Kelvyn Taylor
Kelvyn Taylor

Tips for deploying Service Pack 2

Firms should take five steps to keep systems secure when installing SP2

Kelvyn Taylor

Although Service Pack 2 (SP2) for Windows XP has been widely available for weeks, it will be some time before many firms have tested it enough to be confident that full deployment is a good idea. The update has generally had favourable press, but in some cases it could cripple mission-critical apps.

For IT managers who want to go ahead with deployment now, I'm going to suggest five steps that should be taken first.

Advertisement

1. If you're worried about users running off with sensitive data downloaded onto a USB memory stick or MP3 player, the first thing you should do is make a change to the Registry on your users' systems. Change (or create) the key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control \StorageDevicePolicies\WriteProtect and set the key's DWORD value to 1. This newly-implemented feature makes any USB storage devices read-only.

2. If you use Windows 2000 or earlier versions of Windows to remotely schedule tasks on Windows XP clients - for example by using the Windows command AT.EXE - make sure you install the latest service pack on those systems once the XP machines have been updated. SP2 increases the security of the RPC interface used by the Scheduler service. Hotfixes are available for those who can't install the full service packs. Check out the security bulletin at the first link below.

3. If you have users running Outlook Express, make sure they all take advantage of the new "Read all messages in plain text" option in the Tools/Options/Read menu tab. This will help prevent malicious code being downloaded via email formatted in HTML.

4. If your client PCs have the Windows Firewall enabled, be aware that the new version in SP2 blocks incoming network traffic on TCP port 445. This port is used for two system-generated dialog boxes widely used in the Client Administrative Tools MMC snap-ins. The dialog boxes are "Select Users, Computers or Groups" and "Find Users, Computers or Groups".

If TCP port 445 is blocked, you will likely get an obscure error message. To open the port on the client PC, open a command prompt and type "netsh firewall set portopening TCP 445 enable".

5. If you don't want to use Windows Firewall, you're going to have to turn it off on all your client PCs, as SP2 enables it by default. Some applications may not work with firewalls that perform stateful packet inspection. Fortunately, Microsoft has added a new command line tool - netsh - to Windows that allows you to change the state of the firewall via login scripts or remote management tools.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Neil Barrett

SP2 dumbs down security

Why downloading Windows XP SP2 might leave users with a sense of insecurity

Windows XP SP2

XP SP2: the business angle

What IT managers need to know about XP SP2

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

Google Chrome

Microsoft has no need to worry about Chrome OS

Redmond may actually welcome the new arrival

Dr Aladdin Ayesh

Is it time for the Turing Test to retire?

It is nearly 60 years since Alan Turing devised a...

Security double standards

Broadband provider Tiscali has launched new figures showing an alarming...

Beach

Top 10 holiday gadgets

A wry look at the must-have beach items for any...

Primary Navigation