14 strokes security settings to prevent invasion of hackers
1, IPC prohibit air connection
Cracker net use command can be used Establish an empty connection, and then invade, and net view, nbtstat these are based on empty connections, it is forbidden to empty connections. Open the registry and find Local_MachineSystemCurrentControlSetControlLSA-RestrictAnonymous to change this value to "1".
2, forbid At command
Cracker often gives you a Trojan and then let it run, then he needs the at command. Open the Administrative Tools - Service and disable the task scheduler service.
3, close the super terminal service
If you open, this loophole is rotten.
4, close the SSDP Discover Service service
This service is mainly used to start the UPnP device on the home network device, the service will also start 5000 port. It may cause a DDOS attack, causing the CPU to reach 100%, causing the computer to crash. It is reasonable to say that no one will do DDOS for personal machines, but this process also takes up a lot of bandwidth. It will continuously send data packets to the outside world, affecting the network transmission rate, so it is still closed.
5, close the Remote Registry service
Have a look, let the remote modify the registry? !
6. Disable NetBIOS over TCP/IP
Network Neighborhood - Properties - Local Area Connection - Properties - Internet Protocol (TCP/IP) Properties - Advanced - WINS Panel - NetBIOS Settings - Disabled NetBIOS over TCP/IP. This way Cracker can't use the nbtstat command to read your NetBIOS information and network card MAC address.
7, close the DCOM service
This is the 135 port, in addition to being used as a query service, it may also cause a direct attack, the shutdown method is: enter dcomcnfg in the run, in In the Component Services window that pops up, select the Default Properties tab and uncheck "Enable Distributed COM on this computer."
8. Change the permissions of shared files from "everyone" group to "authorized user"
"everyone" means win2000 means any user who has access to your network can get These shared materials. Do not set the user who shares the file to the "everyone" group at any time. Including print sharing, the default attribute is the "everyone" group, so don't forget to change it.
9, cancel other unnecessary services
Please decide according to your own needs, the following HTTP/FTP server requires the least service as a reference:
Event Log< Br>
License Logging Service
Windows NTLM Security Support Provider
Remote Procedure Call (RPC) Service
Windows NT Server or Windows NT Workstation
IIS Admin Service
MSDTC
World Wide Web Publishing Service
Protected Storage
10, Change TTL Value
Cracker can be based on Ping the TTL value to roughly determine your operating system, such as:
TTL=107(WINNT);
TTL=108(win2000);
TTL=127 Or 128(win9x);
TTL=240 or 241(Linux);
TTL=252(solaris);
TTL=240(Irix);
Actually you can change it yourself:
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTcpip
Parameters:DefaultTTL REG_DWORD 0-0xff (0-255 decimal, default 128) Changed to an inexplicable number such as 258, at least let those little rookies faint for a long time, it is not necessarily okay to give up the invasion.
11, Account Security
First of all, ban all accounts, except yourself, huh, huh. Then rename the Administrator. I just built an Administrator account, but it is not the kind of permissions, and then open the Notepad, a burst, copy, paste into the "password", huh, huh, break the password! Found that it is a low-level account, see you crash?
12. Cancel the last login user
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsNTCurrent VersionWinLogon:DontDisplayLastUserName Change the value to 1.
In the use of notebooks, in the face of various faults, if you do not know the reason, even the mast
Can the icon of the computer hard drive letter be modified? Although this topic seems a bit unintell
Recently, a user has encountered a problem that the size of the recycle bin cannot be modified in th
When you take a new computer out of the box, you must think it is clean and simple. So, do you belie
Seven tricks to avoid illegal invasion without hacking broilers (1)
XP browser to see the page prompts you not authorized to view the page how to solve?
The reason why the new font can not be installed in the XP system and the solution
Windows Vista system disk space solution
How to set up custom paper in Windows XP
Use the "virtual optical drive" that comes with Windows XP
How to remove WinXP boot desktop bottom right corner piracy tips
WinXP system prohibits program running through group policy
A good way to replace the motherboard with the computer does not have to reinstall the system
Reinstalling XP system encounters blue screen code, several tricks solve you no longer worry about
Detailed introduction to windowsXP system optimization method Daquan
Win10 Quickly Locating Registry Editor's Tips for an Item
Windows XP can't wake up after hibernation.
Linux switch path usage guide guide
What if the Win7 System League of Legends is always crashing?
Clean up Windows 8 system app store cache
Upgrade win10 failure prompt boot.wim file can not be installed how to do
Baidu will replace Bing into the domestic Windows 10 default search engine
How to get back the Windows7 volume speaker icon
Win7 system boot does not display the welcome interface method
Use Firefox to let you log in to multiple QQ farms at the same time