Windows 2000 Server system account security settings tips

  

Windows 2000 server contains a lot of security features and options, if you configure them properly, then Windows 2000 server will be a very secure operating system. First of all, we should place the Windows 2000 server server in an isolated room with a monitor installed, and the monitor should keep a record of more than 15 days. In addition, the chassis, keyboard, and computer desk drawers should be locked to ensure that no one can use the computer even if they enter the room, and the keys should be placed in another safe place. We can stop the Guest account, create 2 administrator accounts, rename the system administrator account, set the screen saver password, etc. to ensure security, you can also use win2000 security configuration tool to configure policies, close unnecessary services, close unnecessary Ports, prohibiting the establishment of empty connections and installing Microsoft's latest patches to enhance Windows 2000 Server security. To attack the Windows 2000 system, you first need to know the account number and password. Therefore, to ensure the security of the Windows 2000 system, it is the key to ensure the security of the account and password. However, the password can be cracked by the exhaustive method, etc., so the security of the Windows 2000 account is safe. Very important.

The following methods can effectively protect the security of the account in the Windows 2000 system:

Method 1: Prohibit enumeration of accounts

Since the default installation of Windows 2000 allows any user to pass Empty users get all the accounts and shared lists of the system. This is to facilitate LAN users to share resources and files. However, any remote user can get the account list through the same method. After using the illegal method to crack the account password, it is for us. The computer attacks, so the following methods must be used to prohibit this behavior.

1. Disable the empty user connection by modifying the registry. The steps are as follows:

Click "Start" -> "Run" to open the "Run" dialog box; enter "Regedit" and Click OK to open the Registry Editor; enter [HKEY_LOCAL_MACHINESSYSTEMCurentControlSetControlLsa] layer by layer in the Registry Editor;

Set the value of RestrictAnonymous to 1, which can disable empty user connections, as shown in Figure 1.

Figure 1

2, modify the local security policy, the operation steps are as follows:

Enter the "Control Panel" of Windows 2000; click "Administrative Tools", click " Local Security Policy", enter the "Local Security Settings" dialog box, as shown in Figure 2.

Figure 2

Copyright © Windows knowledge All Rights Reserved