Quick Search


Tibetan singing bowl music,sound healing, remove negative energy.

528hz solfreggio music -  Attract Wealth and Abundance, Manifest Money and Increase Luck



 
Your forum announcement here!

  Free Advertising Forums | Free Advertising Board | Post Free Ads Forum | Free Advertising Forums Directory | Best Free Advertising Methods | Advertising Forums > Post Your Free Ads Here in English for Advertising .Adult and gambling websites NOT accepted. > Post Your Business Ops Here

Post Your Business Ops Here This section is for posting your free classified ads about different work at home and home based business opportunities.

Reply
 
Thread Tools Display Modes
Old 05-27-2011, 08:29 AM   #1
bosswi0548
 
Posts: n/a
Default Office 2007 Product Key Practical knowledge of sec

At present, WIN2000 SERVER is extra favorite server operating methods, yet, for the safe configuration of Microsoft's running system, is not an effortless job. This post attempts to win2000 SERVER protection configuration was talked about.

Initial, customise their WIN2000 SERVER:

one. Model of option: Win2000 a number of languages, for us, you may pick out English or Simplified Chinese model, I strongly suggest: The language doesn't turn into a barrier, be sure to make use of the English version. You understand, Microsoft's item is known for Bug & Patch, much even more than the Chinese model of the Bug in English, while the patch will be delayed at least half of the general (ie, generally after Microsoft announced the vulnerability of your machine is also there will be two weeks in the unprotected state)

2. Custom components:

Win2000 installed by default in some general components, but it really is the default installation is extremely dangerous (Mitre Nico stated that he can enter any one installed by default server, although I hesitate to say so, but if your host is the default installation of Win2000 SERVER, I can tell you, you're dead)

you should know exactly what services you need, and only You really need to install the service, according to safety principles, at least the minimum service + permissions = maximum protection.

typical WEB servers require a minimum component choice is: only install IIS, Com Files, IIS Snap-In, WWW Server components. If you really need to install additional components, please carefully, especially: Indexing Service, FrontPage 2000 Server Extensions, Internet Service Manager (HTML) that several of the risk services.

3. Management application of choice:

choosing a good remote management software is a fairly important thing, not only safety but also of the application needs.

Win2000 the Terminal Service is based within the RDP (Remote Desktop Protocol) remote control software, he's fast, quick to operate, far more suitable for routine operation.

Having said that, Terminal Service also has its shortcomings, because it uses the virtual desktop, along with Microsoft's programming is not strict, when you install the software using Terminal Service or restart the server, etc. interacting with the real Desktop The operation, often there will be enough to create misunderstandings of phenomena, such as: re-using the Terminal Service server from Microsoft's Certification (Compaq, IBM, etc.) might possibly be shut down.

So, for safety reasons, I recommend you go with a remote control software as an aid, and Terminal Service complementarity, as PcAnyWhere is a good choice.

Second, properly installed WIN2000 SERVER:

one. The distribution of partition and logical drive, there are some friends in order to save, just the hard drive into a logical drive, all the software installed in the C drive, this is extremely good, it really is recommended to establish at least two partitions, one program partition, an application partition, this is because there is often a leak of Microsoft's IIS source / overflow vulnerability, if the system and IIS within the same drive, the file will cause the program to leak or even a remote intruder access to ADMIN.

recommended protection configuration is to create three logical drives, the 1st is greater than 2G, and important to install the program log file, the second put IIS, the third one FTP, IIS, or FTP either way out of the security holes will not directly affect the system directory and program files.

to know, IIS and FTP is the external services are relatively easy problems. The separation of the IIS and FTP upload the main program is to prevent intruders to run from IIS. (This could lead to application developers and editors of distress, who cares, anyway you will be an administrator)

2. The order of installation options:

Do not think: What is the order important? If installed, how to load you can actually.

wrong! win2000 installed in a certain order of a few to note:

First of all, when the access network: Win2000 there is a flaw in the installation, you enter the Administrator password, the system's built ADMIN $ shared, but did not use the password you just to protect it, this situation until you start again after this period, anyone can enter through the ADMIN $ on your machine; the same time, as long as the installation is complete, the types of service will run automatically, and when the server is covered with loopholes, extremely straightforward to enter, therefore, fully installed and configured win2000 SERVER, be sure not to host access network.

Second, the patch installation: the installation of the patch should be installed after all the applications, because patches often have to replace / modify certain program files, if you install the patch before installing the application may perhaps cause the patch can not be play the desired effect, such as: IIS's HotFix requires that each change the configuration of IIS to be installed on

Third, protection configuration WIN2000 SERVER:

even if installed properly WIN2000 SERVER, there are nonetheless lots of loopholes in the system, but also the need for further detailed configuration.

1. Port:

port is connected for the computer and the logic of the external network interface, is the 1st barrier the computer, the port is configured properly or not directly affect the security of the host, in general, only open the ports you will need to make use of safer approach is to configure the network card properties -TCP/IP- Advanced - Options -TCP/IP screening enabled TCP / IP filtering, port filtering, but for win2000, there is a bad feature: only the provisions of What ports to open, can not restrict which ports closed, so that a large number of ports that require users to open a lot more painful.

2. IIS:

IIS is Microsoft's one of the largest component in the vulnerability, an average of two to three months out of a hole should, and Microsoft's IIS is installed by default and can not compliment, so the configuration of IIS is our focus, it really is now together with me:

First, the C disk that what Inetpub directory completely deleted, in the D drive to build a Inetpub (do not worry if you may use the default directory name, a name change, but they have to remember that) in the IIS Manager home directory will point to D: Inetpub;

secondly, that what the default IIS installation scripts and other virtual directory Yigai delete (source of evil ah, forget a href =

3: Application Configuration:

in the IIS Manager to delete any unwanted outside the map must be, must refer for the ASP, ASA, and you really need to use other types of files , for example, you use stml, etc. (use the server side include), is in fact 90% of the host with the above two maps enough, the rest of the map almost every story has a sad: htw, htr, idq, ida ... ... want to know these stories? to check it before the vulnerability list.

what? can not find where to delete?

in the IIS Manager, right-click the host -> Properties -> WWW Services Edit -> Home Directory Configuration -> application mapping, and then it started to delete one by one (which does not select all, hehe). Then, in just the bookmarks window application debugging error message within the script to send text ( ASP error unless you want to know your system when the user / network / database structure) error text writing? whatever you like, own selection. Click OK to exit do not forget to set the virtual site inherit your property.

order to deal with the growing number of cgi vulnerability scanners, there is a little trick to refer to the IIS will HTTP404 Object Not Found error page through the URL to redirect to a custom HTM files, can current, most CGI vulnerability scanner failure. It is actually truly quite easy, most of the time of writing CGI scanner in order to facilitate, through the HTTP code to view the back page to determine whether vulnerabilities exist, for example, are generally well-known vulnerabilities by taking IDQ 1. idq to test, if the return HTTP200, to think that there is this vulnerability, whereas if the return HTTP404 to think not, if you will HTTP404 error message through the URL redirected to HTTP404.htm files, then scan all vulnerabilities,Office 2007 Product Key, whether it exists or not will be returned HTTP200, 90% of the CGI vulnerability scanner that what you have, the result will conceal your true vulnerability, so that an intruder at a loss no place to start (instead of martial arts often stated that loopholes in the body perfect, can we say is this state?) But from a personal point of view, I think that such a solid task protection settings than the additional important tips.

Finally, to be safe, you possibly can use the backup feature of IIS, the setting will be just All backup set down, so that you may always restore IIS protection configuration. Also, if that you are afraid of the load is too high causes the server to IIS crash at full capacity, can also open the CPU limitations in performance, for example, the maximum CPU utilization IIS limit 70%.

4. Account Protection:

Win2000 account protection is another focus, 1st of all, Win2000 the default installation allows any user to get the program through the air all the user accounts / share list, this originally for your convenience of LAN users to share files, but a remote user can also get your list of users and crack user password to make use of violence law. various of my friends know that you may change the registry Local_Machine Program CurrentControlSet Control LSA-RestrictAnonymous = 1 to prohibit 139 null,

fact, the local safety policy win2000 (if that is the domain server, domain server protection and domain protection policy) had this choice RestrictAnonymous (additional restrictions for anonymous connections) This choice has three values:

0: None. Rely on default permissions (no, depending within the default permissions)

one: Do not allow enumeration of SAM accounts and shares (not enumeration of SAM accounts and shares allowed)

2: No access without explicit anonymous permissions (without explicit anonymous permissions allow access)

0 This value is the default, what restrictions No, the remote user can see all the accounts on your machine, group information, shared directories, network transmission NetServerTransportEnum, etc., within the server for this setup is really dangerous.

1 This value is only allowed to users of non-NULL SAM account information access and share information.

2 in this value is only supported in win2000, to note that if you use this value if your share is estimated on all finished, so I suggest that you set to 1 or better. Well, now there is no way an intruder to get a list of our customers, our account safe ... ...

Wait, at least one account password can be run This is the system built-in administrator, how do? I change change change, in Computer Management -> right click administrator user account and then change its name changed to whatever you what, as long as I remember on the line.

not No, I have changed the user name, and how people still run my administrator's password? Fortunately, my password is long enough, but this just isn't the answer you? ah, it must be in local or Terminal Service login screen to see , properly, let's put HKEY_LOCAL_MACHINE SOFTWARE Microsoft WindowsNT CurrentVersion winlogon key in the Don't Display Last User Name string data into a one, so the program doesn't automatically display the last logon user name.

the server registry HKEY_LOCAL_ MACHINE SOFTWARE Microsoft WindowsNT CurrentVersion Winlogon key in the Don't Display Last User Name string data revised to one to hide the last login console user name.

5. Security Log:

I encountered such a situation, a host intrusion by others, the program administrator asked me to track down the murderer, I logged into a look: safety log is empty, down, remember: Win2000 the default installation isn't open any security audit! then invite you towards the local protection policy -> audit policy, open the appropriate review, the audit recommended that:

account management success or failure

logon events success and failure

object access failure

success or failure

policy changes failed

privilege to make use of the program event success or failure

directory service access failures

account logon events audit project success and failure

small drawback is that there is no record in case you want to see it at all Mozhe; too countless items will not only review program resources and cause you do not have time to see, so that the significance of losing the audit.

is associated with:

strategy in the account -> Password policy settings:

password complexity requirements enabled

Minimum password length 6

Enforce password history 5

maximum age of 30 days

In the Account Policy -> Account Lockout Policy settings:

account lockout 3 times the error log



locked for 20 minutes 20 minutes
lock count reset
Similarly, Terminal Service safety log just isn't open by default, and we can Terminal Service Configration (remote service configuration) - permissions - Advanced to configure protection auditing, in general, as long as the record of logon, logoff events on it.

6. directory and file permissions:

to control the user's permissions within the server, but also to prevent a doable invasion and subsequent overflow, we must be pretty careful to set the directory and file access permissions, NT access rights are divided into: read, publish, read and perform, modify, list directories, full control. In the default case, the majority of the folder for all users (Everyone in this group) is completely open The (Full Control), you need to apply the required permissions to reset.

making access control, keep in mind the following principles:

1> limit is cumulative: If a user belongs to two groups, he had allowed these two groups of all rights;

2> permission denied permission to allow higher than (denial strategy will be executed) if a Users belong to one is denied access to a resource group, no matter the permissions of other how a great deal authority to give him open, he must not access the resources. so please be extremely careful to make use of reject, any refusal may well have resulted in improper The system can not function properly;

3> file permissions for that folder permissions than the high (need to explain this, right?)

4> use user groups for access control is a mature system administrator one must have good habits;

5> only permissions for the users really need, the principle of least privilege is an important guarantee for the safety;

7: Prevention of DoS:

In the registry HKLM System CurrentControlSet Services Tcpip Parameters, change the following value can help protect you against a certain intensity of DoS attacks

SynAttackProtect REG_DWORD 2

EnablePMTUDiscovery REG_DWORD 0

NoNameReleaseOnDemand REG_DWORD 1

EnableDeadGWDetect REG_DWORD 0

KeepAliveTime REG_DWORD 300,000

PerformRouterDiscovery REG_DWORD 0

EnableICMPRedirects REG_DWORD 0

ICMP attacks : ICMP storm attack and fragment attack is also quite daunting NT host attack methods, in fact, rather straight forward methods to deal with, win2000 comes with a Routing & Remote Access tool that begun to take shape router (Microsoft really, what should do? I heard recently, to do the firewall) in this tool, we can easily define input and output packet filters, for example, setting the input code 255 ICMP dropped to that drop all ICMP packets alien.

Fourth, some of the things to note:

In fact, safety and application is contradictory in lots of cases, so you need to find a balance in which, after all, the server is for users to use and not to do OPEN HACK , if the system protection policy prevents the application of the principle that the security is not a good principle. Network security is a systematic project, which spans not only space, there is nevertheless time span. a good deal of friends (including some program administrators ) considers an the security configuration of the host is secure, in fact, of which there is a misunderstanding: we can only say that a host in certain cases some time is safe, with the network structure changes, new vulnerabilities are discovered administrator / user operation, the host of the security situation is changing at any time, only to protection awareness and safety program throughout the entire process to be truly safe.
  Reply With Quote

Sponsored Links
Old 05-27-2011, 08:39 AM   #2
jheletri
 
Posts: n/a
Default Comprare Zovirax a basso costo

Zovirax





Uso commune
Zovirax e un farmaco antivirale che ha usato per trattare le infezioni da herpes del labbro pelle, e genitali, herpes zoster e la varicella. Zovirax arresta la replicazione virale, ma non funziona nel trattamento di infezioni da virus certi, come il comune raffreddore.
...
Dosaggio e direzioni
Portalo via orale con o senza cibo / latte. dose comunemente usata e di 200 mg ogni 4 ore, cinque volte al giorno per dieci giorni. Se l'herpes e ricorrente, la dose raccomandata per gli adulti e di 400 mg due volte al giorno per 1 anno. Lavaggio delle mani vi aiutera a evitare la trasmissione dell'infezione ad altri.
Nota: questa istruzione presentato qui solo per la revisione. E 'molto necessario consultare il medico prima di utilizzare. Essa vi aiutera ad avere migliori risultati.



































Zovirax Allattamento
Zovirax Senza Ricetta
Zovirax Crema Herpes Genitale
Zovirax online
Zovirax Equivalente
Zovirax Cp
Zovirax In Allattamento
Zovirax Opinione
Zovirax Labiale Crema
Zovirax Labiale Funziona

Buy Apcalis SX Oral Jelly not prescription
Minocin
Comprar Apcalis SX online sin receta medica
Sublingual Viagra a basso costo senza ricetta
Buy CheapED Advanced Pack online not prescription
Ampicillin sin receta medica
Silagra online a basso costo senza ricetta
  Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off


All times are GMT. The time now is 12:41 AM.

 

Powered by vBulletin Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Free Advertising Forums | Free Advertising Message Boards | Post Free Ads Forum