Win2000 system security countermeasures

  

Due to the good network functions of the Win2000 operating system, there are some Web servers that are used by some web servers on the Internet as the main operating system. However, because the operating system is a multi-user operating system, hackers tend to choose Win2000 as the first attack object in order to hide themselves in the attack. So, as a Win2000 user, how can we prevent Win2000 security through reasonable methods?

The author collected and sorted out some measures to prevent Win2000 security, and now contribute them, so please netizens can continue to supplement and improve.

1, timely backup system

In order to prevent the system from happening outside the process and it is difficult to operate normally, we should back up the Win2000 intact system, preferably in a Win2000 After the installation task of the system, the entire system is backed up, and the integrity of the system can be verified according to the backup, so that it can be found whether the system file has been illegally modified. If the system file has been corrupted, you can also use the system backup to restore to the normal state.

When backing up information, we can back up the intact system information on the CD-ROM. Afterwards, we can periodically compare the system with the contents of the CD to verify whether the integrity of the system is damaged. If the security level is particularly demanding, you can set the disc to be bootable and verify the work as part of the system boot process. As long as it can be booted from the CD, the system has not been destroyed.

2, set the system format to NTFS

When installing Win2000, you should choose a custom installation, select only the system components and services required by individuals or units, cancel unused network services and protocols, because The more protocols and services are installed, the more intruders invade and the potential system security risks. When selecting the Win2000 file system, you should choose the NTFS file system to take full advantage of the security of the NTFS file system. The NTFS file system can limit the files that each user can read and write to any folder in the disk directory, and the new disk quota service in Win2000 can also control the amount of disk space allowed by each user.

3, encrypted files or folders

In order to prevent others from peeking at the files in the system, we can use the encryption tools provided by Win2000 system to protect files and folders. The specific steps are, in the Win Explorer, right-click the file or folder you want to encrypt, and then click Properties. Click Advanced on the General tab and select the Encrypt content to keep your data safe check box.

4, cancel the EveryOne group of the shared directory

By default, when you add a shared directory in Win2000, the operating system will automatically add the EveryOne user group to the permission module, because The default permissions for this group are fully controlled, and as a result, anyone can read and write to the shared directory. Therefore, after creating a new shared directory, immediately delete the EveryOne group or adjust the permissions of the group to read.

5, create an emergency repair disk

If the system is accidentally damaged and can not start normally, you need a dedicated Win2000 system boot disk, for which we must remember to install the Win2000 intact Create an emergency repair disk afterwards. When creating the boot disk, we can use Win2000's tool called NTBACKUP.EXE to achieve. Run NTBACKUP.EXE, select "Create an Emergency Repair Disk" from the toolbar, insert a blank formatted floppy disk in the A: drive, click "OK", click "OK" to reach the completion information, and then Click "OK."

The repair disk can no longer be used to restore user account information, etc., and you must back up/restore Active Directory, which will be overwritten in the backup.

Copyright © Windows knowledge All Rights Reserved