Home > Enterprise Desktop Tips > > XP SP2: Nothing more than security best practices?
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


XP SP2: Nothing more than security best practices?


Kevin Beaver
08.18.2004
Rating: -3.69- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In part one of this series below, you'll get a primer on Windows XP Service Pack 2 (SP2) security enhancements. Part two discusses Microsoft's isolation and resiliency initiatives and what benefits they can offer you in securing Windows.


Earlier this year, Microsoft made some waves in the security pool by announcing it would put significant research and development resources into security enhancements for its software, and most recently for its long-awaited Windows XP Service Pack 2 (SP2) -- also referred to as Security Pack 2 given its focus. Should this hoopla be on your radar?

One new feature of XP SP2 is that much of the code has been recompiled to protect against buffer overflows. SP2 also supports the NX (no-execute) flag supported by the AMD K8 and Intel Itanium processors, which prevents code from being executed in areas of memory that are reserved for data. In addition, various DCOM and RPC components have been reworked helping to reduce the "attack surface" of Windows, referring to the system openings that a hacker or malware can exploit.

Other security enhancements include:

  • Over 600 new Active Directory Group Policy Objects affecting security;
  • Security Center module in the control panel with enhanced security settings;
  • New Windows Firewall to replace the original Internet Connection Firewall (ICF), which is now enabled by default and can be managed centrally across the network;
  • Pop-up blocker option, and security zone and Internet Explorer improvements to make it more secure by default;
  • Enhanced security when downloading HTML and file attachments via e-mail and instant messaging in Outlook Express and Windows Messenger, which is now disabled by default;
  • Improvements to the Automatic Updates service.

Other planned security enhancements are in the works for Exchange Server, Windows Server 2003, ISA Server and more.

So nothing is that new here. Microsoft has simply taken some security best practices -- things that should be done to keep operating systems secure in the first place -- and built them into its software to force network managers and users to secure Windows correctly.

I never thought I'd say this, but I actually feel a little sorry for Bill Gates and company. They're releasing software with gobs of features demanded by their customers -- the same customers who often fail to make the slightest effort to correctly secure their systems. What's a software vendor to do?

Don't get me wrong. I'm not completely on Bill's side. I don't like the fact that Microsoft is preventing the installatioon of SP2 on pirated copies of Windows XP. Imagine how much more secure the Internet could be if they did.


About the author
Kevin Beaver is founder and principal consultant of Atlanta-based Principle Logic LLC, as well as a resident expert on SearchWindowsSecurity.com. He specializes in information security assessments and incident response and is the author of the new book "Hacking for dummies" by John Wiley and Sons. Kevin can be reached at kbeaver@principlelogic.com or ask him a question on Windows security threats today.

Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Patches, alerts and critical updates
Microsoft releases six patches for November
Structuring patch management in seven steps
Underlying causes of inconsistent patch management
Microsoft's Online Desktop Manager caters to small IT shops
Microsoft's Patch Tuesday brings a bumper crop of security fixes
Act fast with five critical September patches
Microsoft's August patches run the gamut
Patching third-party browsers adds more work in Windows shops
Troubleshooting Microsoft WSUS connectivity issues
Windows security tools for the busy desktop administrator

Microsoft Windows XP Pro
Guide to converting from Windows XP to Windows 7
Top 5 registry keys for Windows XP
Manage the desktop image lifecycle to limit work, ensure security
Secure Windows XP before a Windows 7 upgrade
Microsoft's August patches run the gamut
Hold on to Windows XP at your peril
XP stragglers blame hardware costs, new features
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Vista shops eye quick path to Windows 7, XP shops likely to resist

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts