Siddee loo Adgeeyaa Amniga Windows 2000 - Windows Xp.

Welcome To My Homepage Muxaadaro SPYWARE IYO ADWARE Web Server 1 Web Server 2 Msconfig  Amniga Windows 2000 - WinXp 1 Amniga Windows 2000 - WinXp 2 Ninyahow

• Habka aad Service u joojinayso

Service walba oo aad rabto inaad disabale ka dhigto ku sameey double click ama inta aad mouse-ka saarto Service-ka dushiisa riix mouse-ka dhangiisa midig kadibna ka dooro "Properties", kadib shaashada kuusoo baxda halkeedda dhexe ee ku qoran Startup type ka dhig Disabled, kadib riix Apply, kadibna Ok, eeg sawirka hoose.

• Jooji barnaamijta aadan rabin.

Si aad isaga joojiso barnaamijta aadan rabin ee isla shidaya windows-ka riix Start, kadib Run, kadib ku qor msconfig, kadib riix Ok, intaas kadib shaashada kuu soo baxda ka dooro Startup tab, kadib ka saar calaamda saxan barnaamij walba oo aadan rabin innuu windows-ka la shidmo, horey baan ugu hadalnay msconfig waxaadna ka akhrisan kartaa halkan: msconfig.

• Secure settings

Si aad wax ugu badasho Secure settings, riix Control panel, kadibna ka dooro Performance and maintenance, kadib ka door Administrative tools, kadib ka dooro Local security policy.

• Hab kale oo ka sahlan

Waxaad Local security policy u furi kartaa adiga oo riixa, Start, kadib doorta Run , kadib ku qora secpol.msc, kadib riix Ok, marka laguu furo shaashada Local security policy ka dhex dooro Account policies, kadib dooro Password policy, kadibna ka dhig sidda hoos ku qoran:

Enforce password history - 0 passwords remembered
Maximum password age - 360 days
Minimum password age - 0 days
Minimum password lenght - 13 characters
Password must meet complexity requirements - Enabled
Store passwords using reversible encryption for all users in the domain - Disable

• Habka aad u furayso:

Habka aad mid walba oo aad rabto inaad wax ka badashaba u furayso waa adiga oo magaca meesha ku qoran double click ku sameeya, sidda adiga oo laba mar gujiya Maximum password age, kadibna shaashada yar ee kuu soo baxda halka ay ku qoran tahay tirada waa halka ka hooseesa meesha ay ku qoran tahay passwords expire in
ka dhig 360 sidda kaaga muuqadda sawirka hoose, kadibna mid walba sidaas iyo si la mid ah u badal.

Haddii aad kombuyuutarkaaga u isticmaasho password ka yar 13 tiro iyo xarfo isugu jirta,
Xasuusnow inaad ku badasho halka ay ku qoran tahay 13 characters, inta tiro iyo xarfo uu ka gooban yahay password-kaaga, waxaan 13 characters u qaadanay amni ahaan, balse haddii uu password-ka aad isticmaasho ka kooban yahay 8, 9 ama 10 nambar oo tiro iyo xarfo isku jira ah ku badal halka ay ku qoran tahay Minimum password lenght - 8 ama 10 characters.

• Account lockout policy

Mar kale shaashada Local security policy dhankeeda bidix ka dooro Account policies, kadibna ka dooro Account lockout policy kadibna ka dhig sidda hoos ku qoran:

Account lockout threshold - 3 invalid logon attempts.
Account lockout duration - 15 minutes
Reset account lockout counter after - 15 minutes

Xasuusnow halka ay ku qoran tahay Account lockout threshold - ka dibna aan ka dhignay 3 invalid logon attempts, in ay la micna tahay in qofkii raba innuu kombuyuutarka isticmaalo uu haysto sedax fursad keliya oo uu khaldi karo password-ka, marka uu log on kombuyuutarka ku sameenayo, haddii uu khaldo sedax jeer Password-ka account-ga waxaa laga dhigayaa disable, qofkana ma isticmaali karo account-ga illaa uu Administrators-ku uu mar kale account-ga ka dhigo active, micnaha ka saaro calaamada saxan ee account-ga laga gelinayo qeybta ah Account is disabled, markii qofkii lahaa account-ga uu gaaro inta jeer ee loogu talla galay innuu ruuxu khaldi karo password-ka.

Haddii qofku arintaas qabsato waa innuu la xiriiro Administrators-ka si ay mar kale account-ga ugu fasaxaan, laakiinse kombuyuutarkaaga adiga ayaa ka ah isticmaale iyo Administrator-ba, haddii aadan lahayn account kale oo Administrators ah, isla markaasna aad khalado intii loogu talla galay in ruuxu uu khaldi karo password-kiisa, account-ga aad isticmaasho waa ay kaa xirmaysaa, xattaa haddii aad soo xasuusato password-kii aad u isticmaali jirtay oo si sax ah aad ugu qorto laguuma fasaxayo inaad gasho account-gaas, illaa qof Administrators-ka ka mid ah intuu kombuyuutarka kusoo gallo Administrators ahaan kadibna mar kale kuusoo fasaxo account-ga.

Marka waxaa naga tallo ah in aad ka fiirsato qeybtan, haddii aadan xasuusan karin password-kaaga oo ay dhacdo in marar badan oo aad rabto inaad kombuyuutarka soo gasho aad khalado password-kaaga wax ka badan 3 jeer, "Haga dhigin inta qofka loo siinayo fursad uu password-ka khaldi karo 3 jeer", balse ka dhig "0/Eber" siddan oo kale: Account lockout threshold - 0 invalid logon attempts.

• Audit policy

Mar kale shaashada Local security policy dhankeeda bidix ka dooro Local Policies, kadibna kasii dooro Audit policy, kadib ka dhig sidda hoos ku qoran:

Audit account logon events - Success, failure
Audit account management - Success, failure
Audit logon events - Success, failure
Audit Object access - Success, failure
Audit policy change - Success, failure
Audit system events - Success, failure
Haddii ay jiraan waxyaabo kale oo meeshan ku qoran oo intaan ka badan sidooda u dhaaf.

• User rights assignment

Mar kale shaashada Local security policy dhankeeda bidix ka dooro Local Policies, kadibna kasii dooro User rights assignment, kadib ka dhig sidda tusaha 1.2 ee hoos ku qoran:

Tusaha 1.2

Access this computer from the network-
Act as part of the operating system-
Add workstations to domain-
Adjust memory quotas for a process- Local Service, Network Service, Administrators
Allow logon through Terminal Services-
Back up files and directories- Administrators
Bypass traverse checking- Authenticated Users, Administrators
Change the system time- Administrators
Create a pagefile- Administrators
Create a token object-
Create permanent shared objects-
Debug programs- Administrators
Deny access to this computer from the network- Everyone
Deny logon as a batch job-
Deny logon as a service-
Deny logon locally-
Deny logon through Terminal Services- Everyone
Enable computer and user accounts to be trusted for delegation-
Force shutdown from a remote system-
Generate security audits- Local Service, Network Service
Increase scheduling priority- Administrators
Load and unload device drivers- Administrators
Lock pages in memory- Local Service,Authenticated Users,Administrators
Log on as a batch job-
Log on as a service-
Log on locally- Authenticated Users, Administrators
Manage auditing and security log- Administrators
Modify firmware environment values- Administrators
Perform volume maintenance tasks- Administrators
Profile single process-
Profile system performance-
Remove computer from docking station- Authenticated Users,Administrators
Replace a process level token- Local Service
Restore files and directories- Administrators
Shut down the system- Authenticated Users, Administrators
Synchronize directory service data-
Take ownership of files or other objects- Administrators

Dhamaan meelaha maran ee aan ku qornay calaamadan "-" keliya, waxaan ulla jeednaa in aad adigu leedahay go'aankoodda, haddii ay wax kugu qoran yihiina sidda ay kuu yihiin ku deyso, haddii ay maran yihiina marnaanshahoodda u deyso, adigaa go'aankoodda iska leh, keliya waxaan kuusoo qornay intaan u aragnay in ay muhiim tahay in wax lagu magacaabo.

Waxaa kale oo dhici karta in waxyaabaha qaar ee aan kugu soo qornay tusaha 1.2 aad ka weyso kombuyuutarkaaga, marka inta aad ka hesho keliya ka dhig sidaas aan kugu soo qornay tusaha 1.2.

• Security options

Mar kale shaashada Local security policy dhankeeda bidix ka dooro Local Policies, kadibna kasii dooro Security options, kadib ka dhig sidda tusaha 1.3 ee hoos ku qoran.

Xasuusnow warbixinta ka muuqada tusaha 1.3 dhankiisa bidix ee aan kugu qornay Sharxaad, kadibna aan ku hoos qornay: Acounts, Audit, Network access i.w.m, waa sharxaad dheeraad ah, balse magaca aad ka raadinayso Security options-ka dhexdiisa waa magaca dhexe ee ku hoos qoran Policy sidda: Administrator account status, Rename administrator account i.w.m, kadib waxaad ka dhigaysaa Setting-ka waxa ku hoos qoran Local Setting sidda: Enable, Disable i.w.m, haddana eeg tusaha 1.3.

Tusaha 1.3

SharxaadPolicyLocal Setting
AccountsAdministrator account status- Enabled
AccountsGuest account status- Disabled
AccountsLimit local account use of blank passwords to console logon only- Enabled
AccountsRename administrator account- Hoos ka akhriso
AccountsRename guest account- Guest
AuditAudit the access of global system objects- Disabled
AuditAudit the use of Backup and Restore privilege- Disabled
AuditShut down system immediately if unable to log security audits- Disabled
DevicesAllow unlock without having to log on- Disabled
DevicesAllowed to format and eject removable media- Administrators
DevicesPrevent users from installing printer drivers- Enabled
DevicesRestrict CD-ROM access to locally logged-on user only- Enabled
DevicesRestrict floppy access to locally logged-on user only- Enabled
DevicesUnsigned driver installation behavior- DO not allow installation
Domain controllerAllow server operators to schedule tasks- Disabled
Domain controllerLDAP server signing requirements- Not defined
Domain controllerRefuse machine account password changes- Enabled
Domain memberDigitally encrypt or sign secure channel data (always)- Enabled
Domain memberADigitally encrypt secure channel data (when possible)- Enabled
Domain memberDigitally sign secure channel data (when possible)- Enabled
Domain memberDisable machine account password changes- Enabled
Domain memberMaximum machine account password age- 1
Domain memberRequire strong (Windows 2000 or later) session key- Enabled
Interactive logonDo not display last user name- Hoos ka akhriso
Interactive logonDisable CTRL+ALT+DEL requirement forlogon - Disabled
Interactive logonMessage text for users attempting to log on-
Interactive logonMessage title for users attempting to log on-
Interactive logonNumber of previous logons to cache- 0 logons
Interactive logonPrompt user to change password before expiration- 14 days
Interactive logonRequire Domain Controller authentication to unlock workstation- Enabled
Interactive logonSmart card removal behavior- Lock Workstation
MS network clientDigitally sign communications- Enabled
MS network clientSend unencrypted password to third-party SMB servers- Disabled
MS network clientAmount of idle time required before suspending session- 1
MS network clientDigitally sign communications (always)- Enabled
MS network clientDigitally sign communications (if client agrees)- Enabled
MS network clientDisconnect clients when logon hours expire- Enabled
Network accessAllow anonymous SID/Name translation- Disabled
Network accessDo not allow anonymous enumeration of SAM accounts- Enabled
AccountsDo not allow anonymous enumeration of SAM accounts and shares- Enabled
Network accessDo not allow storage of credentials or .NET Passports for network authentication- Enabled
Network accessLet Everyone permissions apply to anonymous users- Disabled
Network accessNamed Pipes that can be accessed anonymously-
Network accessRemotely accessible registry paths-
Network accessShares that can be accessed anonymously-
Network accessSharing and security model for local accounts- Classic local users authenticate as themselves
Network securityDo not store LAN Manager hash value on next password change- Enabled
Network securityForce logoff when logon hours expire- Disabled
Network securityLAN Manager authentication level- Send NTLMv2 response only\refuse LM & NTLM
Network securityLDAP client signing requirements- Require signing
Recovery consoleAllow automatic administrative logon- Disabled
Recovery consoleAllow floppy copy and access to all drives and all folders- Disabled
ShutdownAllow system to be shut down without having to log on- Hoos ka akhriso
ShutdownClear virtual memory pagefile- Enabled
System cryptographyUse FIPS compliant algorithms for encryption, hashing, and signing- Enabled
System objectsDefault owner for objects created by members of the Administrators group- Object creator
System objectsRequire case insensitivity for non-Windows subsystems- Enabled
System objectsStrengthen default permissions of internal system objects (e.g. Symbolic Links)- Enabled


Dhamaan waxyaabaha ku jira qeybta Security option, ka dhig sidda tusaha 1.3 kaaga muuuqada, waxaa kale oo aad ogaadaa in ay dhici karto in aysan ugu qornayn kombuyuutarkaaga magacyada waxyaabaha ku jira Security options-ka sidda aan tusaha 1.3 isugu xijinay, sidaas darteed magaca ku qoran tusaha 1.3 ka raadi dhamaan waxyaabaha kuugu jira qeybta Security options-ka ee kombuyuutarkaaga, haddii aadan haysan qaar ka mid ah waxayaabaha aan kugu soo qornay tusaha 1.3, keliya inta aad haysato ee aad ku aragto qeybta Security options-ka ka-dhigo sidda aan kugu soo qornay tusaha 1.3.

• Rename administrator account

Waxaad qeybtan Rename administrator account ka badali kartaa magaca account-ga administrator, kadibna waxaad ku badalan kartaa magacii adiga kuu sahlan ee aad rabto, tusaale: haddii aadan adiga horey u badalin, mar walba oo aad rabto inaad soo gasho qeybta administrator-ka waxaad shaashada log on ku qortaa magacan: administrator iyo password-kiisa, hadaba haddii aad rabto in aad ku badalado magacan administrator ee aad mar walba u isticmaasho user name ahaan magac kale oo kaaga sahlan sidda, aflax, maxamed, zakariye i.w.m, waxaad furtaa oo micanah laba jeer gujisaa qeybta Rename administrator account, kadibna shaashada kuusoo baxda halkeedda dhexe ee ka hooseesa Local Policy Settings kusoo qor magcii aad rabto, eeg sawirka hoose.

Waxa aad halka sawirka sare kaaga muuqadda kusoo qortaa magacii aad rabto in lagugu badallo qeybta administrator account-ga, intaas kadib riix Ok, kadib magaca aad meesha kusoo qortay baad mustaqbalka u isticmaali doontaa user name ahaan mar walba oo aad rabto in aad soo gasho qeybta administrator-ka.

• Do not display last user name

Marwalba oo aad kombuyuutarkaaga dib usoo shido iyo mar walboo inta aad damiso dib usoo daarto waxaad shaashada yar ee aad "log on" ka sameyso lagaa tusayaa magacii ugu danbeeyey ee lagu soo galay kombuyuutarkaaga, waa haddii aad kombuyuutarkaaga u isticmaali jirtay username iyo password, isla markaasna uu ahaa Safer logon enable, sidda aan kor kugu soo sharaxnay "micnaha aad ka dhigtay qeybta Use welcome screen disable, hadaba mar walba oo lagu tuso shaashada aad kombuyuutarka kasoo geli lahayd, waxaa isla markaasna lagu tusayaa username-kii ugu danbeeyey ee lagu soo galay kombuyuutarka, marka taas waxay keeni kartaa in qof walba oo kaaga danbeeya kombuyuutarkaaga argo username-kaaga, kadibna isku dayi karo innuu qiyaaso password-kaaga si uu u galo qeybtaada, marka waxaa dhici karta innuu ku guulaysto oo markaas sidaas kusoo galo qeybtaada, waxaa kale oo dhici karto in uu guulaysan waayo password-kaaga qiyaasidiisa, kadibna ay dhici karto inta uu sedax jeer isku dayo sedaxda jeerba wadda khaldo, kadibna haddii aad ka dhigatay in qofka loo siiyo fursad uu ku saxo password-kiisa sedax jeer lagaa xiro koontada micnaha "disable lagu sameeyo qeybtaada, sidda aan kor kugu soo sharaxnay.

Marka haddii aad doonayso in mar labaadka uu kombuyuutarkaagu dib usoo shidmayo la qariyo user name-kii ugu danbeeyey ee loo isticmaalay kombuyuutarka, ka dhigo enable Do not display last user name, balse waxaa naga tallo ah haddii uu kombuyuutarka kuu yaalo guriga oo aad isticmaashaan adiga iyo inta kulla degan guriga inaad halkan ku deyso disable, sababtoo ah ma ay jirto cid aad ka qarinayso user name-kii ugu danbeeyey ee loo isticmaalay kombuyuutarka, waa haddii aadan ugu baqayn in qof sidda aan kor kugu soo sheegnay inta uu isku dayo qiyaasida password-ka kadibna khaldo 3-jeer, kadib sidaas account-ga looga dhigo disable, taasna waxay ku dhici kartaa keliya adiga oo markaagii hore qeybta aan kor kugu soo sharaxnay ee ku saabsan inta jeer uu ruuxu khaldi karo password-ka account-ka aad ka dhigto 3 jeer i.w.m, ugu dambeyntii adigaa iska leh go'aanka sidda aad rabto ka dhigo.

• Allow system to be shut down without having to log on

Qeybtan ah "Allow system to be shut down without having to log on" haddii aad ka dhigto disable waxaa lagaa qarinayaa mar walba oo kombuyuutarka dib loosoo shidaba ee lasoo gaaro qeybta aad log on ka sameyn lahayd "battoonka yar ee laga damin karo kombuyuutarka "shut down" ee ku qoran qeybta options-ka", kadibna ruuxu ma awoodi karayo innuu kombuyuutarka ka damiyo botoonkaas "shut down" ee ku qoran qeybta options-ka, waxaanna botoonkii meesha ku qornaa ee ahaa "shut down" laga dhigayaa mid disable ah, marka halkana adigaa go'aankeeda leh, haddii aad rabto ka dhig disable haddii kalena u deyso enable.

• Firewall program

Firewall-ku wuxuu kombuyuutarka u noqdaa gaashaan ka difaaca in kombuyuutarku ay iska soo galaan amaba ka baxaan barnaamij aadan ogayn, wuxuu firewall-ku leeyahay (filtering system) joojin kara waxyaabaha soo galaya kombuyuutarkaaga isla markaana khatarta u keeni kara.

Waxaa jira shirkado badan oo ka ganacsado barnaamijta firewall-ada, balse waxaan halkan hoose kugu soo qornay labo firewall oo billaash ah, haddii aad u isticmaalayso shakhsiyan, haddii aad u isticmaalayso ganacsi i.w.m waa lacag, halkan hoose baad kasoo rogan kartaa.

Kuwan kale ee hoos ku qoranna waxaad soo tijaabin kartaa mid walba inta ku hor qoran, kadib marka ay dhamaado xiliga ay shirkada iska leh barnaamijka ay ugu talla gashay in la tijaabiyo barnaamijka, waa inaad iibsato barnaamijka ama aad ka saartaa kombuyuutarkaaga, laakiin labadda kor aan kugu soo qornay waa lacag la'aan aad bayna ugu fiican yihiin Win XP (ICF).

• AntiVirus program

Bil walba waxaa lasoo saaraa in ka badan badan boqolaal Virus, hadaba si aad kombuyuutarkaaga ugu difaacdo innuu soo galo virus, waa in aad antivirus wanaagsan ku xirato kombuyuutarkaaga, isla mar ahaantaasna aad ku samayso up-to-date mar walba.

Waxaan halkan hoose kugu soo qornay qaar ka mid ah shirkadaha kor ku qoran ee ka ganacsadda barnaamijta firewall-adda, isla barnaamijtooda Antivirus-ka oo qaar-kood ay ku siinayaan muddo ka badan 6 bilood in aad soo tijaabiso barnaamijkooda.

• Spyware

Marka kombuyuutarkaaga ay soo galaan spywares waxaad ku argaysaa is badalo badan oo aadan horey ugu argi jirin, waxaad argaysaa boggii hore ee browser-kaaga oo la badalay isla markaasna ay aad u adgaado inaad mar kale dib u badasho, popup-yo fara badan oo wax xayeesiinaya, settings kombuyuutarkaaga oo is badalla, waxaa kale oo aad argaysaa barnaamij badan oo kusoo xirmay browser-kaaga kuwaas oo aadan horey usoo rogan internet-ka.

Marka haddii aad noocaas iyo wax la mid ah kombuyuutarkaaga ku aragto, waxaad isla markiiba ka fiirisaa in kombuyuutarka ay ku jiraan spywares, waxaana kulla gudboon si aad arintaas u samayso inaad internet-ka kasoo rogatto mid ka mid ah barnaamijta lagu ogaado in ay kombuyuutarka ku jiraan spywares, adigoo aad uga fogaanaya in aad iska soo rogato barnaamij walba oo lagu magacaabay antispyware ee ku jira internet-ka, waxaa jirra barnaamij fara badan oo lagu magacaabo inay kombuyuutarka ka nadiifinayaan spywares, adwares, trojan i.w.m, haddana iyaga laftooda ah spywares, adwares ama trojan, kadibna ay dhacdo in aad adigu gacantaadda si sahlan ugu soo geliso kombuyuutarkaaga spywares, adwares, trojan i.w.m, haddii aad kombuyuutarkaaga ugu shakiso spyware waxaan hoos kugu soo qornay barnaamij aad kombuyuutarka ugu baari karto in ay ku jiraan Spyware.

• Microsoft AntiSpyware (Beta 1)

Waxaa kale oo jira AntiSpyware ay leedahay Microsoft oo bilaash ah, isagana waxaan kugulla talin lahayn inaad tijaabiso haddii aad kombuyuutarkaaga ugu shakiso Spywares, waxaad kasoo rogan kartaa AntiSpyware (Beta 1) lin-ga hoos ku qoran.

• Adware

Waxaa jira shirkado fara badan oo marka aad rabto inaad barnaamijtooda isticmaasho sharuud kaaga dhigayo in aad ogolaado adwares-ka ay sidaan barnaamijtooda, waxaa ka mid ah shirkadahaas barnaamijtooda ay la socdaan adwares kazaa version-keeda bilaashka ah, balse waa heshiis iyo go'aan aad adiga iyo shirkada barnaamijka leh wadda gaarteen oo ah in ay shirkadu kusoo lifaaqi doonto barnaamijkeeda xayeesiinada shirkadaha kale ay shirakadaas wax u xayeesiiso, inta aad barnaamijka shirkadaas ay leedahay aad isticmaalayso waxaad argaysaa xayeesiino fara badan.

Balse waa sharci daro in kombuyuutarkaaga ay iska soo galaan barnaamij la magac baxay adware oo aadan raali ka ahayn habkuu doonaba barmaamijku kombuyuutarka hagu soo galee, haddii aad kombuyuutarkaaga ugu shakiso in ay ku jiraan adware, waxaan hoos kugu soo qornay barnaamij aad kombuyuutarka kaga baari karto adware, waxaan kale oo kugulla tallin lahayn in aad isla isticmaasho oo mar aad ka-wadda fiiriso spyware iyo adware haddii aad kombuyuutarkaaga ku aragto popup-yo wax xayeesinaya oo is fur furaya oo aadan horey ugu argi jirin, halkan hoose kasoo rogo barnaamij aad kombuyuutarka ugu baari karto adware, kadibna kombuyuutarkaaga kawadda baar spyware iyo adware.

• Nasteexo iyo Gunaanud

Waxaa hubaal ah haddii aad intaas u sameesay sidda aan kor kugu soo sharaxnay,
inuu kombuyuutarkaaga amaankiisa ka fiicnaan doonno siddii hore, haddii aad kombuyuutarkaaga ugu shakiso Spyware, Adware, virus i.w.m, isticmaal barnaamijta aan kor kugu soo qornay, kadibna ka baar kombuyuutarkaaga Spyware, Adware ama Virus kale. Si kombuyuutarkaaga uu ugu badbaado khatar, waxaa kulla gudboon in aadan iska soo rogan barnaamij walba oo lasoo geliyo internet-ka, haddii aad rabto inaad barnaamij kasoo rogato internet-ka marka hore waa inaad ku galsoon tahay halka aad barnaamijka kasoo roganayso si aad ugu dheeraato khatarta ay waddaan barnaamijta qaarkood ee lasoo geliyo internet-ka oo in badan oo ka mid ah loo saameeyo lugooyo. Waxaad kale oo aad ogaadaa haddii kombuyuutarkaaga ay isticmaalaan caruurta aad dhashay, waa inaad u samayso koonto xadidan "Limited user account", si aysan kombuyuutarka usoo gelin wax walba oo internet-ka lasoo geliyo.
Waxaan kuu rajeenaynaa Guul iyo Horumar insha Allaah.