windows服务器记录3389远程桌面IP策略
程序员文章站
2022-03-29 22:57:09
3389ip日志路径是c:\windows\pdplog\rdplog.txt 程序代码 复制代码 代码如下: md c:\windows\pdplog echo date...
3389ip日志路径是c:\windows\pdplog\rdplog.txt
程序代码
md c:\windows\pdplog
echo date /t ^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo time /t ^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo netstat -n -p tcp ^| find ":3389"^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo start explorer >>c:\windows\pdplog\pdplog.cmd
:: 添加用户每次进入远程桌面时自动记录下来所用ip,可用来发现黑客踪迹!
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v finheritinitialprogram /t reg_dword /d "00000000" /f
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v workdirectory /t reg_sz /d c:\windows\pdplog\ /f
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v initialprogram /t reg_sz /d "c:\windows\pdplog\pdplog.cmd" /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v finheritinitialprogram /t reg_dword /d "00000000" /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v workdirectory /t reg_sz /d c:\windows\pdplog\ /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v initialprogram /t reg_sz /d "c:\windows\pdplog\pdplog.cmd" /f
echo 记录远程桌面ip策略添加完毕! 请按任意键退出!
pause >nul
程序代码
复制代码 代码如下:
md c:\windows\pdplog
echo date /t ^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo time /t ^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo netstat -n -p tcp ^| find ":3389"^>^>rdplog.txt >>c:\windows\pdplog\pdplog.cmd
echo start explorer >>c:\windows\pdplog\pdplog.cmd
:: 添加用户每次进入远程桌面时自动记录下来所用ip,可用来发现黑客踪迹!
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v finheritinitialprogram /t reg_dword /d "00000000" /f
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v workdirectory /t reg_sz /d c:\windows\pdplog\ /f
reg add "hkey_local_machine\system\controlset001\control\terminal server\winstations\rdp-tcp" /v initialprogram /t reg_sz /d "c:\windows\pdplog\pdplog.cmd" /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v finheritinitialprogram /t reg_dword /d "00000000" /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v workdirectory /t reg_sz /d c:\windows\pdplog\ /f
reg add "hkey_local_machine\system\currentcontrolset\control\terminal server\winstations\rdp-tcp" /v initialprogram /t reg_sz /d "c:\windows\pdplog\pdplog.cmd" /f
echo 记录远程桌面ip策略添加完毕! 请按任意键退出!
pause >nul