Professional Documents
Culture Documents
70 270part3
70 270part3
Phn 3 mn 70-270
12. S dng tnh nng Windows Update v cch thc to mt CD Windows XP Professional km theo Service Packs
a. Dng tnh nng cp nht t ng Windows Automatic Update Vi Windows Automatic Updates, Windows s tin hnh cc kim tra cc bn cp nht theo nh k nhm bo v computer chng li cc nguy c bo mt mi nht (cc loi virus mi hay cc nguy c tn cng khc nhau..) Vic thc hin cc cp nht ny c tin hnh thng qua Windows Update Web site ca Microsoft bao gm cc: security updates (cp nht bo mt), critical updates (cp nht khn cp- mc nghim trng) , hoc service packs (bn v v bn nng cp tnh nng). Khi tin hnh kch hot chc nng Automatic Updates, chng ta s khng phi lo lng trong vic tm kim cc cp nht online hoc cc bn v bo mt, n gin bi v Windows s t ng download v ci t t ng theo lch biu (schedule) m chng ta xc nh trc. . Nu chng ta mun t mnh download v ci t cc bn cp nht, c th xc lp trong Automatic Updates thng bo ngay mi khi c cc bn cp nht mi. L do nn lp lch biu cho Windows Automatic Updates t cp nht cc bn nng cp ? Nu khng kch hot tnh nng Windows Automatic Updates, computer s c nhiu l hng to c hi xm nhp cho cc loi virus v cc nguy c bo mt khc. Vic Windows t kim tra theo nh k ti Windows Update Web site pht hin ra c cc nguy c bo mt ln nht, v tin hnh cp nht chng s gip computer bn c th chng li cc kiu tn cng nguy him. Cc bn cp nht lun c Windows xc nh c mc u tin cao (High-priority updates), cn cp nht trc l: security updates, critical updates, v cc service packs. Nhng li ch c a ra, sau Khi lp lch biu cho Computer:
Tnh thun tin Khng cn ghi nh khi no cn truy cp vo Windows Update Web site hoc cc Site bo mt trc tuyn khc tin hnh ci t cc updates. V cng khng cn phi xc nh cp nht no l quan trng, cp nht no l khng bo v computerbi v Automatic Updates s t tm kim security updates, critical updates, v service packs, v sau ci vo my theo ng lch biu ra. 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
tin cy Cc Updates c downloaded m khng nh hng n vic download cc chng trnh khc hoc cc hot ng hin thi ca bn trn Internet hoc xung t vi bt c chng trnh no ang vn hnh trn my ca bn. Nu v l do no , trong tin trnh download, b ngt kt ni Internet, cc cp nht s tip tc download li khi Internet c kt ni tr li. Tuy nhin cng ghi nh rng cc updates ny phi c ci t vo my mi c hiu lc. Khi lp lch biu cho cc updates, Windows s t ng ci cc bn v cho bn , tr khi bn chn thng bo cho bn r trc khi ci v bn s th cng ci t nhng bn v cn thit. software lun c cp nht kp thi Vic lp lch biu cho ci t cc updates mi. iu ny c ngha l Windows s kim tra nh k v ci t bt c updates no m my tnh bn c nhu cu v y chnh l tnh nng cp nht kp thi (up to date) rt quan trng cho hot ng n nh v an ton ca my tnh.
NETWORK INFORMATION SECURITY VIETNAM C th bn s c Microsoft yu cu Tha thun bn quyn vi ngi s dng End User License Agreement (EULA) trc khi cc updates ny c th c ci t. cc cp nht khc c th yu cu phi restart computer trc khi tin trnh ci t hon tt. Nu l administrator ca computer, bn c th xc nhn s restart sau. Ngc li Windows s thng bo v t ng restart computer nhm m bo hiu lc cho cc updates va cp nht. Vi cc Admin ca Domain, lp chnh sch t ng cp nht cho nhiu my Domain Clients mt lc, th nn nhc nh nhn vin ca mnh save li cc cng vic ca h khi thi im cp nht (c bit l nhng cp nht quan trng, nh chng mt loi virus mi..) xy ra trong gi lm vic.
Windows XP SP2 Automatic Updates 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
NETWORK INFORMATION SECURITY VIETNAM 1) Automatic La chn c khuyn co nn dng. Khi bn kt ni Internet, Windows s tin hnh tm v downloads cc updates mt cch m thm (background)bn khng nhn c thng bo v n cng khng lm gin on hay nh hng vi cc chng trnh download khc ang hot ng. Nu bn khng thay i thi gian biu t ng cp nht, th lch biu mc nh s l 3 A.M (3 gi sng) 2) Download updates for me, but let me choose when to install them C ngha l Tin hnh download cc cp nht, nhng hy ti chn thi im ci t vo my.. Tuy nhin nhn c thng bo ny, bn phi l thnh vin ca nhm Administrators. Khi kt ni Internet, Windows s tm v download cc cp nht trong backgroundbn s khng c thng bo..Sau khi hon thnh download , biu s xut hin gc phi mn hnh. V mt cnh bo tng Windows Update icon alert pops up cho bn bit cc cp nht sn sng c ci t. xem li v ci t cc updates ny, click vo icon hoc alert. C th tin hnh ci tt c hoc ch mt vi updates sn sng. 3) Notify me but don't automatically download or install updates La chn ny c ngha l hy thng bo cho ti bit, nhng khng tin hnh download v ci t updates c th th cng download v ci cc updates, bn phi l thnh vin nhm Administrators. Windows s kim tra cc updates quan trng v thng bo vi bn nu chng xut hin; cc updates s khng c phn phi hay ci t vo my tnh cho n khi bn quyt nh chn. Khi Windows tm thy cc updates Windows s xut hin khu vc thng bo v xut hin km cnh bo alert Update icon pops up, cho bn bit rng cc updates sn sng c download. Sau bn c th click vo icon hoc alert chn nhng updates (hoc chn tt c) no cn download. Windows downloads cc cp nht trong backgroundbn cng khng c thng bo trong sut tin trnh v cng khng nh hng n cc chng trnh download khc. 4) Turn off Automatic Updates
NETWORK INFORMATION SECURITY VIETNAM Nu chn la chn ny, bn s khng bao gi nhn c thng bo v cc updates v cng khng nhn c cc yu cu download hoc ci t chng. iu ny ng ngha vi my tnh ca bn ang trong tnh trng cnh bo, nguy c bo mt rt cao, virus v cc l hng bo mt mi s khin my tnh v d liu b e da. Viruses c mt khp mi ni trn Internet, vi nhiu hnh thc ly nhim tinh vi (qua email, share file, IM messenger, download softwares..). Cc th h virus mi v cc hnh thc tn cng a dng c pht trin bi cc Attackers thc s l mi e da v vic ngi s dng Microsoft Windows khng hoc khng bit cch kch hot Automatic Updates thng xuyn cp nht cc Windows Update Web site thc s l mi nguy him ln nht m bn updtaes t ngi s dng my tnh phi i mt hng ngy. http://windowsupdate.microsoft.com/
Cc bc thc hin
Click START menu. Click CONTROL PANEL icon. Click SECURITY CENTER.
b. Cch thc to mt CD Windows XP Professional c Service Packs (Boot & Installation CD) K t khi bn mua Windows XP ca Microsoft, trong qu trnh s dng Microsoft cung cp cho khch hng cc Service packs nhm nng cp tnh nng HH, cng nh cc bn v tng cng bo mt. c th tp hp bn Windows XP km theo cc Service Packs pht hnh , bn c th t mnh to mt CD Windows XP Professional c km Service packs v ng nhin c kh nng Boot t CD (cn c gi vi tn l SPLIPSTREAMING WINDOWS XP SERVICE PACK ) Sau y l cch thc thc hin mt SPLIPSTREAMING WINDOWS XP SERVICE PACK 1
NETWORK INFORMATION SECURITY VIETNAM 1. Copy ton b a ngun Windows XP Professional CD vo mt Folder v d: E:\XP-CD 2. Download ton b Service Pack 1 t Microsoft web site. File download v l xpsp1a_en_x86.exe http://www.microsoft.com/windowsxp/downloads/updates/sp1/network. mspx 3. To mt folder E:\XP-SP1 4. Download ton b xpsp1a_en_x86.exe v folder ny, sau x (Extract) ton b Service Packs 1 vo E:\XP-SP1 bng cch dng lnh sau (t du nhc E:/> cc bn dng lnh CD XP-SP1 vo folder ny trc khi thc hin lnh) E:\XP-SP1> xpsp1a_en_x86.exe x
5. Sau nhng ton b Service Packs 1 vo Folder cha Cd gc E:\XP-CD Bng cch dng lnh sau E:\XP-SP1> CD update E:\XP-SP1\update> update /s:E:\XP-CD 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
6. Bc tip theo tin hnh to CD Windows XP + Service Packs 1 c kh nng boot. 2 chng trnh sau c yu cu : ISO Buster to cc file khi ng (boot file) t CD http://www.soft-ware.net/system/hardware/cdrom/p02491.asp Sau khi ci t, Dng ISO Buster tin hnh x Image File c tn Microsoft Corporation.img Image file ny cn thit cho qu trnh ghi a. Ch thi im ny trong CD-ROM cn c CD Windows XP Professional, sau bn mi c th chn Bootable D khung tri
Sau click phi file Microsoft Corporation.img v chn Extract Microsoft Corporation.img
Sau thot khi ISO Buster Software ghi a CD (Roxio hoc Nero) http://trial.roxio.com/uk/creator75uk.exe 1. Chy Roxio v chn Bootable CD
Sau bn click vo nut Browse, tm n file E:\ Microsoft Corporation.img to trc v chn Open
ty phin bn Windows ca bn l Home hay Pro , mua CD t cc i l phn phi ca Microsoft hay t OEM (my tnh ca nh sn xut ci sn Windows cho bn): Windows Windows Windows Windows XP XP XP XP Professional: WXPCCP_EN Professional-OEM: WXPOEM_EN Home: WXHCCP_EN Home-OEM: WXHOEM_EN
Chn OK
Kt Qu:
Chn Change All tin trnh ghi CD bt u. Finish Thc hnh: Hc vin tin hnh donwload demo lab hng dn Windows Automatic Update v cch to mt Boot CD Windows XP professional. http://www.nis.com.vn/securitytraining/mcse/baigiangchinhthuc/70270/lab/capnhatwindows.rar
13. S dng tnh nng File and Settings Transfer Wizard chuyn d liu v cc thng s xc lp t Computer c sang Computer mi
Chng ta va sm mt PC mi v ci t mi Windows XP Professional, tt c ngi dng u mong mun lm th no chuyn cc file d liu v cc xc lp c t PC c sang PC mi ?. Microsoft cung cp mt cng c mi c th gip bn chuyn (transfer) cc files v cc xc lp c sang PC mi mt cch d dng, cng c h tr ny c gi l File and Settings Transfer Wizard.
File and Settings Transfer Wizard s chuyn nhng g n New PC ? Appearance. Bao gm cc xc lp c nh: wallpaper, colors, sounds, v tr ca thanh taskbar. Action. Chng hn nh tn s lp li khi g phm (key repeat rate), double-clicking m mt folder trong ca s mi hay cng trong ca s .double-click hay single-click m mt mc no Internet. Nhng xc lp khi kt ni Internet v iu khin cch hot ng ca trnh duyt (browser). Chng hn nh cc xc lp v homepage URL, favorites / bookmarks, cookies, security settings, dial-up connections, v proxy settings. Mail. Thng tin cn thit kt ni mail Server , file dng lm ch k cho e-mail (signature file), views, mail rules, local mail, v cc d liu v contacts. Tt nhin l bn ang dng Outlook hoc Outlook Express. Application Setting. Cc xc lp nh dng ca Microsoft Office. Cc phng tin phc v vic chuyn l ? Dng a mm hoc cc loi a tho ri khc c dung lng cao hn (USB, a Quang, CD ghi.). Mt cable kt ni trc tip gia 2 PC (direct cable) qua cng ni tip (Serial Port) tuy cch ny t ph bin Lu tr vo mt a ca mt my tnh Server Mng v sau chuyn i sau (Network Drive)
70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
khi ng File and Settings Transfer Wizard, chy Setup.exe t Windows XP CD-ROM trn h thng c (h thng c c th l bt k Windows 95, 98, 98 SE, Me, NT 4.0, Windows 2000 hoc Windows XP). T menu Setup chn Perform Additional Tasks. Chn tip Transfer files and settings.
Sau File and Settings Transfer Wizard, a ra danh sch cc phng tin chuyn file, hy chn ly mt cch thc ph hp, v d, hin bn khng c Direct Cable cng nh Network, th hy chn lu cc xc lp vo Flloppy Drive hoc USB 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
NETWORK INFORMATION SECURITY VIETNAM hoc nu chn Other, c th save vo bt c folder no trn cng, sau chp li vo CD hay bt c Removeble disk no m bn mun (USB, LS-120..) v sau a cc Disk ny vo New PC tin hnh phc hi : Trong vd ny, chng ta chn Floopy Drive..
K n hy chn nhng g bn mun Transfer . Settings only Files only Both files and settings hoc Let me select a custom list of files and settings...... Trong vd ny chng ta chn Both files and settings.
Click Next bn s thy xut hin cc nt Settings, Folders, Files v File Types. Ch c th chn c nu trc check vobox Let me select a custom list of files and settings....trong mn hnh trc . y l la chn nng cao gip bn hiu c h thng v cc file m n s dng. Nu bn khng c s la chn no y, Microsoft cho rng bn s lu ton b My Documents
Trong giai on ny ca tin trnh ton b file v cc xc lp s c lu vo v tr xc nh . tt nhin thit b lu tr phi p ng dung lng cn lu, nu Floopy disk khng , phi thay th thit b lu tr trc
V by gi chng ta s a nhng d liu ny n PC mi Ti computer mi, cc bn c th m chc nng File and Settings Transfer Wizard bng cch chn Start > All Programs > Accessories > System Tools > File and Settings Transfer Wizard. 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
K tip chn a lu tr m bn lu d liu v cc thng s xc lp ti phn u. C th chn I don't need the Wizard Disk..... t bn tm n a lu tr
Sau khi File and Settings Transfer Wizard hon thnh tc v , nhn Finish, sau bn c nhc nh Log-off New Computer, mc ch l cc xc lp va phc hi c tc dng trn my mi. Log-on tr li v gi y bn c th kim tra tt c cc files v cc xc lp c hin din ti New Computer.
Download Bn cp nht ca chng trnh File and Settings Transfer Wizard. Do c mt s khim khuyt ca c nn cc bn c th cp nht phin bn mi ca n ti y http://support.microsoft.com/default.aspx?scid=kb;en-us;307869 c k v tin hnh Download. Thc hnh: Hc vin tin hnh donwload demo lab hng dn File and Settings Transfer Wizard , ti y
http://www.nis.com.vn/securitytraining/mcse/baigiangchinhthuc/70270/lab/transferwizard.rar
a. Bo mt vt l cho Computer Tin hnh bo mt vt l cho Computer l mt trong nhng vn cn quan tm nht. Ti bt k h thng thng tin nao, t c nhn (PC) cho n Doanh Nghip (Enterprise), vic bo mt vt l u c nh gi cao, xem nh khu ny, vic u t vo cc thit b bo mt t tin (nh Firewall cng..) hoc cc chng trnh an ton my tnh khc (phn mm bo mt..) dng nh khng cn my ngha, v ch mang tnh hnh thc.. K trm khng u xa, chng nm di chn chng ta m ch CPU t di chn bn lm vic, v bn thng khng ngh n vic bo v n, c nh ln c quan.. Ti liu chun ca Microsoft c a ra mt s hng dn bo mt vt l my tnh, n gin v d ghi nh.
Vi a mm khi ng cha cc chng trnh Reset Admin password, Windows 2000, XP, 2003 d dng b xm nhp. Microsoft cung cp sn cho ngi dng tin ch bo mt quan trng l Syskey , c th xem y l lp kha bo v Computer m Ngi dng phi cho bit m truy cp trc khi n lp bo v k tip l Username/password log-in vo my. Mc ch chnh ca Syskey l bo v c s d liu cha ton b ti khon ca my (local accounts database), cc bn sao ca cc kha m ha EFS (local copies of EFS encryption keys), v cc gi tr khc m bn khng mun attackers c th c c. Tham kho ton din v Syskey v cch ci t ti y http://support.microsoft.com/kb/310105/ Ch , khi ci t Syskey dui dng password, phi ghi nh k password ny, nu bn qun kh nng phi ci t li Windows l rt ln. Dng tnh nng m ha EFS - Encrypting File System (EFS) m ha tt c nhng Folder nhy cm trn my bn. EFS c mt trn Windows 2000, Windows XP , Professional, 2003EFS cn c a vo m rng kh nng bo v d liu vt, v d khi a cng b nh cp, d liu vn khng th c, sao chp c nh EFS m ha ton b nhng Folder c bo v. Xem hng dn EFS phn sau b. 3 bc bo v h thng Microsoft
S dng Windows Update cp nht cc bn v kp thi Dng cc chng trnh phng chng Virus (v d nhin l c kh nng chng lun
Worm, Spyware, Trojans..) . Hy xem bng nh gi chi tit v so snh ca 10 AntiVirus Software hng u hin nay (c km theo gi c, v cc thng tin chi tit khc..) Cc bn chn cho mnh sn phm ph hp v tinh nng v gi c
http://anti-virus-softwarereview.toptenreviews.com/?ttreng=1&ttrkey=norton+anti+virus
Trong s , c th k n Zone Alarm, rt ni bt v c a chung vi tnh nng mnh m v min ph. Windows Internet Connection Firewall cng c nh gi cao, v c sn trong cc sn phm Windows XP Professional Xem bng nh gi chi tit cc Personal Firewall ti y http://www.webuser.co.uk/products/Firewalls_203_index.html V Personal Firewall ca Windows XP Professional , cn gi l ICF (Internet Connection Firewall), y l thnh phn c tch hp sn khi dng XP Pro c ci Service Packs 2.
NETWORK INFORMATION SECURITY VIETNAM Thng co mi nht ngy 15.8.2006, bao gm chi tit v mt k thut h tr ngi dng ca Microsoft v sn phm ICF , gip chng ta c th cu hiu v cu hnh ICF mt cch n gin v an ton nh sau: Windows Firewall bo v Computer ca bn qua vic ngn chn (block) cc giao tip t nhng phn mm c kh nng gy nguy him, khi cc phn mm ny thc hin kt ni vo Computer ca bn. Windows Firewall kh nng nhn bit nhng kt ni an ton (t cc my tnh trong Mng ni b n my ca bn) v cho php, ngc li s block nhng kt ni khng an ton t Internet n my bn. Mc nh Windows Firewall cng ch cho php chia s File, hay in n ( files / printer) gia 2 Computer trong Mng ni b v s block bt c truy cp no t Internet kt ni vo my bn. Ch cn cu hnh Windows Firewall nu gp phi vn vi mt chng trnh hp php cn kt ni ra Internet ( v d MSN messenger, yahoo Messenger, Game Online.) . Nu khng gp phi vn g , vic n gin chng ta cn lm l kch hot Windows Firewall trn my tnh ca mnh, v yn tm khi truy cp Internet Khi mt ng dng no cn kt ni Internet v bn bit rng ng dng ny l hp php m ICF khng t ng nhn ra v a vo danh sch cho php , th bn c th a ng dng ny vo danh sch exception (c ngha l tt c s b block, ngoi tr nhng ng dng ny l khng b cm..)
Windows Firewall lm c g v khng lm c g ? C th n s bo v c Computer ca bn chng li cc hnh thc tn cng Mng thng qua cc m phn mm nguy him nh Worms.. tuy nhin vic chng Virus, spyware nm ngoi kh nng ca n. Vi vn Virus v Spyware c l ngi s dng nn dng mt s chng trnh mi ca Microsoft nh :
Windows Live Onecare
(chng Virus)
http://www.windowsonecare.com/
(chng Spyware)
http://www.microsoft.com/athome/security/spyware/software/default .mspx
Cch thc m Windows Firewall Click Start, click Control Panel. T Control Panel, click Security Center
NETWORK INFORMATION SECURITY VIETNAM Khi Windows Firewall ch bo v th tt c traffic t ngoi vo my bn u b cm (block)
Ngoi tr nhng ng dng mc nh v nhng ng dng hp php m Windows Firewall t ng cho php nm trong Exceptions (Danh sch nhng ng dng khng b Block). Chng hn nh c mt ng dng no khng nguy hi, nhng khng nm trong danh sch Exceptions (tc ng dng ny b cm hot ng), bn c th d dng tm ng dng ny v a vo Exceptions List Trong v d ny, chng ta cho php ng dng a vo Exceptions List Windows Messenger hot ng v
NETWORK INFORMATION SECURITY VIETNAM Tm chng trnh Windows Messenger, click phi chut chn Properties tm ng dn n file .exe
Trn Shortcut tab trong Properties dialog box, right-click Target box, click Copy.
Trong Browse dialog box, right-click File name box, sau click Paste.
Click Open.
Nh vy ngoi cc ng dng vn hnh di dng File chng trnh .exe c ci t trn my bn nh (Windows Messenger, Yahoo Messenger, Bit Torrent..) khi chn Edit, cc bn s thy ng dn lin kt ng dng
Nh ng dng yahoo Messenger trn y, nm trong danh sch Exceptions v c php giao tip vi Yahoo Messenger Servers qua Internet (thng qua giao thc v Port xc nh ca nh cung cp dch v Yahoo Messenger vd nh TCP-5050, giao thc v Port khng hin th khi click vo Edit). Nu nh my tnh ca chng ta c mt s dch v no , v cung cp dch v ny cho cc my tnh khc (c th l trong Mng ni b hoc Internet). C th dng tnh nng Add Port, xc nh Giao thc, Cng m dch v ny s dng v xc nh nhng a ch Ip ca my bn ngoi c th truy cp vo My ca bn qua giao thc v cng y.
NETWORK INFORMATION SECURITY VIETNAM Trong v d ny, my ca bn c dch v Remote Desktop ang vn hnh v bn mun cu hnh cho php trc , nhm khi i cng tc xa vn c th lm vic vi my tnh ca bn. Chn Add port, i6n tn dch v l Remote Desktop (cc thng s giao thc l TCP v Port number l 3389. y l cng m remote desktop service cho php t xa kt ni vo qua TCP)
NETWORK INFORMATION SECURITY VIETNAM Chn tip Change Scope xc nh nhng IP no bn ngoi s c kt ni vo, vd ny cc bn chn Any computer (bao gm c Internet IP !!!!) ch hi nguy him.. V tng t nh vy l vi cc dch v chia s File v In n qua Mng
Hoc cc bn cng c th click vo Advanced . Ti y cc bn nhn thy Windows Firewall s bo v cho tt c kt ni Mng dng NIC card hay Wireless, chn Settings cc bn c th thy sn c mt danh sch cc ng dng Mng m my tnh cc bn c th chia s c Windows Firewall cu hnh sn..gip n gin ha vic m Port v Protocol. Nu ng dng cn chia s chy trn my bn, ch cn check vo checkbox th t xa c th truy cp vo my bn, s dng cc dch v chia s 70-270 WINDOWS XP PROFESSIONAL INSTALLATION AND Nis.com.vn ADMINISTRATION
Nu mun m cng cho dch v mi, chon Add, tng t nh cch lm trn. Ngoi ra cc bn c th chn Setting ti Security logging xem kch c cng nh v tr lu tr mc inh ca File nht k bo mt ny xem file c th dng chng trnh chuyn dng Windows Xp Firewall Log Viewer detail download ti link sau: http://eskapism.se/software/bin/windows_xp_firewall_log_viewer_0_ 2.zip
NETWORK INFORMATION SECURITY VIETNAM Thc hnh: Hc vin tin hnh donwload demo lab hng dn Security cho Windows XP Professional . http://www.nis.com.vn/securitytraining/mcse/baigiangchinhthuc/70270/lab/security.rar