IP 安全策略关闭了常见的危险端口
上一篇 / 下一篇 2008-03-18 14:45:46 / 个人分类:网络
xQ J0RD tI0@echo off万客化工在线q-iDi njhf2o
万客化工在线? g5s*U @echo.
)I@T
`3K0echo 本脚本使用 IP 安全策略关闭了常见的危险端口,同时使用 IP 筛选万客化工在线)i,zv7hu"}%N2\
echo 只打开常用的 21 80 4000 端口,双重保护增强安全性!
usW|&p i0echo.万客化工在线x:i/df`0I$W
gpupdate >nul万客化工在线%U0Ya9mX+r L
rem For Client only
+gQF'o m3jN}}0ipseccmd -w REG -p "HFUT_SECU" -o -x >nul
x(qP:W&X
YL$j0ipseccmd -w REG -p "HFUT_SECU" -x >nul
F
Q7v3TUj2^0rem ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/80" -f *+0:80:TCP -n BLOCK -x >nul万客化工在线.N
YP
w4q,M&E3c9X5t
rem ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/1434" -f *+0:1434:UDP -n BLOCK -x >nul万客化工在线N:}AM8L-c!^T@
rem ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/137" -f *+0:137:UDP -n BLOCK -x >nul万客化工在线U
d;w7D6B{W]a,Z
rem ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/138" -f *+0:138:UDP -n BLOCK -x >nul
tNsd,\-n0rem echo 禁止网上邻居的文件传输(去掉上述两行的 REM 即可生效!)万客化工在线&d(WFfQ5W1~
rem ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/139" -f *+0:139:TCP -n BLOCK -x >nul
5a d"uX'W8]#^0rem echo 禁止NetBIOS/SMB服务和文件和打印机共享和SAMBA(去掉REM生效)
Ute7e3d
~!U0rem ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/1433" -f *+0:1434:UDP -n BLOCK -x >nul万客化工在线B%^"v[o4L:Z*@R8x$C$D
echo 禁止Microsoft的SQL服务开放的端口…………OK!万客化工在线-Y3?{0g8i2r5a
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/135" -f *+0:135:TCP -n BLOCK -x >nul
m]{.D)q8b0ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/135" -f *+0:135:UDP -n BLOCK -x >nul万客化工在线*]~
N0bYVe
echo 禁止Location Service服务和防止 Dos 攻击…………OK!万客化工在线W*p1W$D8r9Q#s
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/445" -f *+0:445:TCP -n BLOCK -x >nul万客化工在线+J;^Mn6{
^R
ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/445" -f *+0:445:UDP -n BLOCK -x >nul万客化工在线*M3T9|Wv%\?1y
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/1025" -f *+0:1025:TCP -n BLOCK -x >nul万客化工在线pCEt1W
ipseccmd -w REG -p "HFUT_SECU" -r "Block UDP/139" -f *+0:139:UDP -n BLOCK -x >nul
^q(K\:_7S0ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/1068" -f *+0:1068:TCP -n BLOCK -x >nul万客化工在线)cVY6Q|)~"d
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/5554" -f *+0:5554:TCP -n BLOCK -x >nul万客化工在线{-t?'e
WuE$e5z
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/9995" -f *+0:9995:TCP -n BLOCK -x >nul
i)R$qe
@)^6f4r K X6A/o0ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/9996" -f *+0:9996:TCP -n BLOCK -x >nul万客化工在线5YL&Evb}!sH
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/6129" -f *+0:6129:TCP -n BLOCK -x >nul万客化工在线@nQ)@J/_
ipseccmd -w REG -p "HFUT_SECU" -r "Block ICMP/255" -f *+0:255:ICMP -n BLOCK -x >nul万客化工在线?^-o[3Y
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/43958" -f *+0:43958:TCP -n BLOCK -x >nul万客化工在线y?$h\.TxhyM
echo 关闭流行危险端口…………OK!万客化工在线S;abPq
@
l-y7i
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/20034" -f *+0:20034:TCP -n BLOCK -x >nul万客化工在线[']4}8q)m+^WO[J
echo 关闭木马NetBus Pro开放的端口…………OK!万客化工在线!aN:d9]({2?%m
ipseccmd -w REG -p "HFUT_SECU" -r "Block TCP/1092" -f *+0:1092:TCP -n BLOCK -x >nul
fP&Q










