Anatomy of the eight ultimate weapons in Windows XP SP2

  
        On August 6, 2004, Microsoft finally released XP SP2 to the computer manufacturer. This marks that XPSP2 has passed the final test, and the RTM (a version provided to the manufacturer) stage, the end user will gradually get XP in a few weeks. SP2.

And this is nine months late from the initial expected time, a year and a half away from the previous service pack for Windows XP. What is the most advanced XPSP2 in history, which is the ultimate weapon that has been long-awaited? Let us explore it together.

One of the ultimate weapons: Windows has a security manager

After installing XPSP2 for the first time, you can see this security center window (as shown in Figure 1), it is based on Web page application, where you can directly view the settings of the relevant security options and set them up.


Figure 1
Since most users don't know if their system is in a safe state, this leaves an opportunity for viruses or hackers to invade. The Windows Security Center monitors whether the system security components are working properly, and it can identify whether the Windows Firewall, Automatic Updates, and anti-virus software are working properly in the shortest amount of time.
For the normal setting, the security center will be displayed in green; if the corresponding option status is abnormal (for example, it is turned off or disabled), it will be marked in red; if the status is unknown, it will be marked in yellow (this is in anti-virus software) The options are more common, mainly because some anti-virus software may not be recognized by the system for some reason. But don't worry, it doesn't mean that the anti-virus software doesn't work or is incompatible with the system. The red warning and the yellow error just indicate anti-virus. The software cannot be viewed in the Security Center).
One thing to note is that although the firewall and anti-virus software can be set through the security center, these functions are not provided by the security center. The security center only plays a centralized management role.






































Figure 2
Since it is called Windows Firewall, then the function should be valid for the entire Windows and not just for the network connection. In fact, the Windows Firewall is a core security component in XPSP2, and it has become an indispensable security guard. Compared with the original ICF, there has been a significant improvement.
1. Global configuration, valid for all network connections. Change the problem that ICF must be configured separately for a single network connection.
2. Allow network connection configuration for an application (previous ICF is not acceptable), with the basic functions of the firewall.
3. Make it possible for network services to be effective in the specified network area. Windows Firewall can be divided into a range of network connections. For example, you can limit the scope of file and printer sharing to a network area (such as a subnet or IP range) that you specify, and computers outside this area cannot use the sharing feature.
4. Security protection at the start time. With previous Windows XP, there was a delay between when the computer entered the active state on the network and when the ICF began to protect the connection. This delay leaves an opportunity for unsolicited traffic to attack the computer during startup. Now, only DNS and DHCP are allowed during the startup process. Other network services must wait for the Windows firewall to work before it can be used. Hackers then want to attack at startup.
5. Windows Firewall also modified compatibility and can coexist peacefully with most programs.
Although Windows Firewall provides a lot of features, it is relatively thin compared to professional-level firewall software.
The ultimate weapon of the third: IE refuses to disturb to ensure stability
As the most used web browser, IE's function and security has been receiving a lot of attention.
1. Reject pop-up window interruptions
Prior to XPSP2, various ad pop-up window blocking plug-ins emerged in an endless stream, even Microsoft has added this feature in its own MSN Toolbar. Now, with XPSP2, these plugins can be discarded, because Microsoft has also added a blocking ad pop-up window in IE6SP2 (Figure 3).


Figure 3
2.Manage IE add-ons
In order to enjoy various conveniences when surfing the Internet, many users have installed various IE plug-ins, such as Flash ActiveX plug-ins. Wait. More plug-ins, Internet access may be very convenient, but if there are plug-ins "fighting" each other, IE will be overwhelmed, at any time on the verge of collapse. The "Add-on Management" feature has been added to IE6SP2 to control plugin conflicts.
For add-ons, you can install them or not, and you can disable them after installation. These settings can be easily done in the add-on management component (Figure 4).


Figure 4
3. Make sure the download file is safe
Security as XPSP2 release idea, it has also been reflected in IE6SP2. IE6SP2 will judge whether the downloaded file is masqueraded (MIME sniffing) according to its file content rather than the file extension, and according to the security of the downloaded file, a corresponding graphical warning prompt is given at the bottom of the download information dialog box.
In addition, security enhancements including locking local computer area, unauthorised ActiveX execution restrictions, digital signature control, MSJVM security settings, and IE binary behavior security settings have also been added. Inside XPSP2.
Although XPSP2 provides a number of security settings, but for compatibility, many security settings are not enabled by default, you need to edit the registry or modify the group policy to use. Fortunately, Microsoft has provided a number of guiding articles on XPSP2 security settings on its website. It is not difficult to enable these security settings.
Tips: Add-ons
Various programs that add functionality to the browser. Such as extra toolbars, animated mouse pointers, etc. The common MSN Toolbar is in the scope of add-ons.
Ultimate Arms 4: OE Protection New Ways
Outlook Express (OE) bundled with IE is a good email software, but it is widely criticized. Some people think that because OE is not perfect, it is very easy to spread and spread the virus, but the OE after installing XPSP2 is a lot safer.
1. Avoid malicious code being inadvertently executed
In the past, OE will display all messages directly in Html format, so if the email contains malicious code, it may directly infect the computer when viewing or previewing the email. In XPSP2, Microsoft uses the Richedit control instead of the original MSHtml control to read messages of plain text type, avoiding malicious code being inadvertently executed.
2. Avoid exposing your email address
OE has also added a new feature that first appeared in Outlook 2003, which prohibits downloading images from the Internet. As we all know before, if you receive spam, you must not reply, because the sender just sends the email to the randomly generated address, but does not know if the address is true. Once you reply to the email sent to you, it is tantamount to The sender announces your existence. Everyone remembers this very firmly, but now spammers have new tricks.
This new trick is through a special picture, which may be a normal picture in the mail, or an invisible picture of 0x0 pixels. The particularity of the image is that it is stored directly on the server and has a unique file name (for example, billgatesATmicroosftDOTcom.gif). This file name represents the E-mail address of the recipient of each message sent. In this way, once you receive and display the email, OE will automatically download the image from the web server, the download process will be recorded by the server, and the sender will know which mailbox is in use (because no one The mail in the mailbox used will not be viewed, and the image file will not be downloaded).
Now OE can display the email in Html format without downloading the image, so you can view the email without worrying about exposing your presence. Of course, if you are sure that a message will not have this problem, you can also click on the text of the prompt and download the image (as shown in Figure 5).


Figure 5
Ultimate weapon five: system update is no longer difficult
Windows security is often based on various patches. Perhaps in order to make Windows more secure, in XPSP2, Microsoft upgraded "automatic update" from a normal component to a key component of system security.
The new version of the automatic updater will be able to provide security updates, critical updates, cumulative updates, and downloads of service packs. In addition, with the upcoming Windows Update Services suite, enterprise administrators can easily distribute a variety of patches.
The WindowsUpdate website is probably the most visited patch download site for most people. The V5 version of WindowsUpdate is fully enabled in XPSP2 (as shown in Figure 6), and the new version of Windows Update divides the update into two levels: fast and custom. The quick install mode only downloads important updates, while the custom update mode allows you to customize the required updates. In addition, the V5 version of WindowsUpdate allows hidden updates, and users can hide them for unwanted updates. The next time you access WindowsUpdate, you will no longer be prompted to install hidden updates.


Figure 6
In order to save the patch download time, XPSP2 optimizes the transmission mode, and can download only the changed file part at the specified time and in the specified bandwidth working mode, and support the disconnection. Continue to pass.
If you are very busy and ignore the reminder of the automatic update program, you will find a new gadget when you shut down, and a new icon is added to the shutdown button, which means the system is pressed after pressing this button. The patch will be installed first and then automatically shut down. Adding this feature is equivalent to saying that the Windows update function has no special care, download and installation can be done automatically in the background.
The new patch release method plus the new automatic installation method before shutdown, I believe that most people can get the patch in the shortest time. With new patches, system security has been further improved.
Ultimate weapon

Copyright © Windows knowledge All Rights Reserved