<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"><channel><title>THE OFFICIAL BLOG OF THE SBS "DIVA" : XP2</title><link>http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx</link><description>Tags: XP2</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>No I really haven't lost my mind..</title><link>http://msmvps.com/blogs/bradley/archive/2005/09/01/65034.aspx</link><pubDate>Thu, 01 Sep 2005 22:34:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:65034</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=65034</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=65034</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/09/01/65034.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;So I'm googling for some info to get a 98 attached to a SBS 2003 box for ...what else... a beancounter.&amp;nbsp; A beancounter that SHOULD be signed up for the &lt;A href="http://www.microsoft.com/mpan"&gt;Microsoft's Accountant Network&lt;/A&gt; and not forcing his IT guy to jump through hoops as he'll be able to get Win XPs' and his 98 desktop won't SCREAM&amp;nbsp; &amp;#8220;I don't care about the security of my data&amp;#8221; to every client that walks by... so anyway I googled this...&amp;nbsp; and here's the funny thing... when I emailed it of to the person asking for it... it bounced back...&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;Your e-mail was rejected by an anti-spam content filter on gateway.&amp;nbsp; Reasons for rejection may be: obscene language, graphics, or spam-like characteristics.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You know... I think I quite agree ... having Windows 98 info inside of an email is obscene isn't it?&amp;nbsp; Especially in a SBS 2003 network... it just works soooooo nicely on XP... Remote Web Workplace... man you just do not know what you are missing out on when you don't have XP sp2 on that network....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;Definitely I think I agree with the spam filter... definitely obscene to put a 98 on a SBS 2003 network.&amp;nbsp; It's like making an Indy 500 race car driver drive an... oh I don't know...an Edsel or something...&lt;/FONT&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;PRE wrap=""&gt;&lt;P align=center&gt;&lt;SPAN&gt;&lt;FONT size=1&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;Make sure that you specify WINS as the internal ip address of the server.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial&gt;&lt;FONT size=1&gt;&lt;SPAN&gt;Also, if using DHCP, enable the support for updating to DDNS, for all &lt;/SPAN&gt;&lt;SPAN&gt;legacy clients, &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;by entering the DNS tab in the properites of the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;server.domain.local in the DHCP Console.&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;The supported client OS for SBS 2K3 is Windows 98, Windows 2K, Windows 2K3&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;and Windows XP Pro edition. Windows 95, Windows Millennium are not officially&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;supported in Windows 2003 (which includes SBS 2K3) environment&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;although&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;you may be able to join them into the domain&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;Please also note that although you can use a Windows 98 clients in the&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;domain, they won't have full functionality (won't have full functionality&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;of WSS/companyweb either due to not being able to use Office 2003,) and you&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;will have to manually configure clients networking&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;configure it to logon to the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;2003 domain (you &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;will not be able to join the Win98 clients to the domain &lt;/FONT&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;by using the &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;"connectcomputer" web site).&lt;SPAN&gt;&amp;nbsp; &lt;/SPAN&gt;In addition, there are many&lt;/FONT&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt; other issues with &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;legacy clients as mentioned in: &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;823659"&gt;823659 Client, Service, and Program&lt;/A&gt;&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;823659"&gt;Incompatibilities That May Occur When You -&lt;/A&gt;&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;.&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;It is also recommended that you install the updated DSclient (the one&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;included in the SBS 2K3 setup CD cannot be installed on 98 clients) on the 98 clients.&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;More detailed information can be found in the KB article below:&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;323466 Availability of the Directory Services Client Update for Windows 95&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;and &lt;/FONT&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;323455"&gt;&lt;FONT face=Arial size=1&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;323455&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=1&gt; &lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;226144 NetBIOS Domain Name Field Has a 15 Character Length Limitation -&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;226144"&gt;&lt;FONT face=Arial size=1&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;226144&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=1&gt; &lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;After installing the updated DSclient on 98 clients (you may need to wait&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;for some time after the 9x clients' start until the computer lists are&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;synced,) I can then view and share the shared computers in 'Network&lt;/FONT&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;FONT face=Arial size=1&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT face=Arial size=1&gt;Neighborhood' &amp;#168;&amp;#164; Entire Network &amp;#168;&amp;#164;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=65034" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Why doing a clean install of Windows XP is a good thing..</title><link>http://msmvps.com/blogs/bradley/archive/2005/08/07/61994.aspx</link><pubDate>Mon, 08 Aug 2005 02:26:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:61994</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=61994</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=61994</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/08/07/61994.aspx#comments</comments><description>&lt;P&gt;&lt;!--StartFragment --&gt;&lt;FONT face=Arial size=2&gt;You cannot find options under "Use Extensible Authentication Protocol (EAP)" on a computer that you upgraded from Windows 2000 Service Pack 4 to Windows XP with Service Pack 1 or Service Pack 2: &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?scid=kb;en-us;902934"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;902934&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;It's Knowledge base articles like that that make us recommend clean installs on Windows XP.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;That said... I have to admit that I'm sitting here typing this up on my clunker machine of XP sp2 while my new spiffy super dooper SATA harddrive machine is sitting over there with it's side off waiting for me to hang one of these harddrives on this machine inside that machine to make it easier to migrate the 'profile' data.&amp;nbsp; Once upon a time we could just copy the 'wack' folder from one system to another and everything would just magically work.&amp;nbsp; But then someone invented...the registry.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Yes the same registry that the &lt;A href="http://www.microsoft.com/technet/scriptcenter/tools/wmimatic.mspx"&gt;Scriptomatic&lt;/A&gt; guys joke that you are always reminded in KB articles that oh if you muck with this sucker you could blow up New Orleans in the process if you aren't careful.&amp;nbsp; I think the problem that we all have with people not wanting to migrate up to Windows XP sp2 from what they have because what they have is 'good enough'...I think it's also a problem of migration is still ...even with the &lt;A href="http://www.microsoft.com/windowsxp/using/setup/expert/crawford_november12.mspx"&gt;file and transfer wizard&lt;/A&gt;...isn't good enough.&amp;nbsp; I know in my own office, if Word has a funky macro in the old machine and the new one isn't IDENTICAL, I'll end up with a messy normal.dot or a macro template that I muck around for hours trying to get back out of the newly built system.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;..one of these days I'll be on my new super dooper computer....just probably.... well most definitely...not today....&lt;/P&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=61994" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Rants/default.aspx">Rants</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Sorry Amazon.com, it wasn't you after all</title><link>http://msmvps.com/blogs/bradley/archive/2005/06/06/50883.aspx</link><pubDate>Mon, 06 Jun 2005 22:19:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:50883</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=50883</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=50883</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/06/06/50883.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;I'll be surfing out on Amazon.com and after I've stuck something in the shopping cart...like...oh .... &lt;A href="http://www.amazon.com/exec/obidos/tg/detail/-/0321336437/qid=1118103491/sr=8-1/ref=pd_ka_1/104-7180755-5995925?v=glance&amp;amp;s=books&amp;amp;n=507846"&gt;Dr J's and Riley's new book&lt;/A&gt;..... I'll click the back button and I get a page not displayed.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Rats.&amp;nbsp; Stupid Amazon.com.&amp;nbsp; Does this to me all the time.&amp;nbsp; Really annoying.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Well I was out checking knowledge base articles and found this:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;!--StartFragment --&gt;&lt;FONT face=Arial size=2&gt;FIX: You receive a "Page cannot be displayed" error message in Internet Explorer when you browse back to a Web page that contains data that you previously submitted after you install Windows XP SP2: &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/?kbid=890178"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/?kbid=890178&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;No WONDER I keep getting that issue.&amp;nbsp; It's NOT Amazon.com at all.&amp;nbsp; Remember this is a call for a hotfix, now why this isn't more available, I have no idea, but at least I can call for the free hotfix.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;HR id=null&gt;

&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Update ...okay I'm confused.... if I get the hotfix it says I need to enable it by entering a reg key, but if I have cumulative update&amp;nbsp;the steps do not have to be followed.&amp;nbsp; Have you seen these hotfixes that are like this that have 'reg key enablers'?&amp;nbsp; Outlook Express has a bunch of them too.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;hmmm... I think I'll do the workaround.....&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=50883" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Rants/default.aspx">Rants</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>CRM and XP sp2?</title><link>http://msmvps.com/blogs/bradley/archive/2005/05/03/45591.aspx</link><pubDate>Wed, 04 May 2005 02:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:45591</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=45591</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=45591</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/05/03/45591.aspx#comments</comments><description>&lt;FONT face=Arial size=2&gt;I went to a NT user group meeting tonight and one of the guys sitting next to&amp;nbsp;me said they hadn't yet deployed XP sp2 because Microsoft CRM didn't support it.&amp;nbsp; I knew they had already sent out a patch to fix this... so ... if you are they guy who talked to me tonight...the patch is right &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=95ED89D0-8B99-4458-B798-90AD5400923E&amp;amp;displaylang=en"&gt;here&lt;/A&gt;.&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=45591" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>If you are on XP sp1 you won't wake up with XP sp2 tomorrow</title><link>http://msmvps.com/blogs/bradley/archive/2005/04/11/41664.aspx</link><pubDate>Mon, 11 Apr 2005 17:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:41664</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=41664</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=41664</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/04/11/41664.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Dear Microsoft/WagEd/whomever was in charge of your communication on the 'expiring blocking mechanism of 4/12/2005&amp;#8221;:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Next time, can you try to do a better job of communicating than you did?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Your &lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx "&gt;article here &lt;/A&gt;totally is confusing, misleading and quite frankly scares people.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Conversely Paul Thurott's &lt;A href="http://www.windowsitpro.com/Article/ArticleID/45798/45798.html "&gt;article here &lt;/A&gt;gives the facts:&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Arial size=2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color=#ff0000&gt;&lt;EM&gt;&amp;#8220;However--and this is the most important point--Automatic Updates won't automatically install SP2 at that time. Instead, you must first agree to the End User License Agreement (EULA) before SP2 will install via Automatic Updates. If you decline the EULA, SP2 won't install. End of controversy.&amp;#8221;&lt;/EM&gt;&lt;/FONT&gt;&lt;/STRONG&gt; &lt;/P&gt;
&lt;P&gt;For those folks who also say that they'd love to install it but their vendors won't support it yet, do me a favor and send them this link:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.microsoft.com/windows/appcompatibility/default.mspx"&gt;Windows Application Compatibility Toolkit&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The Application Compatibility Toolkit (ACT) 4.0 was designed to help IT Professionals minimize the risks associated with changes to the operating system and to deploy Windows XP SP2 quickly so they can realize the value of the investments Microsoft has made in securing the desktop from threats such as viruses, worms, and spyware.&lt;/P&gt;
&lt;P&gt;Remember what has been said before about XP sp2 -- this is a WIN for the Security guys.&amp;nbsp; So get your vendors [who obviously don't seem to be into security now, are they?] to help you get your desktops be part of your security protection system.&lt;/P&gt;
&lt;P&gt;April 12 should not be a day of concern for you, rather it should be the day you put your vendors on notice that it's time for them to pick up the ball.&amp;nbsp; I can understand if you can't find the vendor anymore, but folks, if you have a vendor that is on the record for not supporting SP2, that vendor needs to get a clue.&amp;nbsp; They need to help you, help us out here get more secure.&lt;/P&gt;
&lt;P&gt;XP sp2.&amp;nbsp; If you don't have it installed.&amp;nbsp; Do it.&lt;/P&gt;
&lt;P&gt;If it's because of vendor support, start pressuring them.&lt;/P&gt;
&lt;P&gt;It's time.&lt;/P&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=41664" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>So what's YOUR excuse?</title><link>http://msmvps.com/blogs/bradley/archive/2005/04/09/41475.aspx</link><pubDate>Sun, 10 Apr 2005 02:01:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:41475</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=41475</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=41475</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/04/09/41475.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Dual monitors means I multitask.... doing a spreadsheet on one screen, got last years TechEd DVD content playing on the other [geek radio you know].&amp;nbsp; And I'm listening to Steve Riley's presentation on the changes in XP sp2...and he says that the computing industry is in it's infancy really.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Think about it...it's true isn't it?&amp;nbsp; It's really only about 40 years old and the things we've relied on were truly built in an age that we trusted a lot more than we do now...and thus because the world in which computers live in is less trustworthy that the world that the underlying architecture was built for and intended for, means we need to change, to update how we do things.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;He goes on to predict that we might even see some more &lt;A href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/rpc/rpc/how_rpc_works.asp"&gt;RPC issues &lt;/A&gt;crop up [you remember &lt;A href="http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx"&gt;03-026&lt;/A&gt;/&lt;A href="http://www.microsoft.com/technet/security/bulletin/MS03-029.mspx"&gt;03-029 &lt;/A&gt;Blaster right?] because the underlying architecture on what RPC was based on assumed we could trust the network.&amp;nbsp; But we can't anymore, can we?&amp;nbsp; He goes on to say that the&lt;/FONT&gt;&lt;FONT face=Arial size=2&gt; move to making sure that you can trust a machine with your life [&lt;EM&gt;aka trustworthy computing&lt;/EM&gt;] is about a 10 year process...and they've just begun.&amp;nbsp; &lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2netwk.mspx#EGAA"&gt;RPC Interface Restriction&lt;/A&gt; is just one of the first steps.&amp;nbsp; And he finishes it out by saying:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face=Arial color=#ff0000 size=2&gt;&amp;#8220;This [Windows &lt;EM&gt;XP sp2] It's a victory for the security guys&lt;/EM&gt;.&amp;nbsp; &lt;/FONT&gt;&lt;FONT face=Arial color=#ff0000 size=2&gt;It's a step to get your hosts [desktops] become particpants in the security stance of your organization.&amp;nbsp; &amp;#8220;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Hmmm... interesting... so if XP sp2 is a win for the security guys....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;So what the heck are YOU waiting for?&lt;/STRONG&gt;&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You heard me.... why haven't 75% of you&amp;nbsp;deployed it yet?&amp;nbsp; Why has only 1/4 of those on Windows XP rolled it out?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You know your desktops are your weak spots, why haven't you empowered them with all the layers you can to protect them?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You know .... someone was asking&amp;nbsp;in the newsgroup&amp;nbsp;about upgrading from SBS 2000 to SBS 2003 and whether they should upgrade and you know.... it truly isn't just about the killer app of Remote Web Workplace to me.&amp;nbsp; It's also about Security.&amp;nbsp; About the better patching experience I've had.&amp;nbsp; [truly I do mean that]&amp;nbsp; Someone on a listserve mentioned that IIS 6.0 was rock solid.&amp;nbsp; That while they have attacked boxes, they've gotten in via poorly written applications and not via the native IIS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;That's why you should upgrade to Windows 2003/SBS 2003 and Windows XP sp2.&amp;nbsp; Because truly both platforms are a &lt;STRONG&gt;win for the Security guys&lt;/STRONG&gt;.&amp;nbsp; And soon for us, our own service pack,&amp;nbsp;SBSers SP1.&amp;nbsp; I've literally seen the Data Execute Projection mechanism where a potential buffer overrun is flagged [&lt;EM&gt;in my case it was a major update to the Trend virus engine that needed to be 'approved' as a DEP exception&lt;/EM&gt;], I've seen the impact of the firewall as the system is built.&amp;nbsp; The &lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2chngs.mspx#EAAA"&gt;changes in XP sp2&lt;/A&gt;, in &lt;A href="http://www.microsoft.com/windowsserver2003/downloads/servicepacks/sp1/sp1faq.mspx"&gt;Windows 2003 sp1&lt;/A&gt;, the beginning of the band wagon for &lt;A href="http://www.pcworld.com/news/article/0,aid,120314,00.asp"&gt;LUA for Longhorn&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Like this feature for example....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;EM&gt;&lt;B&gt;Post-Setup Security Updates (PSSU).&lt;/B&gt; Servers are vulnerable in the time between being installation and when the latest security updates are applied. To counter this, Windows Server 2003 with Windows Server 2003 Service Pack 1 blocks all inbound connections to the server after installation until Windows Update has run to deliver the latest security updates to the new computer. This feature also guides administrators through Automatic Update at the time of first log on.&lt;/EM&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Do you realize that never again will a box be nailed with Code Red/Nimda as it's being built?&amp;nbsp; Wow, I mean&amp;nbsp;how cool is that?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;So if you aren't on XP sp2, if you aren't getting prepared for SBS 2003 sp [don't install Windows 2003 sp on our boxes], why aren't you?&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=41475" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>The Green versus the Blue</title><link>http://msmvps.com/blogs/bradley/archive/2005/03/25/39749.aspx</link><pubDate>Sat, 26 Mar 2005 03:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:39749</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=39749</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=39749</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/03/25/39749.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;A bit of background first from &lt;A href="http://www.microsoft.com/technet/community/tnradio/archive/securityFeaturesXP.mspx"&gt;Steve Riley&lt;/A&gt;:&lt;BR&gt;&lt;BR&gt;"&lt;EM&gt;Therefore, we admit we broke our promise and we added features to a service pack, but we did it because we believed it was absolutely necessary to improve the resiliency of the operating system to live in the hostile network that we have now that designers of software and even software as recent as Windows XP never really imagined that the Internet would become the hostile place that it is right now. And it's more imperative to software designers than ever before that they build in features that can increase the resiliency and security management, for example, so that it's easier to configure and maintain." &lt;BR&gt;&lt;BR&gt;"The perimeter is, for all practical purposes, almost gone. Every machine is becoming its own perimeter." &lt;BR&gt;&lt;BR&gt;"Moving the security decisions from the edge to the host, it's almost as if the host is now the edge."&lt;/EM&gt; &lt;BR&gt;&lt;BR&gt;Friends, Romans, Countrymen, Geeks, Blogreaders lend me your ears...or eyes as the case may be.....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;XP home does not have the same security features as XP pro.&amp;nbsp; Specifically it is lacking these two that I think are very important ones:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Encrypting File System - protects sensitive data in files that are stored on disk using the NTFS file system.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Access Control &amp;#8211; restrict access to selected files, applications, and other resources&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;In this day and age where Aunt Nellie's system is apt to be turned into a attacking bot, where the home PC has PII [personal identity information] on it [credit cards, bank accounts and what not], where identify theft, phishing, etc etc is a daily occurance, I think the home machine needs as much protection as our most vulnerable web facing machines.&amp;nbsp; Therefore, why is there an operating system 'built for Home", ready for peer to peer networking, that has less security features than XP Pro? &lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;FONT face=Arial size=2&gt;Shouldn't the needs of a home machine, less controlled and protected than a XP pro behind ISA server [preferably in SBSland as well]&amp;nbsp;not be identical to pro...or perhaps [gasp] even &lt;STRONG&gt;exceed&lt;/STRONG&gt; a pro machine in its security needs? &lt;BR&gt;&lt;BR&gt;If I have personal information on that box, I want encryption.&amp;nbsp; If I have junior on my same system doing who knows what, I want the ability to add security permissions and what not to files of a level possibly more paranoid than I do at work. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;Why is there an assumption that Aunt Nellie at home needs less security than Uncle Bob at the office?&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;Shouldn't all desktops be protected in the same manner?&amp;nbsp; Why&amp;nbsp;is there [other than&amp;nbsp;for stupid marketing and pricing decisions] the need for two client systems anyway.&amp;nbsp; Aren't the security needs of us all the same?&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;We in SBSland don't like the&amp;nbsp;Green box because it means that we have to talk the owner into upgrading to the Blue box.&amp;nbsp; [&lt;EM&gt;remember XP homes cannot join a domain&lt;/EM&gt;].&amp;nbsp; But heck I don't like XP Homes for their lack of security features.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;As we go into Longhorn...how about ONE BOX.&amp;nbsp; One Security model...one set of&amp;nbsp;tools and tweaks and protections and ....just one protection level.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;I'm not talking about versions like Tablet and Media center and what not...but just don't have a version at home that cannot have the same security features as an Office version.&lt;/FONT&gt;&lt;BR&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;So Steve Ballmer or&amp;nbsp;Bill Gates or whoever is in charge of making the decision of the client/desktop operating system.&amp;nbsp; Consider that Home machines&amp;nbsp;need&amp;nbsp;just as much security &lt;STRONG&gt;IF NOT MORE these days&lt;/STRONG&gt;&amp;nbsp;than office&amp;nbsp;machines.&amp;nbsp; Don't make this a marketing decision...make the choice of ONE operating system a security one.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=lastInCell&gt;&lt;FONT face=Arial size=2&gt;Just say &lt;STRONG&gt;NO&lt;/STRONG&gt; to the Green Box.&lt;/P&gt;&lt;/FONT&gt;
&lt;P class=lastInCell&gt;&lt;IMG src="http://www.microsoft.com/windowsxp/images/home/highlights/home_145x90.jpg"&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=39749" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Go Borg!!!!</title><link>http://msmvps.com/blogs/bradley/archive/2005/02/18/36402.aspx</link><pubDate>Sat, 19 Feb 2005 05:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:36402</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=36402</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=36402</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/02/18/36402.aspx#comments</comments><description>&lt;P&gt;&lt;IMG src="http://www.microsoft.com/windowsxp/images/pro/highlights/pro_145x90.jpg"&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;In buying some USB cables at Office Depot tonight,&amp;nbsp;I noticed that Office Depot had XP sp2 cdroms in the same shelf as the AOL cdroms.&amp;nbsp; Kewl.&amp;nbsp; I was posting to a listserve some of my accumulated &amp;#8220;stuff&amp;#8221; about XP sp2 and I'll copy it here....&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;For those that haven't deployed it.... DO IT.&amp;nbsp; Go Borg!&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;
&lt;HR id=null&gt;
&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;A class=moz-txt-link-freetext href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx"&gt;&lt;FONT face=Arial size=2&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2aumng.mspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;BR&gt;In my little lan while certainly not a huge rollout, just a few patterns that I noted &lt;BR&gt;&lt;BR&gt;2 out of 2 workstations with Nvidia digital video cards did not like the driver in Sp2 and needed to be booted into safe mode and rolled back to the sp1 driver. &lt;BR&gt;&lt;BR&gt;2 out of 2 computers [laptop/desktop] with various versions of AOL installed on them [yeah... I know....don't ask] did not have good install experiences and required the use of a repair install. &lt;BR&gt;&lt;BR&gt;Ensure you scan with a malware remover BEFORE deploying SP2 as there are a couple of nasty strains [one in particular comes to mind] that wreak havok with sp2 installs &lt;BR&gt;Windows XP Service Pack 2 is not available to install from Windows Update and is not offered by Automatic Updates: &lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?kbid=885627"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/default.aspx?kbid=885627&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;BR&gt;All other machines were deployed in stages using Shavlik HfnetchkPro and had no issues. &lt;BR&gt;&lt;BR&gt;After deployment I would advise installing the Loopback patch for two issues.... &lt;BR&gt;&lt;BR&gt;1.&amp;nbsp; Some reported issues with Cisco VPNS and what not &lt;BR&gt;2.&amp;nbsp; A bit noisy app log files with mrxsmb "cosmetic" issues &lt;BR&gt;&lt;BR&gt;Programs that connect to IP addresses that are in the loopback address range may not work as you expect in Windows XP Service Pack 2: &lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?scid=kb;en-us;884020"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;884020&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;BR&gt;The recent 05-011 patch has some very isolated issues with XP sp2 and 2k3 networks [file shares and mapped drives] so if you are seeing any of these remember it's a free call to Microsoft for security patch issues.&amp;nbsp; [I personally am not seeing issues here] &lt;BR&gt;&lt;BR&gt;There are two other patches that you may want to include in your XPsp2 images for those that RIS and 886185 gets offered up via Windows update but not deemed to be a security patch &lt;BR&gt;&lt;BR&gt;Description of the critical update for Windows Firewall "My Network (subnet) only" scoping in Windows XP Service Pack 2: &lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?scid=kb;en-us;886185"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;886185&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;You receive the Stop error "Stop 0x05 (INVALID_PROCESS_ATTACH_ATTEMPT)" in Windows XP Service Pack 2 or Windows Server 2003: &lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?scid=kb;en-us;887742"&gt;&lt;FONT face=Arial size=2&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;887742&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;
&lt;HR id=null&gt;
&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Get XP sp2... go BORG!&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Arial size=2&gt;&lt;IMG src="http://images.google.com/images?q=tbn:_iYAXQOK-9YJ:http://www.star-voyager.de/humor/simpborg.jpg"&gt;&lt;/FONT&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=36402" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Issues with updates on XP sp2?</title><link>http://msmvps.com/blogs/bradley/archive/2005/02/09/35474.aspx</link><pubDate>Wed, 09 Feb 2005 18:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:35474</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=35474</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=35474</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/02/09/35474.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Here are some tips stolen from the newsgroup:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;!--StartFragment --&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp;Method 1: &lt;BR&gt;&lt;BR&gt;Stop the Automatic Updates Service &lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Start. &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Choose Run. &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In the Run box, type services.msc. &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;BR&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Right-click the Automatic Updates service. &lt;BR&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Properties. &lt;BR&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under Service status, click Stop. &lt;BR&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;BR&gt;&lt;BR&gt;Delete the Contents of the DataStore and Download folders &lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Start. &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Choose Run. &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In the Run box, type %windir%\SoftwareDistribution. &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;BR&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete the contents of both the DataStore and Download folders. &lt;BR&gt;&lt;BR&gt;Start the Automatic Updates Service &lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Start. &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Choose Run. &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In the Run box, type services.msc. &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;BR&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Right-click the Automatic Updates service. &lt;BR&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Properties. &lt;BR&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Under Service status, click Start. &lt;BR&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click OK. &lt;BR&gt;&lt;BR&gt;Reset or Optimize the Internet Explorer: &lt;BR&gt;For this lets follow the steps given below: &lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Double Click on Internet Explorer Icon &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Tools &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select General Tab &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete Cookies-&amp;gt;Click OK. &lt;BR&gt;5.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Delete History-&amp;gt;Click OK &lt;BR&gt;6.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Then go to Advanced Tab &lt;BR&gt;7.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Restore Defaults &lt;BR&gt;8.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Apply-&amp;gt;Click o.k &lt;BR&gt;&lt;BR&gt;Turn-Off the Pop-up Blocker: To disable it : &lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Open an Internet Explorer window &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Tools &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Pop-up blocker &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select Turn-off pop-up blocker &lt;BR&gt;&lt;BR&gt;If our issue stays then kindly proceed to the next set of suggestions. &lt;BR&gt;&lt;BR&gt;Add the following Sites as Trusted Sites: &lt;BR&gt;For this lets follow the following steps: &lt;BR&gt;a.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click Start--&amp;gt;Internet Explorer &lt;BR&gt;b.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to tools in the Tool Bar &lt;BR&gt;c.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click on Internet Options. &lt;BR&gt;d.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Go to the security Tab &lt;BR&gt;e.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click on trusted sites &lt;BR&gt;f.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Add the web-sites one by one. &lt;BR&gt;g.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click add &lt;BR&gt;h.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click ok &lt;BR&gt;i.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; And click ok again &lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;http://Windowsupdate.microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://v4.windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;http://V4.Windowsupdate.microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="https://v4.windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;https://v4.Windowsupdate.microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://download.windowsupdate.com/"&gt;&lt;FONT face=Arial size=2&gt;http://Download.Windowsupdate.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="http://v5.windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;http://V5.Windowsupdate.microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; and &lt;BR&gt;&lt;/FONT&gt;&lt;A class=moz-txt-link-freetext href="https://v5.windowsupdate.microsoft.com/"&gt;&lt;FONT face=Arial size=2&gt;https://v5.Windowsupdate.microsoft.com&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt; &lt;BR&gt;&lt;BR&gt;&lt;BR&gt;Method2: &lt;BR&gt;&lt;BR&gt;1.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Click on Start and then click Run, &lt;BR&gt;2.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In the open field type "REGSVR32 WUAPI.DLL" (Without quotation) &lt;BR&gt;3.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; When you receive the "DllRegisterServer in wuapi.dll succeeded" &lt;BR&gt;message, click OK. &lt;BR&gt;4.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please repeat these steps for each of the following commands: &lt;BR&gt;&lt;BR&gt;REGSVR32&amp;nbsp; WUAUENG.DLL &lt;BR&gt;REGSVR32&amp;nbsp; WUAUENG1.DLL &lt;BR&gt;REGSVR32&amp;nbsp; ATL.DLL &lt;BR&gt;REGSVR32&amp;nbsp; WUCLTUI.DLL &lt;BR&gt;REGSVR32&amp;nbsp; WUPS.DLL &lt;BR&gt;REGSVR32&amp;nbsp; JSCRIPT.DLL &lt;BR&gt;REGSVR32&amp;nbsp; WUWEB.DLL &lt;BR&gt;REGSVR32&amp;nbsp; MSXML3.DLL&lt;/FONT&gt; &lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=35474" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>So why did the laptop have that key and not my workstation?</title><link>http://msmvps.com/blogs/bradley/archive/2005/01/08/31104.aspx</link><pubDate>Sun, 09 Jan 2005 01:24:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:31104</guid><dc:creator>bradley</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=31104</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=31104</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2005/01/08/31104.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Fixing my sister's laptop that has been giving problems with USB devices like the thumb drives and I was trying to get her new gig drive working and it kept coming back with an error message:&amp;nbsp; &amp;#8220;&lt;EM&gt;The specified service does not exist as an installed service&lt;/EM&gt;&amp;#8220;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;A href="http://www.techsupportforum.com/archive/index.php/t-2533.html"&gt;Fixed it.&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;But don't know why her machine had this key and my desktop does not:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Under there was indeed a key called &amp;#8220;lower filters&amp;#8221; and it was indeed a binary. Deleted the key out, rebooted and it can find the drive just fine now.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Weird.&amp;nbsp; My desktop doesn't have it.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Must be sunspots again.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=31104" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>So like how many #$%# firewalls do we need?</title><link>http://msmvps.com/blogs/bradley/archive/2004/12/01/21880.aspx</link><pubDate>Thu, 02 Dec 2004 01:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:21880</guid><dc:creator>bradley</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=21880</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=21880</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2004/12/01/21880.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;The question was asked again in the newsgroup today --&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;#8220;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;Do I need the XP sp2 firewall enabled on the workstations inside my network when I have a firewall on the outside&lt;/EM&gt;?&amp;#8221;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;First off some background.&amp;nbsp; In your computer, in any computer there are over 64,000 ports... tcp/udp ports that are used to talk to one another.&amp;nbsp; Sometimes there is an application that is loaded up and &amp;#8220;listening&amp;#8220; on a port.&amp;nbsp; Kinda like it's sitting on your computer going &amp;#8220;I'm ready! I'm here!&amp;#8220;.&amp;nbsp; For bad things to happen a couple of things have to align in the cosmos.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;First you would have to have this open port with an application that is &amp;#8220;listening&amp;#8220;.&amp;nbsp; Then you would have to have a vulnerable application, something that you didn't patch.&amp;nbsp; Now knowing that I'd wack you guys upside the head for not patching, that's probably not going to happen, but let's pretend, shall we?&amp;nbsp; Then there would have to be a way inside your network.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;If a bad guy knows that behind that open port [think of it as an open door] that application &amp;#8220;X&amp;#8220; is waiting and ready to go, they can build a worm that attacks that &amp;#8220;listening application&amp;#8220; that specifically targets that open port.&amp;nbsp; Now we all know that all we need to be absolutely positively 100% safe is a firewall, right?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;Wrong.&lt;/STRONG&gt;&amp;nbsp; A firewall is only as good as the ports you have closed.&amp;nbsp; Furthermore, its only as good if there's absolutely no other way to get inside your network.&amp;nbsp; In order to do &amp;#8220;normal&amp;#8220; business, we MUST open ports.&amp;nbsp; Think of it this way, in order to do your job you must take the risk of driving a car.&amp;nbsp; You must get in the car and drive on the road or highway to get to your destination.&amp;nbsp; Thus you have opened yourself up to risks.&amp;nbsp; In a typical firm you probably have some ports opened up all the time:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Port 443 - the SSL port that SBS 2003 needs for secure access to RWW and OWA&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Port 25 - needed for email&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;On port 25 in particular [the email port] spammers are trying to &amp;#8220;hang off your nice IP address&amp;#8220; and do what is called an SMTP authorization attack.&amp;nbsp; They will attempt to &amp;#8220;crack&amp;#8220; the password on that port and try to authenticate on the Administrator's account.&amp;nbsp; Keep in mind that the &amp;#8220;attacker&amp;#8220; doing this... I wouldn't call an &amp;#8220;attacker&amp;#8220;.&amp;nbsp; It's a &amp;#8220;bot&amp;#8220; a machine just trying to add another victim to it's lair.&amp;nbsp; There's no human &amp;#8220;hacker&amp;#8220; on the other end of your rj45 connection manually trying to crack password, it's more likely that it's an automated program trying to get into your system.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;This by the way is the &amp;#8220;&lt;A href="http://msmvps.com/bradley/archive/2004/12/01/21728.aspx"&gt;finagle&amp;#8220; vulnerability &lt;/A&gt;that was discussed by USAToday... aka stupid cracked passwords...a &amp;#8220;&lt;STRONG&gt;don't do that&amp;#8220;&lt;/STRONG&gt; event as Jason out of Mothership Charlotte would say.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Okay lets discuss historical events in history that would have been prevented if a firewall had been on the inside of a network shall we?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;SQL slammer would not have been as damaging for one - right now my file and printer sharing ports, my Trend listening ports and nothin' else are open on this workstation.&amp;nbsp; Thus 1433/1434 the MSDE/SQL server ports are not open.&amp;nbsp; Now if I had something like an application [&lt;A href="http://www.lacertesoftware.com/news/102904_new_technolgy_for_2004.cfm"&gt;like the new 2005 Lacerte will do&lt;/A&gt;] that has MSDE installed on the desktop, I can sleep easier knowing that that application is protected.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Remember too that the other way you got nailed was when you had unpatched machines, a firewall on that outside peremeter and somone remoted in/VPN'd into the network and infected the unprotected/unpatched network.&amp;nbsp; Most of us probably are not running with &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=a290f2ee-0b55-491e-bc4c-8161671b2462&amp;amp;displaylang=en"&gt;VPN quarantine features &lt;/A&gt;running as it's not quite SBSized, so unless you can guarantee that all your salesmen have nice, clean, protected machines as they remote into the network, you probably need to think about firewalls on the INSIDE of your network.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;A href="www.steveriley.ms/ "&gt;Steve Riley &lt;/A&gt;will be including this in an upcoming book, but the gist is that the &lt;A href="http://msmvps.com/bradley/archive/2004/07/01/9336.aspx"&gt;concept of the DMZ &lt;/A&gt;is dead.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;So why do you need a firewall on the inside of your network when you have a perfectly good one on the outside?&amp;nbsp; Because stuff happens.&amp;nbsp; That's why.&amp;nbsp; And it's another layered defense to have on our side.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=1&gt;Speaking of patching... for those people that are 100% borg [aka SBS 2003 and Windows XP sp2.... there is no patching needed today whatsoever]&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;B&gt;&lt;FONT face=Arial size=1&gt;Non-Affected Software: &lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE cellSpacing=0 cellPadding=0 border=0&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top&gt;&lt;FONT face=Arial size=1&gt;&amp;#8226;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=listItem&gt;
&lt;P&gt;&lt;FONT face=Arial size=1&gt;Microsoft Windows XP Service Pack 2&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top&gt;&lt;FONT face=Arial size=1&gt;&amp;#8226;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=listItem&gt;
&lt;P&gt;&lt;FONT face=Arial size=1&gt;Microsoft Windows XP 64-Bit Edition Version 2003&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD class=listBullet vAlign=top&gt;&lt;FONT face=Arial size=1&gt;&amp;#8226;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD class=listItem&gt;
&lt;P&gt;&lt;FONT face=Arial size=1&gt;Microsoft Windows Server 2003&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=21880" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Details on Group Policy</title><link>http://msmvps.com/blogs/bradley/archive/2004/11/26/20822.aspx</link><pubDate>Fri, 26 Nov 2004 07:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:20822</guid><dc:creator>bradley</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=20822</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=20822</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2004/11/26/20822.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Jeff from Vancouver also writes in that he wants a more detailed description of what the group policy can and cannot do.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;You know [in my opinion] the best source for seeing the power of group policy is?&amp;nbsp; &lt;A href="http://download.microsoft.com/download/a/a/3/aa32239c-3a23-46ef-ba8b-da786e167e5e/PolicySettings.xls"&gt;In an Excel spreadsheet&lt;/A&gt;. Now granted I think it's because us beancounters are born with a spreadsheet so it's more natural to us, but that one document more often than not shows me what can be done.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Remember my &lt;A href="http://msmvps.com/bradley/archive/2004/11/21/20026.aspx"&gt;NOLMHash thing&lt;/A&gt;?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;On the spreadsheet it's detailed out like this:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE style="WIDTH: 333pt; BORDER-COLLAPSE: collapse" cellSpacing=0 cellPadding=0 width=444 border=0 x:str&gt;
&lt;COLGROUP&gt;
&lt;COL style="WIDTH: 333pt; mso-width-source: userset; mso-width-alt: 16237" width=444&gt;
&lt;TBODY&gt;
&lt;TR style="HEIGHT: 13.5pt; mso-height-source: userset" height=18&gt;
&lt;TD class=xl24 style="BORDER-RIGHT: #ece9d8; BORDER-TOP: #ece9d8; BORDER-LEFT: #ece9d8; WIDTH: 333pt; BORDER-BOTTOM: #ece9d8; HEIGHT: 13.5pt; BACKGROUND-COLOR: transparent" width=444 height=18&gt;&lt;FONT face=Arial size=2&gt;Computer Configuration\Windows Settings\Local Policies\Security Options&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE style="WIDTH: 271pt; BORDER-COLLAPSE: collapse" cellSpacing=0 cellPadding=0 width=361 border=0 x:str&gt;
&lt;COLGROUP&gt;
&lt;COL style="WIDTH: 271pt; mso-width-source: userset; mso-width-alt: 13202" width=361&gt;
&lt;TBODY&gt;
&lt;TR style="HEIGHT: 13.5pt; mso-height-source: userset" height=18&gt;
&lt;TD class=xl24 style="BORDER-RIGHT: #ece9d8; BORDER-TOP: #ece9d8; BORDER-LEFT: #ece9d8; WIDTH: 271pt; BORDER-BOTTOM: #ece9d8; HEIGHT: 13.5pt; BACKGROUND-COLOR: transparent" width=361 height=18&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Network security: Do not store LAN Manager hash value on next password change&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;
&lt;TABLE style="WIDTH: 206pt; BORDER-COLLAPSE: collapse" cellSpacing=0 cellPadding=0 width=274 border=0 x:str&gt;
&lt;COLGROUP&gt;
&lt;COL style="WIDTH: 206pt; mso-width-source: userset; mso-width-alt: 10020" width=274&gt;
&lt;TBODY&gt;
&lt;TR style="HEIGHT: 13.5pt; mso-height-source: userset" height=18&gt;
&lt;TD class=xl24 style="BORDER-RIGHT: #ece9d8; BORDER-TOP: #ece9d8; BORDER-LEFT: #ece9d8; WIDTH: 206pt; BORDER-BOTTOM: #ece9d8; HEIGHT: 13.5pt; BACKGROUND-COLOR: transparent" width=274 height=18&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt;Determines if, at the next password change, the LAN Manager (LM) hash value for the new password is stored. The LM hash is relatively weak and prone to attack, as compared with the cryptographically stronger Windows NT hash. Since the LM hash is stored on the local computer in the security database the passwords can be compromised if the security database is attacked. &lt;BR&gt;For more information on cryptographic hashes of passwords, see "Microsoft NTLM" in the Microsoft Web site at &lt;A href="http://go.microsoft.com/fwlink/?linkID=7029"&gt;http://go.microsoft.com/fwlink/?linkID=7029&lt;/A&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR&gt;&lt;FONT class=font6&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT class=font5&gt;&lt;FONT size=2&gt;&lt;FONT face=Arial&gt; Windows 2000 Service Pack 2 (SP2) and above offer compatibility with authentication to previous versions of Windows, such as Microsoft Windows NT 4.0. &lt;BR&gt;This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP, and the Windows Server 2003 family to communicate with computers running Windows 95 and Windows 98.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Check this spreadsheet out Jeff.&amp;nbsp; It takes some time to go through, but I think it might help.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Let me know.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=20822" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>Some addins on XP sp2 are not listed in the Manage Add-ons box</title><link>http://msmvps.com/blogs/bradley/archive/2004/11/19/19820.aspx</link><pubDate>Sat, 20 Nov 2004 05:50:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:19820</guid><dc:creator>bradley</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=19820</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=19820</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2004/11/19/19820.aspx#comments</comments><description>&lt;IMG src="http://www.microsoft.com/library/toolbar/3.0/images/banners/windowsXP_masthead_ltr.gif"&gt;
&lt;P&gt;One of the big changes in IE under XP sp2 is the ability to manage Internet Explorer add ins.&amp;nbsp; Details of this are showcased here:&lt;/P&gt;
&lt;P&gt;How to manage Internet Explorer add-ons in Windows XP Service Pack 2: &lt;BR&gt;&lt;A href="http://support.microsoft.com/kb/883256"&gt;http://support.microsoft.com/kb/883256&lt;/A&gt;&lt;BR&gt;&lt;!--StartFragment --&gt;&lt;/P&gt;
&lt;P&gt;Tonight on &lt;A href="http://www.thundermain.com/rss/"&gt;Thundermain's RSS feed &lt;/A&gt;I spotted this KB and tracked back the KB that was released to the download page: &lt;BR&gt;&lt;BR&gt;Download details: Update for Internet Explorer 6 for XP Service Pack 2 (KB888240): &lt;BR&gt;&lt;A class=moz-txt-link-freetext href="http://www.microsoft.com/downloads/details.aspx?familyid=d788c59e-b116-4d38-b00c-ff1d529106c8&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=d788c59e-b116-4d38-b00c-ff1d529106c8&amp;amp;displaylang=en&lt;/A&gt; &lt;BR&gt;&lt;BR&gt;Some add-ons are not listed in the Manage Add-ons dialog box in Internet Explorer on your Windows XP Service Pack 2-based computer: &lt;BR&gt;&lt;A class=moz-txt-link-freetext href="http://support.microsoft.com/default.aspx?scid=kb;en-us;888240"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;888240&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;Sounds like a good download to install, don't you think?&amp;nbsp; :-)&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=19820" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>MRXsmb errors in your system event log files after XP sp2?</title><link>http://msmvps.com/blogs/bradley/archive/2004/11/04/17963.aspx</link><pubDate>Thu, 04 Nov 2004 23:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:17963</guid><dc:creator>bradley</dc:creator><slash:comments>8</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=17963</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=17963</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2004/11/04/17963.aspx#comments</comments><description>&lt;P&gt;&lt;FONT face=Arial size=2&gt;Sorry to sound like a broken record again, but first I have to rant:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;EM&gt;"An enterprise class account will typically have adequate security procedures from a firewall perspective, and also have appropriate intrusion detection systems," said Phil Ernst, president of Convergence Technology Consulting, Bowie, Md., which has performed numerous SP2 deployments for SMB customers. "The SMB space is a mixed bag. Best practices costs money, and in some cases too much for many SMB organizations. Either they lack the internal expertise for controlling updates, lack the funds, or both."&lt;/EM&gt;&lt;/FONT&gt;&amp;nbsp;&lt;FONT face=Arial size=2&gt; &lt;A href="http://www.crn.com/sections/breakingnews/dailyarchives.jhtml?articleId=51202859"&gt;X2 Adoption slow in Enterprise, Picks up in SMB&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;I've met some folks in &amp;#8220;enterprise class and I can say without a doubt that &amp;#8220;best practices&amp;#8220; isn't followed in those enterprise marketplaces any better.&amp;nbsp; They don't necessarily because of their size have adequate security procedures.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;So what "&lt;STRONG&gt;best practices&lt;/STRONG&gt;" can you do that we already have the tools for under the hood and just need external expertise from a VAR/VAP to set up [&lt;EM&gt;or even one really geeky admin&lt;/EM&gt;]?&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Controlling updates from the server with &lt;A href="http://www.microsoft.com/windowsserversystem/sus/default.mspx"&gt;SUS&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;&lt;A href="http://www.smallbizserver.net/Default.aspx?PageContentID=26&amp;amp;tabid=201"&gt;Group policy&lt;/A&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;&lt;A href="http://www.microsoft.com/technet/security/secnews/articles/itproviewpoint091004.mspx"&gt;Password&lt;/A&gt; policy&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;OWA with SSL encryption&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;Remote Web Workplace which has SSL&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;We already have a firewall&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Arial size=2&gt;You need to add a antivirus program&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;But the article confirms what I've seen.&amp;nbsp; Out here in SBSland we're rolling out XP sp2 much more than the big guys.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;Remember the&lt;A href="http://msmvps.com/bradley/archive/2004/10/14/15825.aspx"&gt; resources we have &lt;/A&gt;for rolling out XP sp2;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;I also spotted &lt;A href="http://www.prnewswire.com/cgi-bin/stories.pl?ACCT=109&amp;amp;STORY=/www/story/11-03-2004/0002353582&amp;amp;EDATE="&gt;this article &lt;/A&gt;that says &amp;#8220;Business Continuity to suffer&amp;#8220; with the roll out of SP2.&amp;nbsp; What continutity issues?&amp;nbsp; What broken applications?&amp;nbsp;I've had NO issues with SP2 on my workstations and all&amp;nbsp;of my applications work just fine.&amp;nbsp; If the program gets broken with SP2 the program was written poorly in the first place.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;The only issue that I noted, and have now fixed, is that my workstation was throwing off a lot of &amp;#8220;Event 3019 errors - MRXsmb - The redirector failed to&amp;nbsp;determine the connection type&amp;#8221;&amp;nbsp;errors in my system event log and the &lt;A href="http://support.microsoft.com/default.aspx?scid=kb;en-us;884020"&gt;application of the loopback patch&lt;/A&gt;&amp;nbsp;cleaned up my system log files.&amp;nbsp; After I applied that patch, it cleaned up my log files with no issues.&amp;nbsp; It wasn't causing any issues, more of a cosmetic thing that was annoying.&amp;nbsp;&amp;nbsp; The hotfix is available on the download site.&amp;nbsp; Given that I shut off SMB signing here because of attached printers, I'm thinking it was related a bit to that.&amp;nbsp; Whatever the reason, my log files are now as they were before.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=17963" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item><item><title>XP sp2 stuff</title><link>http://msmvps.com/blogs/bradley/archive/2004/10/14/15825.aspx</link><pubDate>Thu, 14 Oct 2004 17:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:15825</guid><dc:creator>bradley</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/rsscomments.aspx?PostID=15825</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/bradley/commentapi.aspx?PostID=15825</wfw:comment><comments>http://msmvps.com/blogs/bradley/archive/2004/10/14/15825.aspx#comments</comments><description>&lt;IMG src="http://www.microsoft.com/h/en-us/i/sec/stage3-server_icon-55x55.gif"&gt;&lt;FONT face=Arial size=2&gt;David S. in the newsgroups asked if I could put a XP sp2 category in the blog. Sure!&lt;/FONT&gt; 
&lt;P&gt;&lt;FONT face=Arial size=2&gt;I'll revisit the &amp;#8220;stuff&amp;#8221; you need to have for deploying sp2 on your SBS 2003 network:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;ENABLING THE FIREWALL&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=d70097c2-4317-40e0-b7da-feb52c6b6386&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;Update to enable and configure the SP 2 firewall inside the network&lt;/FONT&gt;&lt;/A&gt; &lt;FONT face=Arial size=2&gt;[this comes down via Windows Update]&lt;/FONT&gt; 
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&amp;amp;familyid=532a4cd0-f2ce-4fa7-92ab-ac336ad18409&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;Hotfix to fix the &amp;#8220;long name&amp;#8220; error on the Group policy edit&lt;/FONT&gt;&lt;/A&gt; &lt;FONT face=Arial size=2&gt;[this does &lt;EM&gt;not&lt;/EM&gt; come down via Windows Update]&lt;/FONT&gt; 
&lt;LI&gt;&lt;A href="http://support.microsoft.com/?kbid=842933"&gt;&lt;FONT face=Arial size=2&gt;KB article about the issue&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://go.microsoft.com/fwlink/?linkid=33331"&gt;&lt;FONT face=Arial size=2&gt;Whitepaper to deploy XP sp2 firewall&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;DEPLOYING SP2 TO NEW MACHINES/NEWLY JOINED MACHINES&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=A8F72FDD-6D82-4C2B-8078-114460826A40&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;Package to deploy SP2 to new computers&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp; - please note this cannot be uninstalled &lt;/FONT&gt;
&lt;LI&gt;&lt;A href="http://go.microsoft.com/fwlink/?linkid=34345&amp;amp;clcid=0x409"&gt;&lt;FONT face=Arial size=2&gt;Whitepaper to deploy XP sp2 as the SP to new machines&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;SP2 INSTALL PACKAGE&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=049c9dbe-3b8e-4f30-8245-9e368d3cdb5a&amp;amp;DisplayLang=en"&gt;&lt;FONT face=Arial size=2&gt;XP sp2 install package&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;TURN OFF THE FIREWALL?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.sbslinks.com/XPsp2.htm"&gt;&lt;FONT face=Arial size=2&gt;What policies to adjust to turn OFF the firewall at the domain controller&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;MICROSOFT'S RESOURCES&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/winxpsp2.mspx"&gt;&lt;FONT face=Arial size=2&gt;MS's resource page for XP sp2&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://support.microsoft.com/default.aspx?scid=kb;%5bLN%5d;835935"&gt;&lt;FONT face=Arial size=2&gt;XP sp2 release notes&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=3E90DC91-AC56-4665-949B-BEDA3080E0F6&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;XP sp2 deploy tools&lt;/FONT&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyId=49AE8576-9BB9-4126-9761-BA8011FABF38&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;XP sp2 support tools&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;XP SP2 hotfixes you may need&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="http://support.microsoft.com/default.aspx?kbid=884020"&gt;&lt;FONT face=Arial size=2&gt;Loopback fix [for VPNs etc]&lt;/FONT&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;One of the best ways to get a feel for how much you can control is looking over &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7821c32f-da15-438d-8e48-45915cd2bc14&amp;amp;displaylang=en"&gt;&lt;FONT face=Arial size=2&gt;&lt;STRONG&gt;THIS spreadsheet&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Arial size=2&gt;&amp;nbsp; Take a look at it and I think it will give you the best feel for how powerful this is.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Arial size=2&gt;So, I'm sure you are wanting to know ...why do we need a firewall on the inside when we have ISA/RRAS on the outside.&amp;nbsp; Because look at our past Blasters, Sasser and other worms.&amp;nbsp; Most of the affected businesses HAD firewalls, yet they got nailed.&amp;nbsp; Port 80 is jokingly called the universal firewall bypass port because so much goes though there now.&amp;nbsp; Protecting your workstations, limiting the ports that they are exposed on is the best practice going forward.&amp;nbsp; The Windows 2003 R2 [the next release of the server OS in a year or so] will include network protection feature so that workstations that don't &amp;#8220;pass muster&amp;#8221; won't get a IP address.&amp;nbsp; Enabling the firewall inside our networks is the first step in the journey towards that.&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=15825" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/bradley/archive/tags/XP2/default.aspx">XP2</category></item></channel></rss>