If they're running, I'd recommend disabling the peripheral services such as the Remote Command Server and the JDBC Applet Server. For the ultra - paranoid , consider disabling the DAS, too.