Changes in Windows XP Service Pack 2

Slides:



Advertisements
Similar presentations
®® Microsoft Windows 7 for Power Users Tutorial 7 Enhancing Your Computers Security.
Advertisements

Chapter 7 – Managing Windows XP. Control Panel The main tool for configuring your system. Most of the tools to configure the system come with the normal.
Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Module 6: Configuring Windows XP Professional to Operate in a Microsoft Network.
Windows Server 2003 SP1. Windows Server™ 2003 Service Pack 1 Technical Overview Jill Steinberg: Added TM Jill Steinberg: Added TM.
Configuring Windows Internet Explorer 7 Security Lesson 5.
Configuring Windows Vista Security Lesson 8. Skills Matrix Technology SkillObjective DomainObjective # Setting Up Users Configure and troubleshoot parental.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Windows XP Service Pack 2 Technical Update. Windows XP Service Pack 2 Technical Workshop Agenda –Security Overview –Introduce Windows XP Service Pack.
Windows XP Service Pack 2 Alex Balcanquall Senior Consultant Microsoft Services Organisation.
11.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 9: Implementing and Using Group Policy.
Information for Developers Windows XP Service Pack 2 Information for Developers.
MCDST : Supporting Users and Troubleshooting a Microsoft Windows XP Operating System Chapter 15: Internet Explorer and Remote Connectivity Tools.
Windows Remote Administration
TCP/IP Tools Lesson 5. Objectives Skills/ConceptsObjective Domain Description Objective Domain Number Using basic TCP/IP commands Understanding TCP/IP3.6.
WebCCTV 1 Contents Introduction Getting Started Connecting the WebCCTV NVR to a local network Connecting the WebCCTV NVR to the Internet Restoring the.
EDDS Error Handling QP & Reliability Team. 2 EDDS Error Handling 1. In case of ‘Error code: -1’ (refer below captured error message ) EDDS system need.
SP2 Mikael Nystrom. Agenda Översikt Installation.
Security Flaws in Windows XP Service Pack 2 CSE /14/04 By: Saeed Abu Nimeh.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Microsoft Windows XP SP2 for Developers Rafal Lukawiecki Strategic Consultant Project Botticelli Ltd This session is based.
2851A_C01. Microsoft Windows XP Service Pack 2 Security Technologies Bruce Cowper IT Pro Advisor Microsoft Canada.
Using Application Compatibility Toolkit (ACT) 4.0 to Manage Application Compatibility on XP SP2 and Server SP1 Corey Hynes DSK304.
Microsoft ® Official Course Module 9 Configuring Applications.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
9.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
Module 7: Configuring TCP/IP Addressing and Name Resolution.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 9: Implementing and Using Group Policy.
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp
70-294: MCSE Guide to Microsoft Windows Server 2003 Active Directory Chapter 12: Deploying and Managing Software with Group Policy.
Tutorial 11 Installing, Updating, and Configuring Software
Using Windows Firewall and Windows Defender
COMPREHENSIVE Windows Tutorial 5 Protecting Your Computer.
®® Microsoft Windows 7 Windows Tutorial 5 Protecting Your Computer.
Course ILT Windows installation and upgrades Unit objectives Install a Windows operating system Upgrade from one version of Windows to another.
Troubleshooting Windows Vista Security Chapter 4.
Configuring Network Connectivity Lesson 7. Skills Matrix Technology SkillObjective DomainObjective # Using the Network and Sharing Center Use the Network.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
Network Management Tool Amy Auburger. 2 Product Overview Made by Ipswitch Affordable alternative to expensive & complicated Network Management Systems.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
Windows XP Professional Features ©Richard L. Goldman February 5, 2003.
C HAPTER 2 Introduction to Windows XP Professional.
Windows Vista Inside Out Ch 10: Ch 10: Security Essentials Last modified
Module 7: Managing the User Environment by Using Group Policy.
Module 5: Configuring Internet Explorer and Supporting Applications.
Remote Administration Remote Desktop Remote Desktop Gateway Remote Assistance Windows Remote Management Service Remote Server Administration Tools.
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
Module 4 Planning for Group Policy. Module Overview Planning Group Policy Application Planning Group Policy Processing Planning the Management of Group.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 1 Craig Schofield Microsoft Ltd. UK September.
Lesson 12: Configuring Remote Management
Deploying Software with Group Policy Chapter Twelve.
Module 10: Windows Firewall and Caching Fundamentals.
Configuring Network Connectivity Lesson 7. Skills Matrix Technology SkillObjective DomainObjective # Using the Network and Sharing Center Use the Network.
Module 8 Implementing Security Using Group Policy.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK
ITMT Windows 7 Configuration Chapter 7 – Working with Applications.
XPSP2 “Basic Gotchas” Security Center “Welcome” –May be confusing –Gives a “No Antivirus” warning for machines with SAV which have NOT been patched for.
11 SUPPORTING INTERNET EXPLORER IN WINDOWS XP Chapter 11.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Windows Tutorial 5 Protecting Your Computer
Module Overview Installing and Configuring a Network Policy Server
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Implementing Advanced Server and Client Security
Presentation transcript:

Changes in Windows XP Service Pack 2

Enhancements in XP SP2  Network Protection  Memory Protection (compatible cpu’s)  Safer handling  Enhanced Browsing Security  Improved Computer Maintenance

Services Disabled by Default  Messenger Service  Alerter Service

Updated / Modified Applications  Windows Media Player upgraded to v9  Windows Messenger security enhancements: - blocks unsafe file transfers - required user display name (different from address) - ports need to be opened through firewall  Outlook Express – plain text mode, more  Windows Installer v3.0

RPC / DCOM, other Changes  Anonymous RPC calls no longer allowed  DCOM computer level ACL  Configurable via Registry key  Better support for Bluetooth wireless devices

Major changes  Firewall turned on by default  IE Pop-Up blocker  IE runs in restricted mode  Installed patches not displayed by default (enabled via registry key)

Firewall Definition - electronic blocking mechanism that will not allow unauthorized intruders into a computer system The firewall in Windows XP will not block any traffic originated on the local system.

Quick Survey  Black Ice?  ZoneAlarm?  Symantec Firewall?  Tiny?  Other? SCS Computing Facilities will support the firewall bundled with WinXP SP2

Methods for configuring the Windows Firewall in XP-SP2  Group Policy .Inf file bundled with setup  Manual configuration  Netsh command line tool Example: netsh firewall show state

Group Policy Settings  GPO will be linked to the three Organizational Units where computers reside  Contain settings that allow the standard SCS Windows environment to function:  Backup Agents (local network scope)  Windows File Sharing (local network scope)  Remote Administration (Hyena),WMI (local network scope)  Common Internet Services (Http,FTP,Telnet,SSH)  Additional exceptions will be configurable by user

Group Policy Details Ports: 7 (Echo) 6050 (Arcserve Client Agent) 497 (Retrospect Client Agent) 1977 (TiBS Client Agent) 6000,177(udp) (X-Win32) 3389 Remote Desktop Windows File Sharing (NetBios Ports) Remote Management (WMI Ports) All ICMP Traffic

Configuring Exceptions

Configuring Exceptions # 2

Configuring Exceptions #3  Add a text description and specify port

Dynamic additions of exceptions Add an exception to the firewall when a newly installed application wants to listen on a port. Add an exception to the firewall when a newly installed application wants to listen on a port.

SCS Subnets – Local Scope /23 ( ) /22 ( ) /21 ( ) /19 ( ) /24 ( ) /24 ( )

Pop-Up Blocker Pop-up Blocker can be enabled by three different methods: Pop-up Blocker can be enabled by three different methods: Prompt at first occurrence. Prompt at first occurrence. A prompt appears before the first pop-up window appears that asks the customer to enable Pop-up Blocker. The Tools menu: In Internet Explorer, on the Tools menu, click Pop-up Blocker, and then click Block Pop-up Windows. Internet Options: In Internet Explorer, on the Tools menu, click Internet Options, click the Privacy tab, and then click Block pop-up windows. You can then click Options to configure Pop-up Blocker settings.

IE Restrictions  Configurable via Group Policy (TBD) Binary Behavior Security Restriction MK Protocol Security Restriction Local Machine Zone Lockdown Consistent Mime Handling Mime Sniffing Safety Feature Object Caching Protection Popup Management Scripted Window Security Restrictions Protection From Zone Elevation SecurityBand Restrict ActiveX Install Restrict FileDownload

IE prompt when downloading files, adding ActiveX controls, etc. Information Bar - used to bypass default settings in order to download files (AES), display pop-up windows, run unsigned scripts, etc. Information Bar - used to bypass default settings in order to download files (AES), display pop-up windows, run unsigned scripts, etc.

Tools for troubleshooting  Port Reporter Tool – useful for determining additional ports that may need to be opened.  Firewall Log: %systemroot%\winnt\win_FW.log

Additional Reading   Details on changes aspx?FamilyID=7bd948d7-b791-40b b84158c78&DisplayLang=en   Manually configuring the Firewall y/columns/cableguy/cg0204.mspx

Questions ???

Fall Software Changes  New Kerberos ticket manager (Kfw)  Updates versions of WinZip, Mozilla,X- Win32, OpenAFS (integrated with Kfw)