Kelvyn Taylor
Kelvyn Taylor

Tips for deploying Service Pack 2

Firms should take five steps to keep systems secure when installing SP2

Kelvyn Taylor

Although Service Pack 2 (SP2) for Windows XP has been widely available for weeks, it will be some time before many firms have tested it enough to be confident that full deployment is a good idea. The update has generally had favourable press, but in some cases it could cripple mission-critical apps.

For IT managers who want to go ahead with deployment now, I'm going to suggest five steps that should be taken first.

Advertisement

1. If you're worried about users running off with sensitive data downloaded onto a USB memory stick or MP3 player, the first thing you should do is make a change to the Registry on your users' systems. Change (or create) the key HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control \StorageDevicePolicies\WriteProtect and set the key's DWORD value to 1. This newly-implemented feature makes any USB storage devices read-only.

2. If you use Windows 2000 or earlier versions of Windows to remotely schedule tasks on Windows XP clients - for example by using the Windows command AT.EXE - make sure you install the latest service pack on those systems once the XP machines have been updated. SP2 increases the security of the RPC interface used by the Scheduler service. Hotfixes are available for those who can't install the full service packs. Check out the security bulletin at the first link below.

3. If you have users running Outlook Express, make sure they all take advantage of the new "Read all messages in plain text" option in the Tools/Options/Read menu tab. This will help prevent malicious code being downloaded via email formatted in HTML.

4. If your client PCs have the Windows Firewall enabled, be aware that the new version in SP2 blocks incoming network traffic on TCP port 445. This port is used for two system-generated dialog boxes widely used in the Client Administrative Tools MMC snap-ins. The dialog boxes are "Select Users, Computers or Groups" and "Find Users, Computers or Groups".

If TCP port 445 is blocked, you will likely get an obscure error message. To open the port on the client PC, open a command prompt and type "netsh firewall set portopening TCP 445 enable".

5. If you don't want to use Windows Firewall, you're going to have to turn it off on all your client PCs, as SP2 enables it by default. Some applications may not work with firewalls that perform stateful packet inspection. Fortunately, Microsoft has added a new command line tool - netsh - to Windows that allows you to change the state of the firewall via login scripts or remote management tools.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Neil Barrett

SP2 dumbs down security

Why downloading Windows XP SP2 might leave users with a sense of insecurity

Windows XP SP2

XP SP2: the business angle

What IT managers need to know about XP SP2

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation