Official Windows XP SP2 New Features Overview


Recommended Posts

I had a training session for SP2 at work today. Here are some notes and screenshots I grabbed for the Neowin Community. Enjoy.

Official Windows XP SP2 New Features Overview

Overview of Key Changes

Service Pack 2 introduces a set of security technologies whose goal is to help improve the ability of Windows XP-based computers to withstand malicious attacks from viruses and worms.

The key technologies enhancements are:

Network Protection

Memory Protection

Safer E-Mail and Instant Messaging

Safer Browsing

Improved Computer Maintenance

Overview of Security Enhancements

The key technologies enhancements are:

Network Protection

Changes in Windows Firewall, RPC handling, and DCOM Control Restrictions

Memory Protection

Adds No Execute (NX) restrictions on processors that support it to enforce separation of application code and data

Safer E-Mail and Instant Messaging

Allows for more secure and reliable attachment control in Outlook Express and Windows Messenger

Safer Browsing

Enables better restrictions, user controls and interfaces with regard to Internet use that help prevent malicious code and spyware from running on systems without customer knowledge and consent

Improved Computer Maintenance

Helps customers monitor usage of latest security tools and allows for easier methods to keep system updated with the latest security patches and fixes.

Network Protection ? Windows Firewallb>

Previously known as Internet Connection Firewall in SP1 but was not turned on by default

Turned on by default in SP2

Boot time and shutdown protection

Multiple configuration options available via UI, group policy, command line, and unattended setup

RPC support and better control of RPC services exposed over the network

Global configuration for all connections making it easier to manage firewall policies across all network connectionsWindows Firewallb>

New UI easily accessible directly from Control Panel icon called Windows Firewall. Old location in Advanced tab of the network connection property?s dialog box will now have a link to the new UI.

Picture2.jpg

All outbound connections are automatically allowed, regardless of the program or user context.

E.g. Web browsing with Internet Explorer, checking email in Outlook Express

When an application makes an inbound connection that has been permitted by the user, the port(s) will be dynamically enabled as necessary, only for as long as necessary, and disabled again when done.

E.g. Hosting a game server, transferring files in Windows Messenger

When a service makes an inbound connection that has been permitted by the user, fixed ports will be statically open and remain open and should be limited to only traffic on the local subnet whenever possible.

E.g. File and Print Sharing, Universal Plug and Play (UPnP), Remote Desktop

When an application attempts to allow an inbound connection such as setting up a multiplayer game host, a security alert will be displayed that allows the user to configure the firewall permission for the application:

Picture3.jpg

Exceptions list is configurable list that allows users to specify which applications or services have permission to receive inbound connections from outside sources through the firewall.

Users can edit an application?s firewall properties or manually add applications to the exceptions list by browsing for it.

Picture4.jpg

Local Subnet Restriction ? By default, enabling permissions for services such as File and Print Sharing and Universal Plug and Play will only make ports available to other units on the same local subnet. This will help mitigate attacks from external sources.

Supports Multiple profiles and allows user to have separate firewall restrictions for different networks.

E.g. One profile for wired connection at work and another profile for a wireless hotspot connection on tNetwork Protection ? RPC and DCOMand DCOM

Changes done to help reduce RPC/DCOM attack surface exposed to network

Improved Remote Procedure Call (RPC) protection

Requires authenticated access

Executes with reduced privilege

Disabled over UDP by default

Improved Distributed Component Object Model (DCOM) protection

Greater restrictions when launching DCOM apps

Enhanced control over what DCOM apps are alloMemory Protection tection

The top security hole that MS has been attempting to address are buffer overruns which are vulnerabilities that allow too much data to be copied into areas of the computer?s memory

To help mitigate these types of attack, SP2 uses the No Execute Protection (NX) for systems that support it by using a computer?s microprocessor to separate application code from data

NX prevents code execution from data pages such as the default heap, various stacks, and memory pools. This helps protect from malicious code executing in memory.

NX support requires 64 bit processors (like AMD Hammer used in Diaz) or newer 32-bit processors with NX feature

SP2 automatically enables NX support when NX supported microprocessor is detected

Adds /noexecute parameter in Boot.ini to the boot partition that contains SP2

If exception is detected due to no execute protection, the process is typically either terminated or raises a bugcheck

Settings are configurable from System Properties > Advanced Tab > Performance Options.

This UI enables users to configure execution protection for either the entire computer or selectively disable execution protection for individual applications.

These options will be grayed out for units that do not support NX protection.

b].jpg

Security Center

Security Center analyzes current settings for Firewall, Automatic Updates, and Virus Protection.

Security Center will alert the user if any of these settings is not in the recommended state. Security Center will recommend users to enable a firewall, turn on Automatic Updates, and load an antivirus software.

Picture9.jpg

If any of the current security settings are not at the recommended level, Security Center warnings will appear in system tray and warn user of possible problems during start up or when the settings change.

New Security Center applet will be Additional Enhancementsel

Additional Enhancements

Alerter and Messenger services are now disabled by default

Windows Media Player 9

DirectX 9.0b

Windows Movie Maker 2.1

MSN Explorer 9

New BluetootZeroConfig Wirelessreless

ZeroConfig Wireless

New client that works with broad range of wireless hotspots

UI change to ?View Available Wireless Networks? to support additional branding and information about wireless hotspots.

Enables user to connect easier to wireless hotspots without having to install or update a 3rd party client.

Update to Network connections folder and system tray icon to allow users to easily disconnect from wireless hotspots

Picture10.jpg

The new UI for ?View Available Wireless Networks? shows security settings and signal strength of available hotspots

b]jpg

Major Risk Areas for SP2

Active X Lockdown

when an application or web site runs an ActiveX component in the incorrect Security Zone, the user will be warned and will have to grant permission for it to work properly

To prevent warning message, ISVs and OEMs will have to spin the software

Due to new security restrictions in SP2, majority of software using ActiveX components will have this problem.

HP Bluetooth originally had this problem as well but MS has inserted workaround to automatically permit it to load

HP Image Zone currently causes security warning and will not run until user permits it. Workaround to allow HP Image Zone is currently being investigated.

HP Bluetooth -

Installation of BT drivers will display two warning messages to users

First warning that driver is not signed

Second warning that recommends user check for a signed driver on Windows Update

Automatic Updates - installation of updates during shutdown could be problem because user may transport laptop before shutdown is complete potentially causing data loss or hard drive problems

New security restrictions detect that the majority of softpaq files for HP web deliverables have an unknown publisher and issues a security warning to the user that these fileSchedule and Buildstal signature.

Schedule and Builds

Beta 1 Build 2.055 was released on 12/16/03.

The current build in test is Build 2.094 which was released on 3/12/04.

The next targeted milestone is RC1 on 3/17/04.

RC2 is targeted for 4/30/04.

RTM is targeted for 5/28/04. MS is curreAddendument of meeting this date.

Addendum

Screen shots were captured from Build 2.089.

Since SP2 is still in a development phase, please be aware that some of the new UI?s and tools are still being modified and are subject to change prior to RTM.

All scheduled milestone dates are the current MS target dates and also subject to change.

How is this any different than just going to Microsoft's website to get the same type of information? Can we stop with all this service pack 2 crap? Anyone who hs been following it already knows about these features and most likely has already deployed them.

Give it a rest people..save the bandwidth

very nice. a few problems though:

"This will also held minimize the common problem of dial-up connections"

"NX support requires 64 bit processors (like AMD Hammer used in Diaz) or newer 32-bit processors with NX feature" < so processors with nx support then!

"DirectX 9.0b" < i thought 9.0c is going to be used. or am i wrong?

Anyway nice overview

Schedule and Builds

Beta 1 Build 2.055 was released on 12/16/03.

The current build in test is Build 2.094 which was released on 3/12/04.

The next targeted milestone is RC1 on 3/17/04.

RC2 is targeted for 4/30/04.

RTM is targeted for 5/28/04. MS is currently 90% confident of meeting this date

hahahahhahah, what Bull Sh**. :pinch:

Be the way, excellent review. :yes:

Just an addition, my trainer installed S2P over SP1 and SP1a with not a single issue. She uninstalled and re-installed it 15x just to make sure nothing went wrong and no files were left around or damaged.

She also uses Zone Alarm, a router and two other firewalls and the SP worked flawlessly with them.

Looks like MS might have gotten it right with this one (Y)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Did you watch the keynote? It is way beyond what is described in this article. Looks interesting. Now it is time for them to deliver unlike what happened in 24.
    • It pretty much has to be compatible with MS Office or it is going nowhere. The rest of the world runs office including Europe. If it is not compatible it will not survive.
    • Incredible deal gets you free NVMe 512GB SSD with AMD AM5 B850 motherboard for only $150 by Sayan Sen Earlier this week we covered the story of an interesting PC case wherein you can build two full-size computers inside it as in it can house and run an AMD and an Intel system simultaneously. Speaking of building PCs, these are hard times to make one for sure as prices are often very high except during flash sales or discounts. If you are in the market for a 1080p gaming PC then Nvidia's 8GB RTX 5060 Ti is currently on sale for just $330 and you get the latest James Bond game too, for free. Speaking of which, right now there is another incredible sale going on as we can get a free 512 GB NVMe SSD from TeamGroup in the form of the G50 alongside the purchase of an AMD B850 socket AM5 motherboard for only $150 (purchase link under the specs table down below). Getting an AM5 motherboard now in 2026 will be a wise investment for sure, especially since AMD confirmed its commitment to support the socket till at least 2029. The MSI PRO B850M-P WIFI is a micro-ATX motherboard that is compatible with AMD Ryzen 9000 series processors. Since it is AM5, the motherboard works with DDR5 memory and includes MSI’s Memory Boost technology, along with EXPO and XMP support. Connectivity features include built-in Wi-Fi 7 paired with a 5G LAN solution. The board offers a PCIe 5.0 M.2 slot with MSI’s EZ M.2 Shield Frozr II thermal solution, that is said to help maintain SSD performance by providing ample cooling against overheating. The technical specifications of the MSI PRO B850M-P WIFI motherboard are given in the table below: The free TeamGroup T-FORCE G50 NVMe SSD is a PCIe Gen4 and as such it promises to deliver sequential read speeds of up to 5,000 MB/s, helping accelerate game loading, file transfers, and everyday computing tasks. The SSD features an InnoGrit controller and SLC caching technology to support consistent performance. An ultra-thin, patented graphene heatsink is included to aid in heat dissipation. The NAND flash is based on TLC which means it has plenty of endurance up its sleeve. The random performance may not be as amazing as other drives with DRAM though. Still it should be very good since it can access system memory via HMB to use it as its DRAM cache. The technical specifications of the TeamGroup 512GB G50 NVMe SSD are given in the table below: Get it at the link below: MSI PRO B850M-P WIFI AM5 AMD motherboard + Team Group T-FORCE G50 512GB SSD (free gift): $149.99 (Sold and Shipped by Newegg US) This Newegg deal is US-specific and not available in other regions unless specified. This is a first-party seller link (at the time of article publishing); ensure that you also purchase from a first-party seller link only. If you don't like it or want to look at more options, check out the previous deals that we have covered, OR you can also visit Amazon US deals page. Get Prime (SNAP), Prime Video, Audible Plus or Kindle / Music Unlimited. Free for 30 days. As an Amazon Associate, we earn from qualifying purchases.
    • RapidRAW 1.5.7 by Razvan Serea RapidRAW is a beautiful, non-destructive, GPU‑accelerated RAW image editor designed for speed and simplicity. It uses a lightweight (~30 MB), efficient code base built with Rust, React and Tauri. Ideal for Lightroom workflows, it offers rich editing tools—exposure, contrast, highlights, shadows, whites/blacks, tone curves, HSL mixer, dehaze, vignetting, film grain, sharpening, clarity and noise reduction—processed in real-time on the GPU. Features include intuitive masking (brush, linear, radial, AI-powered subject and foreground detection), generative edit layers (via ComfyUI), 32‑bit precision, and full RAW format support through rawler. RapidRAW also provides library management (folder navigation, ratings, metadata, EXIF viewer), batch operations, export presets (JPEG/PNG/TIFF), sidecar editing (.rrdata), undo/redo history, customizable UI themes, smooth animations, resizable panels, and preset copy/paste. A modern high-performance Lightroom alternative with polished UX and creative tools, RapidRAW brings powerful photo editing to photographers seeking speed, responsive GPU feedback, and streamlined workflows. RapidRAW v1.5.7 release notes: This update serves as a direct follow-up to the core architectural migration introduced in v1.5.6. While the transition to a more modular state management system marked a significant step forward for RapidRAW's stability and long-term maintainability, it also introduced several edge cases and regressions within the library and editing workflows. This release focuses on addressing those issues, with a particular emphasis on a complete overhaul of library performance to ensure smooth and responsive browsing following the refactoring. It also resolves inconsistencies in the copy-and-paste workflow and expands RapidRAW's accessibility by adding support for eight additional languages. [full changelog] Download: RapidRAW 1.5.7 | ARM64 | ~20.0 MB (Open Source) View: RapidRAW Home Page | Screenshot | Other operating systems Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Thank god they got rid of the disgusting looking sidebars, and the corner radius looks much better, too. Two things I hated on day one, and never got used to.
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      PsYcHoKiLLa
      223
    3. 3
      ATLien_0
      87
    4. 4
      Steven P.
      80
    5. 5
      +Edouard
      80
  • Tell a friend

    Love Neowin? Tell a friend!