Safe to take XP without any SPs online?


Recommended Posts

My comment "No you can't get a virus from having an idle computer running. That's BS.", was meant towards running the PC and updating it while connected to the internet. Not visiting thousands of websites that are shady and then leaving it idle.

The worm doesn't come from the remote web server, but other compromised PCs on the same network. Pre-SP2, the firewall isn't on by default; couple that with known vulnerabilities in network-facing services and IP-scanning worms have a free lunch.

The issue with XP pre-SP2 was that the firewall didn't activate at the same time as the network connection, so there was a delay between network-on and firewall-on. This left a window of opportunity for the IP scanning worms to get in.

There was no firewall on by default in XP SP0.

And yes, XP can become infected by just sitting there as long as certain ports are accessible from the internet. Most people today have NAT gateways that do not allow any incoming connections by default, and in those cases you are safe. If you don't have that, install it without a network cable plugged in, and then install SP2 before going online.

I wouldn't use Windows XP without any service packs online. I remember in late 2004, early 2005 I formatted my laptop, installed Windows XP SP1, and connected to the internet to download SP2, and within seconds, was infected, so I had to reformat and reinstall.

Just slipstream SP3 onto a fresh install media. Less hassle/time wasted then :)

+1

Also bear in mind any version of XP without SP2 on the disc will not like being installed to a system with a PCI-e graphics card in it. Voice of experience here.

There was no firewall on by default in XP SP0.

And yes, XP can become infected by just sitting there as long as certain ports are accessible from the internet. Most people today have NAT gateways that do not allow any incoming connections by default, and in those cases you are safe. If you don't have that, install it without a network cable plugged in, and then install SP2 before going online.

Exactly, XP RTM (no Service Pack) can be infected without ever using the computer. Install it and leave it on for a bit and you'll be infected (try it in a VM if you don't trust me, just make sure it has direct access to the internet)

it aint safe to use xp without a service pack as you would be wormed and exploited within minutes but the safe thing to do is download sp3 and run it on the xp without sp but do it offline so that the os is safe from infection.i recall doing that and i got infected very fast so i learned to update while offline to prevent being infected, the mydoom and several exe infectors(don't recall the names)got in and i could not run any exe files so i had to format to fix it.

Download SP3 and then install XP and install SP3 and then go online.

I don't know if it is possible to directly install SP3. If not then download SP2 also and install SP2 before SP3.

Only connect to internet after SP3 is installed and then also run Windows Update and install all available updates.

You may also download and install an antivirus software before connection to internet.

  • 2 weeks later...

"I don't know if it still applies now, but I don't think it's just a case of FUD.

When worms such as Blaster etc. were prevalent you could be infected without doing anything."

Yeah if you were directly connected to the public net -- behind a NAT router then NO!! Unless some other machine on your local net got infected. It just seems asinine that 99% of the broadband users out there would not be behind a router.. Most every DSL connection gives the users a modem/router combo device vs just a modem.. So they are behind a nat, etc. If you are on cable -- your just plain stupid to not put your machine behind a router. There is no reason to directly connect your machine to the public net.

Its sad to see such a lack basic understanding of even how even basic worms work.

Unless your local network is hostile.. Its fine to get online with XP without a SP or firewall as long as your behind a router -- and you do not have the box in the DMZ ;)

But I would suggest the first thing you do is fully update the machine. A nat router will protect you from worms, but it won't protect you from exploits on sites you visit.

Why is nobody suggesting the obvious answer here? Install XP and then go immediately to Windows Update and grab the service packs before going to any other site. If you're really paranoid about it then run a virus scanner afterward. Or of course, if you're super paranoid then just do the second most obvious thing, which is what most other people are suggesting: download SP3 first and then load it on the XP machine before taking it online. There's also the option of copying your XP files and using something like nLite to slipstream SP3 (you can use command lines, too, but why bother when there are several free utilities that will do it for you?) and reburn it with SP3 integrated.

Why is nobody suggesting the obvious answer here? Install XP and then go immediately to Windows Update and grab the service packs before going to any other site. If you're really paranoid about it then run a virus scanner afterward. Or of course, if you're super paranoid then just do the second most obvious thing, which is what most other people are suggesting: download SP3 first and then load it on the XP machine before taking it online. There's also the option of copying your XP files and using something like nLite to slipstream SP3 (you can use command lines, too, but why bother when there are several free utilities that will do it for you?) and reburn it with SP3 integrated.
I guess you don't know what the blaster worm is then?

Darrian: if he really did that he would be infected as windows update in the past got exploited so to be safe make sure you got sp3 installer and install it offline then reconnect afterwards then at least your more up to date and safe until you fully update as lots of updates have been released after sp3 but that happens after every sp. if your offline you can't be infected unless your install is infected and the blaster worm was terrible as i recall that and a few others like the mydoom one.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Kind of glad I upgraded to S26 Ultra 1TB this year, with trade-in and discounts it cost me €1199, that's only €119 more than the S23 Ultra (256 GB) cost me. Last time I bought it via my phone provider outright, now via Samsung.com I reckon the S27 series will be more expensive too.
    • Save 66% on a MagTag Ultra Slim Tracker Card for Apple or Android by Steven Parker Never Lose Anything Again with MagTag Today's highlighted deal comes via our Gear + Gadgets section of the Neowin Deals store where you can save 66% on this MagTag Ultra Slim Tracker Card - Works with Apple Find My App. Keep track of your world with MagTag, a sleek, ultra-slim, reliable tracker that’s built to help you safeguard your most important items. In the size of a credit card, just 1.5mm thick, you can slip MagTag easily into your wallet, backpack, passport pouch luggage…etc. Integrated seamlessly with Apple’s FindMy app, MagTag offers precise real-time global tracking, instant left-behind alerts, loud location beeping, and a long-lasting rechargeable battery. Whether you’re heading to work, on vacation, or simply running errands, MagTag ensures you never lose what matters most. No item left behind Precision Global Tracking: Works seamlessly with the Apple FindMy app, providing real-time tracking anywhere in the world, powered by the vast Apple network. Ultra Slim Design: At just 1.5mm thick and the size of a credit card, MagTag slips easily into your wallet, passport pouch, backpack, or luggage. Instant Alerts: Receive notifications the moment you leave behind your valuables, and locate them easily with a loud beeping sound. Versatile Attachment Options: With a built-in keyring hole, attach MagTag to keys, ID lanyards, kids’ bags, or name tags for easy access and protection. Long Battery Life & Wireless Charging: Lasts up to 5 months on a single charge and can be easily recharged with any Qi wireless charger. Durable & Waterproof: IP68 waterproof and dustproof built to withstand your adventures, perfect for vacations and everyday use, no matter where life takes you. Specs Color: Black Materials: ABS Dimensions: 0.05" x 3.35" x 2.13" (1.5mm x 85mm x 54mm) Ultra-slim Apple FindMy App Built-in keyring hole Battery life: up to 5 months Charging: Qi wireless IP68 rating (waterproof, dustproof) Manufacturer's 90-day warranty Good to know Ships to US Expected Delivery: Expected Delivery: Jun 23 - Jul 2 All sales final. This item is excluded from coupons. Here's the deal: This MagTag Ultra Slim Tracker Card (for Apple or Android) normally costs $59.99, but you can pick it up for just $19.99 for a limited time - that represents a saving of $19. For a full description, specs, and shipping info, click the link below. MagTag Ultra Slim Tracker Card now just $19.99 (was $59.99) Get the two-pack and save 70% Ships only to Contiguous US Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • I cannot believe this is a news post from Neowin. This should be embarassing, coming from a "senior editor". Is it your first day using Windows?! Maybe it's time to find a new Windows news site.
  • Recent Achievements

    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      586
    2. 2
      +Edouard
      169
    3. 3
      PsYcHoKiLLa
      73
    4. 4
      Michael Scrip
      66
    5. 5
      ATLien_0
      64
  • Tell a friend

    Love Neowin? Tell a friend!