Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2004

What You Need to Know About Windows XP Service Pack 2


RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

When Microsoft released Windows XP Service Pack 1 (SP1) less than a year after the initial XP release, many users and administrators assumed that the company was settling into a comfortable, once-a-year service pack schedule. Indeed, Microsoft originally intended to release XP SP2 in late 2003, roughly a year after SP1, and that service pack would have included the standard set of fixes Microsoft had released since SP1.

However, in the days since Microsoft released XP SP1, the security climate has changed dramatically, and Microsoft has recast XP SP2 as a more comprehensive, safety-oriented release that, as a result, won't ship until the first half of 2004. Here's what you need to know about XP SP2.

Safety Technologies
In addition to the usual collection of security and bug fixes, XP SP2 will include a vast suite of security features—what Microsoft calls safety technologies—that are designed to make the underlying XP platform safer than ever. First, XP SP2 will ship with an improved Internet Connection Firewall (ICF) program that will be enabled by default. This version of ICF includes support for Group Policy; command-line, scripting, and unattended installation; and support for multiple profiles, enabling different settings for home and work.

XP SP2 will also change the way XP handles email attachments in Microsoft Outlook Express and will provide third-party email applications and new APIs to access those attachment-blocking features. Similar to the default attachment-blocking behavior in Microsoft Office Outlook 2003, Outlook Express won't trust any email attachments by default and will open or execute attachments with the least possible privileges.

XP SP2 will also include a new version of Microsoft Internet Explorer (IE—expected to be IE 6.05) that will be similar to the locked-down IE version that ships in Windows Server 2003. The new IE version will lock down the local machine zone and will block unknown and unsigned ActiveX controls.

Finally, XP SP2 will include new memory-protection technology that should thwart most buffer-overrun attacks. Based on features in modern Intel and AMD 32-bit and 64-bit processors, this technology, called no execute (NX), prevents code from running in the data areas of your system's RAM.

Patching Improvements
One of the biggest complaints users have about Microsoft product updates is that they're difficult to roll out, especially in large enterprises. For this reason, XP SP2 will be the first major release in a new series of patches that will include common command-line options across installers, support for rolling back update installations, and reduced rebooting. Under this new plan, Microsoft will release patches on a more regular schedule. To test this new scheme, the company started issuing critical security patches on a monthly basis in late 2003.

Widespread Adoption
Because of its pervasive security changes, some of which will require changes to third-party applications and end-user behavior, Microsoft expects XP SP2 to be widely deployed in virtually all markets. To this end, the company began courting application developers and Web developers in late 2003 to encourage them to make changes to their products so that the products would work properly in XP SP2.

Microsoft is launching a global education and training initiative to get end users and administrators up to speed on the benefits and changes in XP SP2. This initiative includes documentation such as technology summaries, step-by-step user guides, and prescriptive guidance for administrators, chief technology officers (CTOs), and IT professionals; security seminars on TechNet; and monthly security Webcasts.

Recommendations
XP SP2 will likely be one of the most important platform releases Microsoft has made in some time, and because of the numerous changes SP2 makes to XP security, all enterprises and businesses should consider upgrading to this release as soon as possible. But because XP SP2 isn't expected until May or June 2004, you still have plenty of time to evaluate the changes and determine what effect, if any, the changes will have on your products and users. Even if your corporation typically waits before deploying service packs, you should get involved with the XP SP2 beta process so that you can thoroughly evaluate the product before its release. This is one service pack that enterprises will want to be prepared for and implement quickly.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Friday at PASS Europe 2006

Kevin talks about the closing day of the event and shares a funny Microsoft film. ...

Escape From Yesterworld

Kevin points you to the funniest SQL Server website ever! ...

PsExec

This freeware utility lets you execute processes on a remote system and redirect output to the local system. ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Introduction to Identity Lifecycle Manager "2"

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing