3.安裝最新的服務包:SP6a 安裝最新的熱補?。?br> q241041 Enabling NetBT to Open ip Ports Exclusively q243404 WINOBJ.EXE May Let You View Securable Objects Created/Opened by JET500.DLL q243405 Device Drivers Create their Corresponding DeviceObject with FILE_DEVICE_SECURE_OPEN Device Characteristics q244599 Fixes Required in TCSEC C2 Security Evaluation Configuration for Windows NT 4.0 Service Pack 6a. Windows NT Appears to Hang When You Log Off After Installing Service Pack 6. q188806 NTFS Alternate Data Stream Name of a File May Return Source q252463 Security Update, APRil 13, 2000 q267559 Security Update, July 17, 2000 q269862 Security Update, August 15, 2000 q271652 Security Update, September 8, 2000
4.安裝option pack: 選擇自定義安裝: 只安裝如下組件: [_] Internet Information Server [_] Internet Service Manager [_] World Wide Web Server [_] Microsoft Data access Components 1.5 [_] Data Sources [_] MDAC: ADO, OBDC, and OLE DB [_] Remote Data Service 1.5 [_] RDS Core Files [_] Microsoft Management Console [_] NT Option Pack Common Files [_] Transaction Server [_] Transaction Server Core Components 將www安裝在和操作系統不同的分區上 安裝transaction server時選擇default/local administration
5.安裝最新的MDAC (2.6 RTM as of 10/30/00)
二、配置NT
1.設置權限: 使用用戶管理器在所有分區上的根目錄上設置如下: * Administrators::FULL CONTROL * System::FULL CONTROL
2.設置屏幕保護 在控制面板中選擇顯示 選擇屏幕保護程序 選中密碼保護,點擊確定
3.設置服務: 禁止如下的服務: Alerter (disable) ClipBook Server (disable) Computer Browser (disable) DHCP Client (disable) Directory Replicator (disable) FTP publishing service (disable) License Logging Service (disable) Messenger (disable) Netlogon (disable) Network DDE (disable) Network DDE DSDM (disable) Network Monitor (disable) Plug and Play (disable after all hardware configuration) Remote Access Server (disable) Remote Procedure Call (RPC) locater (disable) Schedule (disable) Server (disable) Simple Services (disable) Spooler (disable) TCP/IP Netbios Helper (disable) Telephone Service (disable)
在必要時禁止如下服務: SNMP service (optional) SNMP trap (optional) UPS (optional
設置如下服務為自動啟動: Eventlog ( required ) NT LM Security Provider (required) RPC service (required) WWW (required) Workstation (leave service on: will be disabled later in the document) MSDTC (required) Protected Storage (required)
3.用戶權限分配: 從網絡中訪問這臺計算機:No one 將工作站添加到域:No one 備份文件和目錄:Administrators 更改系統時間:Administrators 強制從遠程系統關機:No one 加載和下載設備驅動程序:Administrators 本地登錄:Administrators 管理審核和安全日志:Administrators 恢復文件和目錄:Administrators 關閉系統:Administrators 獲得文件或對象的所屬權:Administrators 忽略遍歷檢查(高級權力):Everyone 作為服務登錄(高級權力):No one 內存中鎖定頁:No one 替換進程級記號:No one 產生安全審核:No one 創建頁面文件:Administrators 配置系統性能:No one 創建記號對象:No one 調試程序:No one 增加進度優先級:Administrators 添加配額:Administrators 配置單一進程:Administrators 修改固件環境值:Administrators 生成系統策略: Administrators 以批處理作業登錄:No one