Protect you computer and your data
 

Welcome to our computer security Archive. Have fun browsing!

 

(Browse for more articles)

 

Windows Xp Professional - a Complete Summary Pt 1

This article talks about Windows XP and profile from which he logs on last will
all the new features it brings along with the last profile updated. This can also
it. Microsoft has really introduced a be made ad a mandatory profile for e.g.
powerful new operating system which in kiosk environment where you want the
brings lots of flexibility and ease of user to have the exact same profile
use to the user. It also at the same whenever he/she logs on. You can do this
time is an extremely reliable and sturdy by going into the user profile and
operating system for both the average and renaming a file ntuser.dat to ntuser.man
the excessive user. In this article we and no changes will be saved when the
start by talking about the requirements user logs off so he/she will get the same
XP needs for optimum operation and how we default profile when he/she logs back on.
can meet those requirements. We also talk Local Security Policy:
about the bits and pieces of installing, Local security policies give the
upgrading and migrating user settings. We administrator several measures to
also highlight the new powerful features maintain security in the workgroup. There
in Windows XP installation like are three different types of policies
unattended installations and remote like auditing, user rights and security
installations. Microsoft also aims to settings. There are also account policies
target the home market with this new which include password policies and
operating system and has included several account lockout policies. Password
new features such as user account policies enable us to enforce password
management and group's management at a laws where the administrator can set
much easier GUI level. Yet it remains password length, history, age and even
the same reliable operating system if not complexity for secure environments.
even better for setting security, group Account lockout policies prevent hackers
security and domain security policies. from constantly trying to log on to the
Microsoft also includes several new system using brute force like all
features in terms of auditing and combinations of passwords. Local policies
generating a lot of reports in logs for give us a variety of features. One
the administrative user. We also talk section is user rights assignments where
about the Windows installer included in the administrator can assign specific
this new operating system which helps policies to specific users and groups
remove code clutter and in turn provides which allow different users to have
us with a more stable operating system different powers and rights on the
than earlier releases. We also see a network and the machine. Auditing
significant improvement in user interface properties enable us to generate reports
and options with a greater ease-of-use on how the system is performing to be
for the average day user and options like clear who is trying to do what on the
multilingual support which target the machine or the network. Microsoft does
corporate environment. Windows XP also make our work easier by giving us
takes hardware support and installation preconfigured security templates. These
to a new level with its new plug-and-play are groups of settings for various
features an extremely good compatibility scenarios. These can be accessed through
with mobile hardware. We then discuss a bunch of .inf files provided by
the Revolutionary new NTFS file system on Microsoft and you can implement these by
which Windows XP runs and all its new either importing the .inf file into the
advantages over the old FAT and FAT32 group or by using the Microsoft security
file systems. Windows XP also gives us a configuration and analysis snap-in. These
good Networking set up and can be applied to a local machine or a
troubleshooting environment with new group and are easy to create through the
features like off-line folder sharing and MMC. The preconditions are to first
resource management. Remote connectivity create a snap-in and add the security
has become a much achievable target with policies and security configuration and
the launch of Windows XP giving the templates modules in it and then create a
telecommuter the flexibility to work from database and then import a security
home. We finally talk about how this new template into it. Then you can compare
operating system stands up to its older and analyze or even set your computer to
legacy brothers in terms of performance, these configurations. You can also save
optimization, recovery, back up and other these security templates as shortcuts for
services. All in all Microsoft has access to each machines security
definitely released a powerful beast of settings.
an operating system onto the consumers Group Policies:
and it is up to us to realize and utilize The main function of group policies is to
Windows XP at its full potential. implement restrictions on their computer
Meeting Minimum XP Requirements: to prevent unintentional mess up of the
Microsoft Win XP minimum requirements can OS on the computer. In a workgroup
be classified into various categories. background you can implement local group
The most important requirement is the policies which are specific to that local
minimum processor power needed, which is machine only and to the users on that
set to 233 MHz by Microsoft. I personally machine, so in order to implement this on
do not agree with such low standards the entire workgroup you will have to
since the cost of processors is dropping implement this locally on each machine
fast and it is the biggest driver for a which can become a headache. However, you
machines performance factor. A minimum of can have remote shortcuts to each
300 MHz is what I would recommend on the desktop's MMC (focus MMC on remote
lowest level. The control terminal machines) on your computer and then can
investigated in this report is up to the implement those policies through this
benchmark or just above average procedure. In a domain setting you need
requirements for the user. The processor to implement these policies through the
is a 2.5 GHz Pentium 4 and is performing organizational units in active directory
at an optimal rate. Win XP pro does on the active directory server. By
support multi processor support, but is default group polices have a refresh
not necessary in this scenario. The next period after which group policies will be
requirement brought to my attention is downloaded but you can run a GPUPDATE to
the amount of RAM Microsoft recommends refresh and implement new group policies
for minimum requirements for Win XP Pro immediately. Group policies are accessed
to operate is 64MB, which is clearly too through the same way as local policies by
low according to current standards. adding the snap-in of group policies. You
However, Microsoft does state a serious can create group policies on that local
lack of Win XP pro function availability machine or connect to remote machine by
while using 64MB of RAM. An example of clicking the browse icon, but you need to
this would be disabled Fast user have administrative rights on each
switching during this mode. I personally machine and also on that machine. As ever
recommend a minimum of 256MB for any domain policies override local computer
machine with average performance policies.
requirements running Win XP Pro. The Auditing Windows XP:
control machine undertaken in this report As a network administrator one of the
has excellent RAM support with 1GB of main tasks is to make sure that the
available RAM. The RAM level in this resources are being used the way they are
machine takes a load of the processor as used or not being used they should not
well and at the same time provides be. Auditing in Windows XP is just the
excellent performance for heavy multi feature which helps us track these key
usage of various software's in the events. This can be used to track
market. The hard drive requirements for successful or failed system events. It
Microsoft have been ever increasing with helps the administrator choose between
new releases of operating systems and Win either tracking things being done
XP pro requires a minimum of 1.5GB of correctly or things not being done
hard drive space. This higher increase correctly. The most important factor is
can be accounted for bigger operating file access and account logon. One
systems with more included in them, for drawback of auditing is that it should be
e.g. Win XP pro includes a several turned on locally on each machine, since
features like media support for writing it cannot be enabled on a domain basis.
to CD media and also a built in firewall. Auditing should not be turned on in the
The control machine does a pretty good entire domain since it does take a
job of satisfying these hard drive performance hit on the system. An example
requirements with a 120GB primary would be the Audit object failures which
(Master) hard drive and another 120GB tracks failures or successes of files and
secondary (Slave) hard drive. However printers. Enabling this would not turn on
there are some flaws in this auditing on the file, in order to that
implementation which are highlighted in you need to go to the properties of the
the backup section of the report. One folder or files you want to audit. Head
advantage of having two hard drives is to the security tab, if you cannot see
clear that the paging file can be placed the security tab this either means that
on a separate hard drive for better and simple file sharing is turned on or that
faster performance. The control machine your drive is based on FAT32 partitioning
also exceeds the display requirements of style. You need to have a NTFS partition
Win XP. Microsoft has stepped up the bar style and simple file sharing tuned off
with this release and has made 800 x 600 for this security tab to show up.
a minimum display requirement for this However, in a domain environment simple
operating system and a lot of video file sharing is turned of by default.
drives will not let you shift below this Once you can see the security tab hit the
resolution. The control machine had advanced tab and select the auditing tab
capabilities above this with display and add the user or the group you would
potential up to 1600 x 1200. Win XP Pro like to audit. Auditing reports can be
also recommends setup floppies or seen through the event viewer which can
bootable CD standards for repair and be located through control panel and then
reinstall, which is also met by the in administrative tools. Finally the key
control machine. However I personally thing to remember about auditing is that
recommend bootable CD's to setup floppies it has to be turned on at two separate
which are more prone to failure of a long places, once in the local security
period of time. A better way would also policies and second at the resource you
be image backups and image installs which want to audit like a file or a printer.
are discussed later in this report. The Windows Installer:
BIOS is ACPI (Advanced Configuration and If you install an application on Windows
Power Interface) capable, which enables XP you are most probably using the
power management features and shut down Windows Installer. Microsoft started this
through HAL (Hardware abstraction Layer) through Windows 200o to prevent other
installation. Win XP pro has a lot of applications from just installing
graphical user features which can only be themselves and breaking and clobbering
utilized through a good graphics card. other DLL's. There are also problems
The control unit in this audit has a good during uninstall where the program would
graphics card with 128 MB of dedicated take away a critical Windows component
graphics memory for exploiting these and then your system might not boot. This
features. new service is integrated into the
Installing Windows XP: operating system to make the programs
I would like to bring to notice some well behaved. Windows Installer
installation features available from introduces package files (.msi) which are
Microsoft during a windows install. The installation files on the CD itself.
text mode option is enabled during a There are a lot of advantages to using
clean install and gives us the ability to the Windows Installer, for e.g. the
press the F5 key to choose a HAL enable ability to self-heal in a case where the
BIOS from the menu. This is critical for program detects that a DLL is corrupt or
an individual or an organization which missing and then can heal itself by
wants to enable the feature of auto power pulling that file back from the source CD
off. The BIOS has to HAL capable in order or network. There is also a rollback
to use this feature. It is always capability where something terrible
recommended to update the BIOS to HAL happens during the installation, Windows
capability before installing Win XP. Installer makes sure to take snapshots of
Changing BIOS after installing Win XP has the system before and after the
some serious risks of resulting in an installation. In case of failure it
unbootable OS and should not be attempted rollback's the system to the state how it
without proper back up of data. Microsoft was before. There is also on-demand
advertises the F6 option during this to installation where you can install
install any SCSI/RAID adapters. You can features as needed and required later on
also turn of ACPI by pressing F7 to get a by the system. These can be obtained from
HAL that is not ACPI capable. ACPI can the source on either a media format like
interfere with some features on the a CD or on the network. Source resiliency
machine, for e.g. if the machine is a also enables us to define several source
server type auto shut down would not be targets where you can connect and
really a good feature to implement. The download the files you need incase one
rest of the process is old style mode source is corrupted. You can publish
where you can create and delete application in a domain setting and then
partitions on your hard drive. There is can assign a group or users who can
also the option of choosing between NTFS connect to download and install this
and FAT32. However I would recommend application. Also, you can assign
NTFS, if your hard drive is over 32GB applications to users or groups where the
NTFS is the only choice for you. Windows application doesn't really install itself
XP does all the hard work and jumps into but it places a link or a shortcut of
the GUI mode installation and then asks that application on that terminal for
the user for information like the windows that user to access it and when the user
key, name and regional settings. The most tries to access it the first time it goes
important thing is setting the windows ahead and installs itself using the
administrator password and writing it Windows Installation services. This also
down and keeping it somewhere safe. It enables us to have two different versions
also asks for computer names and network of the same program using two different
configuration and also asks for whether DLL's which can coexist on the same
you are in a domain environment or a terminal in the same hard drive. MSIEXEC
workgroup environment and our IP is the command prompt installer which is
settings. NetBEUI has been disabled in the core of the Windows Installer. There
this version of Microsoft operating are several flags to this command and you
system. You can also enter the hard drive can run this from the command line to
for file access during this installation install those problematic applications.
by pressing Shift+F10. This enables you One of the most important flags is the /f
to move files across the hard drives, which can be used to repair bad
access files you need and even install installations and even find corrupt DLL
drivers for new hardware during files.
installation. For people who want the old User Interface:
style installation you can press Windows XP gives the average user a lot
Shift+F11 for the old style wizard of power with the ease to configure his
settings. Microsoft has also implemented her user interface. Configuring the
dynamic update which means that as long desktop is something you can do almost to
as you have an internet connection it an extreme in Windows XP. Standard
will try to connect and try to download desktop settings remain the same as the
all the updates needed before your ability to change wallpapers, colors and
machine is up and running. It will also sounds. There are also themes and skins
try to install new device drivers, as which can change the entire look the
long as the manufacturer has his drivers Windows XP and work as API's which run on
windows logo certified. However dynamic the machine and not any third party tools
update is only available for updated you need to get. Simple day to day tasks
installs and is not available on clean have been made a lot easier with a folder
installs. Microsoft also enables you and file options available on the left
implement your own dynamic update sites hand side of the windows explorer. The
to prevent clogging of bandwidth in a start menu has become more powerful than
corporate environment for machines it was before. It also incorporates the
searching for updates through the ability to customize itself as per your
Microsoft's website. The admin can link program usability. However for you old
to windows update corporate site and school people Windows XP does give you
download all the updates and package them the option of switching to the old style
together and put it up on a web server desktop or the classic desktop. All you
for the staff to install. A switch can be have to do is right-click and go to
installed inside the setting of the properties and change the theme to
answer file for downloading from these Windows classic to obtain the old style
installs. Another feature is windows Windows look. The appearance tab helps
product activation which does not exist the user pick a color scheme they like
for the volume license user where the best or you could also enter advanced
same media kit is going to be used for mode and pick colors for each part
multiple installs. However retail and OEM yourself. The effects tab is the most
licenses require windows product underused tab which gives the user the
activation by creating a hash of your ability to get cleaner fonts and even
computer depending upon several features remove and set animations on your
like hardware. Windows product activation windows. Most appearances are
can also be done in the answer file and customizable in Windows XP and
the information sent through HTTP or Microsoft's is trying real hard towards a
HTTPS and Microsoft's minimal requirement goal to please every user type.
is that reactivation is required after Interface Options:
changing 3-4 pieces of hardware on your Microsoft has added a lot interface
computer. options for users who otherwise have
Upgrading Windows XP: problems using the computer. One is
Most administrators do not have the accessibility services where Microsoft
luxury to make a clean install because has included several options like the
there are a lot of software and data sticky keys, filter keys or toggle keys
installed on the current operating and even sounds and onscreen keyboard.
system. The biggest drawback to this is There is also a narrator which gives us
that all the legacy code and baggage in text to speech for the visually
the old operating system will be carried challenged. There is also the magnifier
over to the new operating system. An which is also a great asset. An easy way
upgrade is possible from Windows 98/98SE to access the narrator, magnifier and the
ME/2000 and Windows NT 4.0 with SP6. onscreen keyboard is pressing the Windows
However the server class cannot be key + U. Multilingual support has also
upgraded from windows 2000 professional. been included in Windows XP just like as
You cannot upgrade from Windows 95 or in Windows 2000. However, not all
Windows 3.x. A compatibility check should applications support this but you can
always be made before upgrading to the almost enable this all API's. All that is
new OS. Check using the switch required is to head to the regional
(-checkupgradeonly) for hardware report settings in the control panel and install
on compatible hardware on the machine to the language you want to work with the
install windows XP. If you're running remap the keyboard accordingly and you're
Windows NT 4.0 with fault tolerance and done. One drawback is that for other
volume sets the drives are going to be users to use a document created in this
inaccessible once you install XP since it language they must have the same language
does not support fault tolerance or settings installed on their computer. You
volume sets. Microsoft does give you an can even change entire interface of the
easy way to use the key FTONLINE to bring computer into another language by
the fault tolerant set online to backup installing support for that language.
the information or recreate a volume set This servers as a strategic advantage for
or striped volumes and get that global organizations which operate in
information back. However you cannot different regions in terms of saving
create fault tolerant drives with Win XP. space in terms of storing a file in
In a case of serious error you can different languages since multi language
always roll back the upgrade. This support enables us to store only one copy
feature can be accessed from the "Add of the file and have it available in
Remove Programs" in the Control Panel. different languages.
However the biggest drawback is that once Hardware Installation:
you change from FAT32 to NTFS you cannot Windows XP supports plug and play feature
go back to uninstall the upgrade and get where you can just plug in devices and it
your old operating system running. The will detect them automatically without
install procedure is pretty much the same any installations. One of the most
as the once we encountered on a clean important advantages of this feature is
install without the headache of drive that signed drivers are installed
partitioning. It even tries to download automatically without prompting. However,
updates (Dynamic Update) if an internet non plug and play devices require manual
connection is detected. The software and installation. This saves a lot of
regional settings and other user settings headache to the administrator when it
are preserved on the computer. The comes to installing different pieces of
upgrade does come with different view hardware. The user needs to have the
screens after the install. Views change administrative privileges to install
with the kind of environment you are these hardware's and drivers. These can
running in for e.g. a domain environment be maintained to the device manager which
the user gets to see the Ctrl+Alt+Del can be accessed from right clicking my
screen whereas the user gets to see the computers icon. Microsoft is pushing to
welcome screen in a workgroup wears a new setting known as driver
environment. signing. This enables Microsoft to see
Migrating User Settings: what drivers are installed on the system.
User settings are an extremely important In a case of an unsigned driver the user
feature needed in a corporate environment is warned about this before installing it
to preserve the same look for a user. The but he/she can still choose to go ahead
file and transfer settings wizard comes or not go ahead with it. Vendors have to
to our rescue down to the last solitaire actively pursue to get their drivers
icon on the users computer. File and signed by Microsoft to achieve a signed
transfer settings transfer transfers driver rating. In a case of an unsigned
files in four categories. The first driver Microsoft raises a flag which
category is appearance which includes warns the user about the unsigned driver.
color schemes, sounds and others. Second, This can raises several issues in a
it also keeps internet settings like your network for the administrator to handle
favorites and your internet security where people bring in their own USB
settings. Third, it also backs up all devices to plug in to their systems and
your account settings like all your then can raise several flags and
e-mail accounts and all the internet incompatibilities in the environment. The
addresses stored in your machine through administrator can handle this situation
outlook. Finally it even transfer the by disabling and blocking the
settings for installed software's like installation of unsigned drivers. One of
Microsoft office and even third party the drawbacks in windows 2000 was the
software's like adobe. However the ability for a user to modify the registry
drawback is that the required software's keys and install an unsigned driver and
should be installed before their settings then change back the keys after the
can be reapplied to the new operating installation. This loop hole has been
system. The File and Transfer settings fixed by Microsoft and the user is not
wizard can be reached through the windows given the ability to change registry keys
CD by accessing the icon "Perform and hence he cannot install unsigned
Additional Task". The process is simple drivers without administrative
and visually guided. It gives you the permission. One of the other features
option to choose just files or both files that will is the facility of the drivers
and settings and transfer all the or to even roll back drivers incase of a
required files through a direct cable, mishap. Updating device drivers still
floppies/media or network. This can also requires the user to have administrative
be used from XP to XP machines, in a case privileges. However updating device
of customizing a brand new machine to drivers is one of the most frequent
industry standards. However this is