to the maximum length of the URL that IIS is allowed to accept. The CNNS setting is 256.
2) Delete the HTR script map.
3) Set the /_vti_bin directory under the IIS web server to disable remote access.
4) In the IIS management console, point to the web site, properties, select the home directory, configure (start point), application mapping, delete the mapping between htw and webhits.dll.
5) If the installed system is 2K, install Q256888_W2K_SP1_x86_en.EXE.
6) Delete: c:\\Program Files\\Common Files\\System\\Msadc\\msadcs.dll.
7) If you do not need to use Index Server, disable or uninstall the service. If you are using Index Server, disable the "Index this resource" option for directories containing sensitive information.
8) Solve the unicode vulnerability: 2K install 2kunicode.exe, NT install ntunicode86.exe.
After the above settings, I still can't say that it is completely safe, you can't go back to sleep! But you can relax!
Microsoft's products are good Use, but its vulnerability is the most vulnerable one compared with the same kind. As a network management, we must pay attention to the emergence of new vulnerabilities at all times, and take corresponding measures in time to be prepared!
IIS (Internet Information Server) is a Web service component provided by Windows.
. The VPS in foreign countries uses Xen-Shell for control. It is quite convenient, and the tutorial
What is the most regrettable thing for intranet users? Of course, it
Mount data disk 1, start the lower server manager in the lower left corner of the taskbar, select st
Finding application pool pid through iisapp command to solve IIS CPU usage is too high.
Does the server operating system choose Windows or Linux?
Top Ten Issues to Protect Windows Servers
Perfectly solve Nginx 504 Gateway time-out
Configure Nginx subdomain generic resolution binding to a separate directory
Four considerations for server security management
What is a time protector and what does the time protector do?
360 browser splash screen solution
Configuring a NAT server in Win 2003
Use the QuickTime video player in the MAC to play various media videos
How to turn off windows security alerts
Customize the Win7 power button to shut down or hibernate?
Windows7 system optimization speed speed book (2)
WinXP uses the Picture and Fax Viewer feature to print multiple images on a single sheet of paper