There are so many users of Windows 2000 system that it ranks at the top of the list of attacked systems. However, this does not mean that the security of Windows 2000 is not good at all. As long as it is properly configured and managed, it is relatively safe. I have been using Windows 2000 for a long time, and I have gradually figured out some ways to maintain its security. Here are some personal opinions. Please correct me if I have any shortcomings.
Safe installation minimizes worries
The security of Windows 2000 system should be accumulated bit by bit from the time of installation, but this is often ignored. The following points need to be noted when installing Windows 2000:
1. Do not choose to install from the Internet
Although Microsoft supports online installation, it is definitely not safe. Do not connect to the network, especially the Internet, before the system is fully installed! Do not even connect all the hardware for installation. Because when Windows 2000 is installed, after entering the password of the user administrator account "Administrator", the system will create a shared account of "$ADMIN", but it will not be protected with the password just entered. This situation will continue until The computer starts again. During this period, anyone can enter the system through "$ADMIN"; at the same time, after the installation is completed, various services will automatically run immediately. At this time, the server is still full of vulnerabilities, making it very easy to intrude from the outside.
2. Select NTFS format to partition
It is best that all partitions are in NTFS format, because NTFS formatted partitions are more secure. Even if other partitions use other formats (such as FAT32), at least the partition where the system is located should be in NTFS format.
In addition, applications should not be placed in the same partition as the system to prevent attackers from exploiting application vulnerabilities (such as Microsoft's IIS vulnerabilities, everyone knows this) to cause the leakage of system files and even allow intruders to remotely obtain management member permissions.
3. Selection of system version
We generally like to use software with Chinese interfaces, but for Microsoft products, due to geographical location and market factors, there are English versions first, and then versions in other languages of various countries. In other words, the kernel language of the Windows system is English, so relatively speaking, its kernel version should have many fewer vulnerabilities than its compiled version. This is also true. The Chinese input method vulnerability of Windows 2000 has made a big fuss for everyone to see.
The safe installation mentioned above can only reduce your worries. Don’t think that you can do it once and for all. There is still a lot of work waiting for you to do. Please continue reading: