Safe to take XP without any SPs online?


Recommended Posts

My comment "No you can't get a virus from having an idle computer running. That's BS.", was meant towards running the PC and updating it while connected to the internet. Not visiting thousands of websites that are shady and then leaving it idle.

The worm doesn't come from the remote web server, but other compromised PCs on the same network. Pre-SP2, the firewall isn't on by default; couple that with known vulnerabilities in network-facing services and IP-scanning worms have a free lunch.

The issue with XP pre-SP2 was that the firewall didn't activate at the same time as the network connection, so there was a delay between network-on and firewall-on. This left a window of opportunity for the IP scanning worms to get in.

There was no firewall on by default in XP SP0.

And yes, XP can become infected by just sitting there as long as certain ports are accessible from the internet. Most people today have NAT gateways that do not allow any incoming connections by default, and in those cases you are safe. If you don't have that, install it without a network cable plugged in, and then install SP2 before going online.

I wouldn't use Windows XP without any service packs online. I remember in late 2004, early 2005 I formatted my laptop, installed Windows XP SP1, and connected to the internet to download SP2, and within seconds, was infected, so I had to reformat and reinstall.

Just slipstream SP3 onto a fresh install media. Less hassle/time wasted then :)

+1

Also bear in mind any version of XP without SP2 on the disc will not like being installed to a system with a PCI-e graphics card in it. Voice of experience here.

There was no firewall on by default in XP SP0.

And yes, XP can become infected by just sitting there as long as certain ports are accessible from the internet. Most people today have NAT gateways that do not allow any incoming connections by default, and in those cases you are safe. If you don't have that, install it without a network cable plugged in, and then install SP2 before going online.

Exactly, XP RTM (no Service Pack) can be infected without ever using the computer. Install it and leave it on for a bit and you'll be infected (try it in a VM if you don't trust me, just make sure it has direct access to the internet)

it aint safe to use xp without a service pack as you would be wormed and exploited within minutes but the safe thing to do is download sp3 and run it on the xp without sp but do it offline so that the os is safe from infection.i recall doing that and i got infected very fast so i learned to update while offline to prevent being infected, the mydoom and several exe infectors(don't recall the names)got in and i could not run any exe files so i had to format to fix it.

Download SP3 and then install XP and install SP3 and then go online.

I don't know if it is possible to directly install SP3. If not then download SP2 also and install SP2 before SP3.

Only connect to internet after SP3 is installed and then also run Windows Update and install all available updates.

You may also download and install an antivirus software before connection to internet.

  • 2 weeks later...

"I don't know if it still applies now, but I don't think it's just a case of FUD.

When worms such as Blaster etc. were prevalent you could be infected without doing anything."

Yeah if you were directly connected to the public net -- behind a NAT router then NO!! Unless some other machine on your local net got infected. It just seems asinine that 99% of the broadband users out there would not be behind a router.. Most every DSL connection gives the users a modem/router combo device vs just a modem.. So they are behind a nat, etc. If you are on cable -- your just plain stupid to not put your machine behind a router. There is no reason to directly connect your machine to the public net.

Its sad to see such a lack basic understanding of even how even basic worms work.

Unless your local network is hostile.. Its fine to get online with XP without a SP or firewall as long as your behind a router -- and you do not have the box in the DMZ ;)

But I would suggest the first thing you do is fully update the machine. A nat router will protect you from worms, but it won't protect you from exploits on sites you visit.

Why is nobody suggesting the obvious answer here? Install XP and then go immediately to Windows Update and grab the service packs before going to any other site. If you're really paranoid about it then run a virus scanner afterward. Or of course, if you're super paranoid then just do the second most obvious thing, which is what most other people are suggesting: download SP3 first and then load it on the XP machine before taking it online. There's also the option of copying your XP files and using something like nLite to slipstream SP3 (you can use command lines, too, but why bother when there are several free utilities that will do it for you?) and reburn it with SP3 integrated.

Why is nobody suggesting the obvious answer here? Install XP and then go immediately to Windows Update and grab the service packs before going to any other site. If you're really paranoid about it then run a virus scanner afterward. Or of course, if you're super paranoid then just do the second most obvious thing, which is what most other people are suggesting: download SP3 first and then load it on the XP machine before taking it online. There's also the option of copying your XP files and using something like nLite to slipstream SP3 (you can use command lines, too, but why bother when there are several free utilities that will do it for you?) and reburn it with SP3 integrated.
I guess you don't know what the blaster worm is then?

Darrian: if he really did that he would be infected as windows update in the past got exploited so to be safe make sure you got sp3 installer and install it offline then reconnect afterwards then at least your more up to date and safe until you fully update as lots of updates have been released after sp3 but that happens after every sp. if your offline you can't be infected unless your install is infected and the blaster worm was terrible as i recall that and a few others like the mydoom one.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I agree with what I think you are saying, just not in the way you are saying it. Like any tool, the amount it represents your work is perorational to the effort you put into it. It is similar to why 2nd grade math students learning to add and subtract are not allowed to use calculators, but a high-school calculous student is. For the 2nd grader, that tool would completely replace the work they are doing, for the calculous student the same tool allows them to work far more effectively while in no way replacing their effort or knowable. If you spend 30 seconds writing a prompt, then the image that comes out is no more "yours" than if you found the same image with a Google Image search. However, many of these generative tools also support highly iterative processes that allow back and forth, and merging generated images with photos or human created images. I am sure you would agree that a human spending hours of time working on a project, even if AI was involved in the process, still reflects that human's work.
    • Windows 11 version 26H2 is now available for testing in the latest preview build by Taras Buria Friday Windows 11 preview builds are here. Insiders in the Experimental (formerly Dev) and Beta Channel can download builds 26300.8697 and 26220.8690. There are no new features, but Microsoft is officially moving the Experimental Channel to version 26H2. In addition, Microsoft is improving the copy dialog in File Explorer, the Start menu reliability, and fixing virtualization issues. Here is the changelog: [General] With today’s build, Windows Insiders in the Experimental channel will see the versioning updated under Settings > System > About (and winver) to version 26H2. For more information, see the Windows Insiders blog. [File Explorer] We’ve improved the visual consistency and reliability of the Copy dialog in Dark mode, including its launch experience and the expanded progress view. [Start menu] - Also available in Beta Improved reliability of Start menu reflecting newly installed or removed apps without requiring sign-out or restart. [Taskbar] Fixed an issue for Insiders using the new smaller taskbar option, where the system tray might get cut off or pushed off screen. [Settings] - Also available in Beta Improved reliability of Settings > Apps > Startup. [Virtualization] - Also available in Beta This update addresses an issue that could result in bugchecks citing HYPERVISOR_ERROR (0x20001) and KMODE_EXCEPTION_NOT_HANDLED (0x1E) errors after installing the latest flights on some devices during system restarts, virtual machine operations, or while running some gaming applications. You can find the official changelog for the Experimental build here and for the Beta build here.
    • I've always preferred this possibility. There is something that feels good about the idea that all matter in the universe will eventually come back together and maybe even result in another big bang. The idea that the universe would fizzle out over the eons and forever drift apart is a little depressing. I realize it is not logical to let a basic human desire for life to have a grand everlasting meaning change the way I feel about a scientific theory, but I am human, so that is how I feel :-).
    • Windoze 11 could finally go to hell, instead of making me savor yet another error I've never had. "Bad Pool Caller" or whatever TF cryptic crap0la message it is. Adding salt to injury, it says something along these lines (on the blank black screen after it hard stops): "Your windoze needs to restart. You can restart." NO WAY SHERLOCK. The PEECEE, look, it's *blocked*, I can do jack sh1t with it as it is and you say that it needs to restart? Further, that I can restart? What am I supposed to do, take a herbal bath? Sudo a sandwich? Timewaster pile of useless slop and errors, coded by monkeys and force-fed on us by a pedo-founded corporation, that's all there is to it. Now, let's have a fun weekend trying to handle the error, which after a quick internet check can basically be due to EVERYTHING, from memory faults to drivers to motherboard issues. Thanks M$.
    • Zen Browser 1.21.3b by Razvan Serea Zen Browser is a privacy-focused, open-source web browser built on Mozilla Firefox, offering users a secure and customizable browsing experience. It emphasizes privacy by blocking trackers, ads, and ensuring your data isn't collected. With Zen Mods, users can enhance their browser experience with various customization options, including features like split views and vertical tabs. The browser is designed for efficiency, providing fast browsing speeds and a lightweight interface. Zen Browser prioritizes user control over the browsing experience, offering a minimal yet powerful alternative to traditional web browsers while keeping your online activity private. Zen Browser’s DRM limitation Zen Browser currently lacks support for DRM-protected content, meaning streaming services like Netflix and HBO Max are inaccessible. This is due to the absence of a Widevine license, which requires significant costs and is financially unfeasible for the developer. Additionally, applying for this license would require Zen to be part of a larger company, similar to Mozilla or Brave. Therefore, DRM-protected media won't be supported in Zen Browser for the foreseeable future. Zen Browser offers features that improve user experience, privacy, and customization: Privacy-Focused: Blocks trackers and minimizes data collection. Automatic Updates: Keeps the browser updated with security patches. Zen Mods: Customizable themes and layouts. Workspaces: Organize tabs into different workspaces. Compact Mode: Maximizes screen space by minimizing UI elements. Zen Glance: Quick website previews. Split Views: View multiple tabs in the same window. Sidebar: Access bookmarks and tools quickly. Vertical Tabs: Manage tabs vertically. Container Tabs: Separate browsing sessions. Fast Profile Switcher: Switch between profiles easily. Tab Folders: Organize tabs into folders. Customizable UI: Personalize browser interface. Security Features: Inherits Firefox’s robust security. Fast Performance: Lightweight and optimized for speed. Zen Mods Customization: Deep customization with mods. Quick Access: Easy access to favorite websites. Open Source: Built on Mozilla Firefox with community collaboration. Community-Driven: Active development and feedback from users. GitHub Repository: Contribute and review the source code. Zen Browser 1.21.3b changelog: New Features Updated to Firefox 152.0.1 Fixes Fixed transparency not working after updating to 1.21.2b (#14259) Fixed frequent crashes affecting users with Intel Raptor Lake processors Fixed an issue on macOS where choosing a PDF option, such as "Save as PDF", from the system print dialog would send the job to your printer instead of saving a file. Other minor bug fixes and improvements. Download: Zen Browser | 90.2 MB (Open Source) Download: Zen Browser ARM64 | Other Operating Systems View: Zen Browser Home Page | Screenshots 1 | 2 | Reddit Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Collaborator
      ryansurfer98 went up a rank
      Collaborator
    • Week One Done
      Eurosoft10 earned a badge
      Week One Done
    • One Month Later
      Eurosoft10 earned a badge
      One Month Later
    • One Year In
      Skeet Campbell earned a badge
      One Year In
    • One Month Later
      Sharbel earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      577
    2. 2
      +Edouard
      190
    3. 3
      Michael Scrip
      77
    4. 4
      PsYcHoKiLLa
      76
    5. 5
      Steven P.
      73
  • Tell a friend

    Love Neowin? Tell a friend!