Win2003 system security countermeasures

  

Due to the good network function of the Win2000 operating system, there are some websites on the Internet that Win2000 uses as the main operating system. However, because the operating system is a multi-user operating system, hackers tend to choose Win2000 as the first attack object in order to hide themselves in the attack. So, as a Win2000 user, how can we prevent Win2000 security through reasonable methods? The author below collected and sorted out some measures to prevent Win2000 security, and now contribute them, I hope that all users can continue to supplement and improve.
1. Timely backup system
In order to prevent the system from running normally in the process of using it, we should back up the Win2000 system, preferably after completing the installation of Win2000 system. Back up the entire system, and then verify the integrity of the system based on this backup, so you can find out if the system files have been illegally modified. If the system file has been corrupted, you can also use the system backup to restore to the normal state. When backing up information, we can back up the intact system information on the CD-ROM, and then periodically compare the system with the contents of the CD to verify that the integrity of the system has been compromised. If the security level is particularly demanding, you can set the disc to be bootable and verify the work as part of the system boot process. As long as it can be booted from the CD, the system has not been destroyed.
2, set the system format to NTFS
When installing Win2000, you should choose a custom installation, select only the system components and services required by individuals or units, cancel unused network services and protocols, because the protocols and services are installed more The more ways an intruder invades, the greater the potential system security risks. When selecting the Win2000 file system, you should choose the NTFS file system to take full advantage of the security of the NTFS file system. The NTFS file system can limit the files that each user can read and write to any folder in the disk directory, and the new disk quota service in Win2000 can also control the amount of disk space allowed by each user.
3, encrypted files or folders
In order to prevent others from peeking at the files in the system, we can use the encryption tools provided by Win2000 system to protect files and folders. The specific steps are, in the "Win Explorer", right-click the file or folder you want to encrypt, and then click "Attributes". Click “Advanced” on the “General" tab, then select the "Encrypt content to ensure data security" checkbox.
4, cancel the EveryOne group of the shared directory
By default, when you add a shared directory in Win2000, the operating system will automatically add the EveryOne user group to the permission module, because the default permissions of this group are Full control, the result is that anyone can read and write to the shared directory. Therefore, after creating a new shared directory, immediately delete the EveryOne group or adjust the permissions of the group to read.

Copyright © Windows knowledge All Rights Reserved