Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.

Slides:



Advertisements
Similar presentations
Desktop Value - Introducing Windows XP Service Pack 2 with Advanced Security Technologies Presenter: James K. Murray Title: Information Technologies Consultant.
Advertisements

WSUS Presented by: Nada Abdullah Ahmed.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Windows Server 2003 SP1. Windows Server™ 2003 Service Pack 1 Technical Overview Jill Steinberg: Added TM Jill Steinberg: Added TM.
Defense-in-Depth Against Malicious Software Jeff Alexander IT Pro Evangelist Microsoft Australia
Windows XP Service Pack 2 Technical Update. Windows XP Service Pack 2 Technical Workshop Agenda –Security Overview –Introduce Windows XP Service Pack.
Windows XP Service Pack 2 Alex Balcanquall Senior Consultant Microsoft Services Organisation.
Changes in Windows XP Service Pack 2
1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Information for Developers Windows XP Service Pack 2 Information for Developers.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 15: Internet Explorer and Remote Connectivity Tools.
Patching MIT SUS Services IS&T Network Infrastructure Services Team.
Guide to Operating System Security Chapter 2 Viruses, Worms, and Malicious Software.
Windows XP Service Pack 2 and the Microsoft Virtual Machine: Developer Implications Rudi Larno Developer & Platform Group Microsoft BeLux.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 2 Craig Schofield Microsoft Ltd. UK September.
Security Flaws in Windows XP Service Pack 2 CSE /14/04 By: Saeed Abu Nimeh.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Security of Communication & IT systems Bucharest, 21 st September 2004 Stephen McGibbon Chief Technology Officer, Eastern Europe, Russia & CIS Senior Director,
Microsoft Windows XP SP2 for Developers Rafal Lukawiecki Strategic Consultant Project Botticelli Ltd This session is based.
2851A_C01. Microsoft Windows XP Service Pack 2 Security Technologies Bruce Cowper IT Pro Advisor Microsoft Canada.
Microsoft October 2004 Security Bulletins Briefing for Senior IT Managers updated October 20, 2004 Marcus H. Sachs, P.E. The SANS Institute October 12,
Microsoft ® Official Course Module 9 Configuring Applications.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
Chapter 4: Security Baselines Security+ Guide to Network Security Fundamentals Second Edition.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 15 Installing and Using Windows XP Professional.
Hands-On Microsoft Windows Server 2008
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp
Introduction to Windows XP Professional Chapter 2 powered by dj.
Course ILT Windows installation and upgrades Unit objectives Install a Windows operating system Upgrade from one version of Windows to another.
DIT314 ~ Client Operating System & Administration CHAPTER 2 INTRODUCTION TO WINDOWS XP PROFESSIONAL Prepared By : Suraya Alias.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Windows Small Business Server 2003 Setting up and Connecting David Overton Partner Technical Specialist.
Windows XP Professional Features ©Richard L. Goldman February 5, 2003.
C HAPTER 2 Introduction to Windows XP Professional.
Computer Emergency Notification System (CENS)
Module 5: Configuring Internet Explorer and Supporting Applications.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 13 Understanding and Installing Windows 2000 and Windows NT.
Week #3 Objectives Partition Disks in Windows® 7 Manage Disk Volumes Maintain Disks in Windows 7 Install and Configure Device Drivers.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Windows XP Service Pack 2 Customer Awareness Workshop Trustworthy Computing – XP SP2 Technical Overview Craig Schofield Microsoft.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 1 Craig Schofield Microsoft Ltd. UK September.
NetTech Solutions Supporting Users and Troubleshooting Desktop Applications on Microsoft Windows XP Instructor Richard Fredrickson.
Module 7: Implementing Security Using Group Policy.
Hands-On Microsoft Windows Server 2008 Chapter 5 Configuring Windows Server 2008 Printing.
Module 8 Implementing Security Using Group Policy.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK
Active X and Signed Applets Chad Bollard. Overview ActiveX  Security Features  Hidden Problems Signed Applets  Security Features  Security Problems.
Vulnerabilities in Operating Systems Michael Gaydeski COSC December 2008.
ITMT Windows 7 Configuration Chapter 7 – Working with Applications.
1 BCS 4 th Semester. Step 1: Download SQL Server 2005 Express Edition Version Feature SQL Server 2005 Express Edition SP1 SQL Server 2005 Express Edition.
By the end of this lesson you will be able to: 1. Determine the preventive support measures that are in place at your school.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Windows Vista Configuration MCTS : Network Security.
11 DEPLOYING AN UPDATE MANAGEMENT INFRASTRUCTURE Chapter 6.
HARDENING CLIENT COMPUTERS
Chapter 4: Security Baselines
Lesson #10 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 10 Configuring Network and Firewall Settings.
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Implementing Client Security on Windows 2000 and Windows XP Level 150
Designing IIS Security (IIS – Internet Information Service)
Windows XP SP2 & Windows Server 2003 SP1
Using Software Restriction Policies
Implementing Advanced Server and Client Security
Presentation transcript:

Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH

Overview Of Windows XP SP2 Memory Provide system-level protection for the base operating system Network Help protect the system from attacks from the network /IM Enable safer and Instant Messaging experience Web Enable safer Internet experience for most common Internet tasks

Windows Firewall Goal and Customer Benefit Provide better protection from network attacks by default Provide better protection from network attacks by default Focus on roaming systems, small business, home users Focus on roaming systems, small business, home users What We’re Doing Windows Firewall (formerly ICF) will be on by default in almost all configurations Windows Firewall (formerly ICF) will be on by default in almost all configurations More configuration options More configuration options Group policy, command line, unattended setup, Group policy, command line, unattended setup, Better user interface Better user interface Boot time protection Boot time protection Multiple profile support Multiple profile support Connected to corporate network vs. home Connected to corporate network vs. home Enable file sharing on home networks with Windows Firewall on Enable file sharing on home networks with Windows Firewall on Developer Impact In-bound network connections not permitted by default In-bound network connections not permitted by default Dynamically enable ports as necessary, but only for as long as necessary, disable when done Dynamically enable ports as necessary, but only for as long as necessary, disable when done Memory Network /IM Web

DCOM And RPC Changes Goal and Customer Benefit Reducing DCOM / RPC attack surface exposed on network Reducing DCOM / RPC attack surface exposed on network What We’re Doing Require authentication on default interfaces Require authentication on default interfaces Enable programmatic ability to restrict RPC interfaces to local machine only Enable programmatic ability to restrict RPC interfaces to local machine only Configuration of access and launch permissions for DCOM through registry Configuration of access and launch permissions for DCOM through registry Move most RPCSS code into reduced privilege process Move most RPCSS code into reduced privilege process Enable customer-controlled option to require authentication to the end-point mapper Enable customer-controlled option to require authentication to the end-point mapper Disable RPC over UDP by default Disable RPC over UDP by default Developer Impact Where appropriate, use new RPC API to limit calls to local machine Where appropriate, use new RPC API to limit calls to local machine Ensure your application doesn’t require anonymous clients Ensure your application doesn’t require anonymous clients Don’t use RPC over UDP Don’t use RPC over UDPNetwork Memory /IM Web

Attachments Goal and Customer Benefit Consistent system-provided mechanism for applications to determine unsafe attachments Consistent system-provided mechanism for applications to determine unsafe attachments Consistent user experience for attachment “trust” decisions Consistent user experience for attachment “trust” decisions What We’re Doing Create new public API for handling safe attachments (Attachment Execution Services) Create new public API for handling safe attachments (Attachment Execution Services) Default to not trust unsafe attachments Default to not trust unsafe attachments Outlook, Outlook Express, Windows Messenger, Internet Explorer changed to use new API Outlook, Outlook Express, Windows Messenger, Internet Explorer changed to use new API Open / execute attachments with least privilege possible Open / execute attachments with least privilege possible Safer message “preview” Safer message “preview” Replaces AssocIsSafe() Replaces AssocIsSafe() Developer Impact Use new API in your applications for better user experience, and better determination of safe content Use new API in your applications for better user experience, and better determination of safe content Memory Network /IM Web

Web Browsing Goal and Customer Benefit Ensure a safer web browsing experience Ensure a safer web browsing experience What We’re Doing Locking down local machine and local intranet zones Locking down local machine and local intranet zones Improved notifications for running or installing applications and ActiveX controls Improved notifications for running or installing applications and ActiveX controls HTML files on the local machine will not be able to script unsafe ActiveX controls or access data across domains in the Local Machine Security Zone HTML files on the local machine will not be able to script unsafe ActiveX controls or access data across domains in the Local Machine Security Zone Blocking unknown, unsigned ActiveX controls Blocking unknown, unsigned ActiveX controls Disarm cross domain script attacks on APIs Disarm cross domain script attacks on APIs Improved detection and handling of downloaded files through improvements to mime-handling code path Improved detection and handling of downloaded files through improvements to mime-handling code path Files served with mismatched or missing mime-headers and file extensions may be blocked Files served with mismatched or missing mime-headers and file extensions may be blocked Memory Network /IM Web

Web Browsing What We’re Doing (continued) Mitigate ActiveX reuse through potential limited control leashing and more guided user experience Mitigate ActiveX reuse through potential limited control leashing and more guided user experience Limit UI spoofing Limit UI spoofing Pop-up windows will be suppressed unless they are initiated by user action Pop-up windows will be suppressed unless they are initiated by user action Developer Impact Check for web application compatibility with newer, safer browsing defaults Check for web application compatibility with newer, safer browsing defaults Identify whether controls are safe for scripting on the Internet, or if they can be more restricted Identify whether controls are safe for scripting on the Internet, or if they can be more restricted Memory Network /IM Web

Hardware Execution Protection Goal and Customer Benefit Reduce exposure of some buffer overruns Reduce exposure of some buffer overruns What We’re Doing Leverage hardware support in 64-bit and newer 32-bit processors to only permit execution of code in memory regions specifically marked as execute Leverage hardware support in 64-bit and newer 32-bit processors to only permit execution of code in memory regions specifically marked as execute Reduces exploitability of buffer overruns Reduces exploitability of buffer overruns Enable by default on all capable machines for Windows binaries Enable by default on all capable machines for Windows binaries Ensure application compatibility with NX for Longhorn Ensure application compatibility with NX for Longhorn Developer Impact Ensure your code doesn’t execute code in a data segment Ensure your code doesn’t execute code in a data segment Ensure your code runs in PAE mode with <4GB RAM Ensure your code runs in PAE mode with <4GB RAM Use VirtualAlloc with PAGE_EXECUTE to allocated memory as executable Use VirtualAlloc with PAGE_EXECUTE to allocated memory as executable Test your code on 64-bit and 32-bit processors with “Execution protection” Test your code on 64-bit and 32-bit processors with “Execution protection” Memory Network /IM Web

Additional Enhancements In Windows SP2 Automatic Update Automatic Update  SP2 will make it more convenient for customers to enable Automatic Update for critical updates SUS 2.0 client SUS 2.0 client  Software Update Services 2.0 will use a consistent engine for reporting system state and reducing inconsistent results on secure patch availability on a computer Windows Media 9 Series Player: Windows Media 9 Series Player:  Enhanced performance and security improvements over prior versions

Additional Enhancements In Windows SP2 DirectX 9.0b DirectX 9.0b  Latest, most secure DirectX components include fixes to address a network firewall change that impacts OEM pre- installs and DirectPlay Bluetooth 2.0 Bluetooth 2.0  Includes support for the latest version of Bluetooth 2.0 allowing customers to take advantage of the latest wireless devices Unified Windows Local Area Network (LAN) client Unified Windows Local Area Network (LAN) client  New wireless LAN will work with a broad range of wireless hotspots enabling customers to connect seamlessly without having to install or update a third-party client

© 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.