• We should now be fully online following an overnight outage. Apologies for any inconvenience, we do not expect there to be any further issues.

How secure is Win2k Pro if your not running a firewall

owensdj

Golden Member
Jul 14, 2000
1,711
6
81
I have a Windows 2000 Pro machine connected to the Internet 24/7 via a cable modem. It's been running since October 2000 without any security problems so far.

Windows 2000 Pro is one of the most secure operating systems available right now. There are far less security exploits found on Win2K than most other operating systems, especially Linux. Linux can be very secure when configured and maintained by a good Unix administrator, but it's usually full of holes out-of-the-box.

If you are running Windows 2000 Pro on the Internet, there are a few things you'll want to do to make it secure. Double click on Network and Dial-Up Connections in Control Panel. Go to the Advanced menu and down to Advanced Setting. Make sure that Internet Protocol(TCP/IP) is UNchecked under both Files and Print Sharing and Client for Microsoft Networks. The next thing you'll want to do is right click Local Area Connection inside Network and Dial-Up Connections and select Properties from the menu. Highlight Internet Protocol(TCP/IP) and then click the Properties button. Click the Advanced button. Select the WINS tab. Make sure that Disable NetBIOS over TCP/IP is choosen and then click OK.
 

FOBSIDE

Platinum Member
Mar 16, 2000
2,178
0
0
actually...any windows OS is on the bottom of the pile when youre talking about security. heres an article i read recently from another one of the posts here on anandtech.

LINK
 

dave1980

Member
Oct 16, 1999
117
0
0
better yet, test it out for yourself - www.grc.com. go into the site and click on 'shields up!' to begin testing.

somethings to mention besides what owensdj said.

if you're not connected to any LAN (basically home use with a dialup/dsl modem to connect to the internet, i'm not sure about this if you're on cable), you'd want to turn off NetBIOS to cover another huge hole. go to start->settings->control panel->administrative tools->services.

set the 'TCP/IP NetBIOS Helper Service' to manual and restart your computer.

BTW, with my DSL modem (and RASPPPOE used instead of verizon's crappy WinPOET implimentation), i can even turn off the DNS Client, DHCP Client too (well, set it to manual...but it's never activated by win2000 when i check) to free up some more RAM w/o any problems.
 

abracadabra1

Diamond Member
Nov 18, 1999
3,879
1
0
win2k secure??
dunno about that bud. i just read an article about how win2k servers are the most hacked servers out of all other servers running different operatings systems.

it was from some damn hacker site w/ statistics. hm....i'm sure someone else read it...link anyone?
 

rbV5

Lifer
Dec 10, 2000
12,632
0
0
I agree with abracadabra1, Zonealarm at the minimum, why would you not want to run a firewall?
 

qmac

Member
May 27, 2000
56
0
0
I'm running a misconfigured linux firewall right now
but that's beside the point.
in win2k if i uncheck tcp/ip from under filesharing, file sharing
is disabled also. is there another protocol i need to install to
get file sharing working within my local network?

also, if someone doesn't mind helping me with my linux firewall configuration
i think i have a misedited rc.firewall file. i just want to forward traffic on
port 21 to my comp, and allow web functionality, napster functionality on other
computers in the network.

 

qmac

Member
May 27, 2000
56
0
0
if i were to guess
i would say my linux box is directing all traffic
to my machine. telnet/ftp/etc.. not just ftp if
that helps. i can't even telnet into it, so i have to
go dig up a old monitor.
icq: #13359037
aim: dr steelface
 

knowley

Senior member
Sep 24, 2000
221
0
0
hmmmmm

I have Zonealarm on both Win98 machine and Win2k

I just ran some tests on both and Zonealarm only improves security on Win98!!! There is no difference between having it swithed on or off in Win2k!

My 2ps worth!
 

Moohooya

Senior member
Oct 10, 1999
677
0
0
I have Win2K on one machine, and 98 on another. They are both connected to the cable modem via a hub and I share files and the printer from one machine to the other.

What should I do to protect myself? I assume if I follow owensdj advice I won't be able to share anything with my other machine, so I can't do that.

Should I use a firewall on my machine? If so, which ones do you recomend? I would like to be able to access my machine from work (not required, but very much wanted.) The file sharing locally is required.

Thanks

Moohoo
 

Davegod75

Diamond Member
Jun 27, 2000
5,320
0
0
<<I just ran some tests on both and Zonealarm only improves security on Win98!!! There is no difference between having it swithed on or off in Win2k!>>

I think not. w2k does not stealth ports and does not filter ingoing and outgoing traffic for you. How can you say there is no differcne with using it and not using it.
 

CLL Sr

Senior member
Oct 12, 1999
415
0
0
I have 2 machines setup similar to Moohooya only using 2 Nics. One nic connects Win2k to the internet with ICS enabled.

This causes win2k to enable a DHCP server for the other nic (lan).

That allows me to plug the 2nd nic into a hub and allocate IP's to anything else I connect to the hub.

By doing this I can turn off file and print sharing on the (wan} cable nic and enable it on the (lan) 2nd nic.

Shields up shows my ports as closed however instead of being stealthed.

So far it has been fairly secure. /fingers crossed mode.

I even connected my Linux machines using this setup without any problems.(except setting up Samba)

Best of luck to you.
 

GAZZA

Golden Member
Oct 18, 1999
1,987
0
0
As most users have said your better off with a firewall , and you dont really get muich better than ZoneAlarm and especially cause it's free adnd extremely easy to use :D
Even on my dialup i use it continuosly