Windows XP SP2s Firewall Will Be in Your Face
Windows XP's Internet Connection Firewall proved underwhelming, and was included just to satisfy a check-off list of feature. With Service Pack 2, it looks as if Microsoft learned its lesson. The new firewall will do a lot more of the things personal fireAs we reported recently, Microsoft just released a document going into more detail about the features expected in the upcoming Service Pack 2 for Windows XP. The company on Thursday released a beta of SP2 and will ship for real well into 2004. SP2 is basically about security enhancements to Windows, such as the improved Internet Connection Firewall (ICF). The information in this document is important and in all likelihood reflects the way things will turn out. But everyone should recognize that this document is a beta document for an almost-beta set of programs, and we have to assume there will be differences as the tests of SP2 proceed. Future changes will be reported at a particular MSDN link: The Microsoft Security Developer Center. In a previous column, I mentioned that the Internet Connection Firewall will be turned on by default under SP2. Ports not actually being used will be shut by default.
In addition, both RPC and DCOM have been restructured to diminish the possibility of attack and to let the administrator control access rights. Microsoft frequently points out that users with ICF enabled were not vulnerable to Blaster.