Windows XP Service Pack 2 Alex Balcanquall Senior Consultant Microsoft Services Organisation.

Slides:



Advertisements
Similar presentations
®® Microsoft Windows 7 for Power Users Tutorial 7 Enhancing Your Computers Security.
Advertisements

Desktop Value - Introducing Windows XP Service Pack 2 with Advanced Security Technologies Presenter: James K. Murray Title: Information Technologies Consultant.
Remote Desktop Services
Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Windows Server 2003 SP1. Windows Server™ 2003 Service Pack 1 Technical Overview Jill Steinberg: Added TM Jill Steinberg: Added TM.
1 of 5 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Windows XP Service Pack 2 Technical Update. Windows XP Service Pack 2 Technical Workshop Agenda –Security Overview –Introduce Windows XP Service Pack.
Changes in Windows XP Service Pack 2
Using Internet Information Server And Microsoft ® Internet Explorer To Implement Security On The Intranet HTTP.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment Chapter 10: Server Administration.
1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Kalpesh Patel Ramprabhu Rathnam
1 of 3 This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. © 2007 Microsoft Corporation.
Information for Developers Windows XP Service Pack 2 Information for Developers.
Module 6 Windows 2000 Professional 6.1 Installation 6.2 Administration/User Interface 6.3 User Accounts 6.4 Managing the File System 6.5 Services.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
VMware vCenter Server Module 4.
SP2 Mikael Nystrom. Agenda Översikt Installation.
Windows XP Service Pack 2 and the Microsoft Virtual Machine: Developer Implications Rudi Larno Developer & Platform Group Microsoft BeLux.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 2 Craig Schofield Microsoft Ltd. UK September.
Module 16: Software Maintenance Using Windows Server Update Services.
Choose and Book Installing Security Broker (IA) client.
Security Flaws in Windows XP Service Pack 2 CSE /14/04 By: Saeed Abu Nimeh.
Security of Communication & IT systems Bucharest, 21 st September 2004 Stephen McGibbon Chief Technology Officer, Eastern Europe, Russia & CIS Senior Director,
Microsoft Windows XP SP2 for Developers Rafal Lukawiecki Strategic Consultant Project Botticelli Ltd This session is based.
2851A_C01. Microsoft Windows XP Service Pack 2 Security Technologies Bruce Cowper IT Pro Advisor Microsoft Canada.
Microsoft October 2004 Security Bulletins Briefing for Senior IT Managers updated October 20, 2004 Marcus H. Sachs, P.E. The SANS Institute October 12,
Microsoft ® Official Course Module 9 Configuring Applications.
Working with Applications Lesson 7. Objectives Administer Internet Explorer Secure Internet Explorer Configure Application Compatibility Configure Application.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
Information for Developers Windows XP Service Pack 2 Information for Developers Tony Goodhew Product manager Developer Division Microsoft Corp

TUTORIAL # 2 INFORMATION SECURITY 493. LAB # 4 (ROUTING TABLE & FIREWALLS) Routing tables is an electronic table (file) or database type object It is.
A+ Guide to Managing and Maintaining Your PC Fifth Edition Chapter 15 Installing and Using Windows XP Professional.
Using Windows Firewall and Windows Defender
© 2012 The McGraw-Hill Companies, Inc. All rights reserved. 1 Third Edition Chapter 5 Windows XP Professional McGraw-Hill.
CN1260 Client Operating System Kemtis Kunanuraksapong MSIS with Distinction MCT, MCITP, MCTS, MCDST, MCP, A+
Course ILT Windows installation and upgrades Unit objectives Install a Windows operating system Upgrade from one version of Windows to another.
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
3-Protecting Systems Dr. John P. Abraham Professor UTPA.
DIT314 ~ Client Operating System & Administration CHAPTER 2 INTRODUCTION TO WINDOWS XP PROFESSIONAL Prepared By : Suraya Alias.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
CN1176 Computer Support Kemtis Kunanuraksapong MSIS with Distinction MCT, MCTS, MCDST, MCP, A+
SMS 2003 Deployment and Managing Windows Security Rafal Otto Internet Services Group Department of Information Technology CERN 26 May 2016.
IIS Security Sridurga Mavram. Contents -Introduction -Security Consideration -Creating a web page -Drawbacks -Security Tools -Conclusion -References.
OFC290 Information Rights Management in Microsoft Office 2003 Lauren Antonoff Group Program Manager.
C HAPTER 2 Introduction to Windows XP Professional.
70-290: MCSE Guide to Managing a Microsoft Windows Server 2003 Environment, Enhanced Chapter 10: Server Administration.
Compatibility and Interoperability Requirements
Module 5: Configuring Internet Explorer and Supporting Applications.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Windows XP Service Pack 2 Customer Awareness Workshop Trustworthy Computing – XP SP2 Technical Overview Craig Schofield Microsoft.
Windows XP Service Pack 2 Customer Awareness Workshop XP SP2 Technical Drilldown – Part 1 Craig Schofield Microsoft Ltd. UK September.
Information Security 493. Lab # 4 (Routing table & firewalls) Routing tables is an electronic table (file) or database type object that is stored in a.
Internet Explorer 7 Updated Advice for the NHS 04 February 2008 Version 1.3.
Windows Server 2003 SP1 Technical Overview John Howard, IT Pro Evangelist, Microsoft UK
ITMT Windows 7 Configuration Chapter 7 – Working with Applications.
1 BCS 4 th Semester. Step 1: Download SQL Server 2005 Express Edition Version Feature SQL Server 2005 Express Edition SP1 SQL Server 2005 Express Edition.
NETWORK SECURITY LAB 1170 REHAB ALFALLAJ CT1406. Introduction There are a number of technologies that exist for the sole purpose of ensuring that the.
Windows Vista Configuration MCTS : Internet Explorer 7.0.
Windows Vista Configuration MCTS : Network Security.
ArcGIS for Server Security: Advanced
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
Session Objectives And Key Takeaways
Implementing Client Security on Windows 2000 and Windows XP Level 150
Designing IIS Security (IIS – Internet Information Service)
Windows XP SP2 & Windows Server 2003 SP1
Using Software Restriction Policies
Implementing Advanced Server and Client Security
Presentation transcript:

Windows XP Service Pack 2 Alex Balcanquall Senior Consultant Microsoft Services Organisation

Agenda for Workshop Introduction Protection Technologies Network Web & Memory Protection Manageability But that’s not all… Deployment & Troubleshooting Round-up

Exploit Timeline Days From Patch to Exploit The average is now nine days for a patch to be reverse- engineered As this cycle keeps getting shorter, patching is a less effective defense in large organizations Why does this gap exist? Blaster Welchia/ Nachi Nimda 25 SQL Slammer exploit code patch Days between patch and exploit

Goals of XP SP2 Memory Network Maintenance /Web Provide system-level protection for the base operating system Help protect the system from directed attacks from the network Ensure that when updates are necessary, they are easier to deploy quickly Enable safer Internet experience for most common Internet tasks

Windows Firewall Goal in XP SP2   Provide better protection from network attacks   Provide administration tools suitable for the enterprise Changes in XP SP2   Windows Firewall on by default   Boot time protection   Multiple configuration mechanisms   Better user interface   Boot time protection   Multiple profile support   Restrict anonymous connections to DCOM/RPC interfaces Impact   Applications that initiate outbound connections will work out of the box   Only applications that accept unsolicited inbound communications will be affected by the firewall   Firewall should be deployed in all organisations   Develop organisation wide firewall exceptions & deploy as needed   Consider IPSEC bypass for administrative tasks Maintenance Network (1) & Web Memory

Windows Firewall

Windows Firewall Group Policy

DCOM / RPC Goal in XP SP2   Reduce DCOM / RPC attack surface exposed on the network Changes in XP SP2   Require authentication on default interfaces   Enable ability to restrict RPC interfaces to local machine only   Granular configuration of launch permissions for DCOM   Moved most RPCSS code into reduced privilege process   Disable RPC over UDP by default Impact Application using anonymous authentication will break Significantly reduces ability of unauthenticated processes or users to attack RPC May require applications and COM components to be recoded. Network (2) Maintenance & Web Memory

Attachments Goal in XP SP2   Consistent system-provided mechanism for applications to determine unsafe attachments   Consistent user experience for attachment “trust” decisions Changes in XP SP2   Create new public API for handling safe attachments (Attachment Execution Services)   Default to not trust unsafe attachments   Outlook Express, Windows Messenger, Internet Explorer changed to use new API   Open / execute attachments with least privilege possible   Safer message “preview” Impact   Select applications that use the new API for better user experience, and better determination of safe content   Applications which depend on attachments may be impacted Maintenance Network & Web (1) Memory

Web Browsing Goal in XP SP2   Ensure a safer web browsing experience Changes in XP SP2   Locking down local machine and local intranet zones   Improved notifications for running or installing applications and ActiveX Controls   Pop-Up Blocker for Internet Explorer   New Internet Explorer add-on manager   Limit UI spoofing   Change to IE zones   Improved download and security related dialog boxes Impact   Check for Web application compatibility with newer, safer browsing defaults   Line of Buisness applications that use pop-ups may need to change or be added to exception listNetwork & Web (2) Maintenance Memory

Pop-up Blocker

Download Prompts Old vs. New

Data Execution Protection (NX) Goal in XP SP2   Reduce exposure of common buffer overruns Changes in XP SP2   Leverage hardware support in 64-bit and newer 32-bit processors to only permit execution of code in memory regions specifically marked as execute   Binaries Compiled with /GS Flag (Not Dependent on DEP)   Reduces exploitability of buffer overruns   Enabled by default on all capable machines for Windows binaries   Application Compatibility Toolkit setting to exclude incompatible applications Impact   System runs in PAE mode. All drivers and application will need to be compatible with PAE   Currently needs 64bit Extended Systems (e.g. Intel Itanium Family, AMD Opteron, AMD Athlon 64) Maintenance Network & Web Memory

DEP End-user Experience Application termination dialogs

DEP End-user Experience Configuration experience Accessible through System Properties control panel

Manageability Goal   Reduce management overhead of securing Windows XP What we’re doing   Windows Security Center   Anti-Virus Checking   Firewall   Automatic Updates   Automatic Update enhancements   Centralised & granular management of the Windows Firewall   New Wireless LAN client   Bluetooth update   SmartKey Wireless Setup Impact   Use group policy or any software distribution mechanism to easily configure firewall Maintenance Network & Web Memory

Internet Explorer Add-on Manager

But that’s not all…. Tablet PC NEW V2 “Lonestar”. Tablet PC NEW V2 “Lonestar”. In Place Tablet Input Panel (TIP)& Handwriting to text on the fly Better office OneNote integration Windows Media 9 Series Bluetooth Update Movie Maker 2.1 New Wireless LAN Client Direct X9.0b

XP SP2 Deployment Planning and Testing

Why Plan & Test? New security features will make the system secure but may break some applications In common test scenarios expect >=90% of applications to work In RC1 these issues have been found to break down as follows: 30% Firewall 22% DEP / PAE 14% IE 8% DCOM / RPC 6% RTF Converters NB These figures are for consumer and corporate scenarios & fixes will be incorporated in the final XP SP2 Release to mitigate many scenarios

Deployment Planning Review XP SP 2 Changes Document Test XP SP 2 on limited ‘real systems’ Deploy with firewall on Determine commonly needed open ports Deploy settings with AD, INF files, WMI, Unattend.txt Deploy with XP SP2 DCOM and IE defaults Use custom OU if you have Active Directory Don’t forget to test all Intranet applications Deploy to test community to catch final 5% of issues START TESTING NOW!

Troubleshooting 32-Bit Applications 1. Test application on XP SP1 2. If 64bit Extended use Application Compatibility Toolkit to disable DEP on a per app basis 3. Disable Firewall  NOT RECOMMENDED FOR PRODUCTION MACHINES (deploy exceptions and keep firewall enabled) 4. Disable DCOM / RPC authentication  NOT RECOMMENDED FOR PRODUCTION MACHINES 5. Ask software vendor for any needed updates or patches 6. Consider risks of disabling protection vs. selection of alternate application

Troubleshooting Web Applications 1. Test on XP SP1 2. Add trusted intranet applications to trusted sites list 3. Sign all custom Active X objects 4. Review application to remove all cross zone scripting 5. Disable new IE protection measures to verify which protection is stopping application  NOT RECOMMENDED FOR PRODUCTION MACHINES 6. Consider re-writing application vs. risk of disabling new protection mechanisms

Other troubleshooting tools Application Compatibility Toolkit V3 Now V4 End of Dedicated to SP2 features etc. NB New ‘shims’ like the NX can be used with V3 toolkit Reporting RC 1 Bugs NEW desktop icon in RC1 Click on the “Report a XP SP2 Bug” Corporate Error Reporting If you have a Premier Agreement and Enterprise Agreement talk to your TAM about CER

Round-up XP SP2 has additional protection for: Network Web Browsing Memory Protection (64 bit only) XP SP2 Includes tools for improved manageability Adequate testing is key to successful deployment of XP SP2 Aim to deploy with Firewall Turned On Attend Infosec patch management session / review Microsoft recommendation on patching

Further Information XP SP2 /winxppro/maintain/winxpsp2.mspx General Security: Windows Application Compatibility Toolkit:

© 2004 Microsoft Corporation. All rights reserved. This presentation is for informational purposes only. Microsoft makes no warranties, express or implied, in this summary.