It is forbidden to execute exe, bat, com files in the directory, and cancel the website directory execution permission.

  
Use the group policy to restrict the permission of the executable exe of the website directory, which can improve the security of the server!

Use gpedit.msc (Group Policy) to prohibit certain directories from executing certain files.

Operation steps:

gpedit.msc---computer configuration---windows settings---security settings ↓---software restriction policy (if not next, right click to create a strategy) --- other rules --- Right

key to create a path rule

Figure:

In this way d: \\ wwwroot \\ directory can not be executed Any exe.bat.com file is gone.

Even if the system can't be executed,

c:\\windows\\temp\\ is a temporary folder. A lot of cmd or overflow tools are passed to this directory, which limits its execution permissions.

You can add a rule to him. Let c:\\windows\\temp\\ have no execute permission.

Note: Untested, maybe invalid for aspx webshell, but can prevent asp call exe, php has not been tested yet.

Copyright © Windows knowledge All Rights Reserved