Freakin out a little here....SP2

General software, Operating Systems, and Programming discussion.
Everything from software questions, OSes, simple HTML to scripting languages, Perl, PHP, Python, MySQL, VB, C++ etc.
Post Reply
User avatar
Subsane
Advanced Member
Posts: 688
Joined: Wed Oct 22, 2003 3:43 pm
Location: Vancouver, B.C - Canada

Freakin out a little here....SP2

Post by Subsane »

Someone I work with has informed me of major security issues regarding SP2. Problems with it not allowing Nortan antivirus to do it's job properly and many others. Has anyone heard of Nortan issues and SP2? Something about open ports being left open because windows firewall is blocking nortan? :irate:

I'm running XP Pro with SP2
Nortan system works 2003


Help?

This is an email I received from our corporate techy guy....got me a little worried as I have already installed SP2...

On Friday I sent out a notice about a new exploit vulnerability flaw within the Windows XP operating system. Since then it has come to light that there are serious problems with the Service Pack 2 update for Windows XP. We received an advisory through our Microsoft TechNet subscription that notified us of these problems.

Apparently the Service Pack 2 interferes with the Symantec anti-virus platform, as well as some applications such as AutoCAD and similar programs. Some of these applications are critical and part of the security infrastructure of your computer system.

Microsoft has created a tool that you can access through their TechNet Partner Program site and which we are passing on to you so that you can read more about this problem and disable the Automatic Update feature until December 14th, 2004. By that time Microsoft should have all the bugs ironed out of the update.

For all Windows XP Pro users it is important that they access this site BEFORE August 25th as this is the delivery date set by Microsoft for the SP2 update for XP Pro. The service pack update has already been delivered to XP Home users. If you use any of the programs I have listed please visit the site and disable the automatic download feature before August 25th..

The advisory can be found here: http://members.microsoft.com/partner/pr ... pdate.aspx

The actual download blocking feature is found at this URL: http://www.microsoft.com/technet/prodte ... xpsp2.mspx and is found under the Get the Service Pack heading with the title Block Windows XP SP2 via WU and AU.

If you are not running any of the applications listed and you are still planning to perform the update installation you must take some precautions. You must back up all your crucial data before installing the update.

List of applications affected by SP2:

Programs

Program Vendor Ports Default exception Notes
Visual Studio .NET Microsoft See the documentation See the documentation Needed only for Remote DCOM debugging
SQL Microsoft Dynamically assigned ports for RPC and DCOM Needed only for remote debugging
Backup Exec 9 Veritas 10000 C:\Program Files\Veritas\Backup Exec\RANT32\beremote.exe Needed only to back up a client from a server
Ghost Server Corporate Edition 7.5 Symantec 139-TCP-NetBIOS Session Service; 445-TCP-SMB over TCP; 137-UDP-NetBIOS Name Service; 138-UDP-NetBIOS Datagram Service See the documentation Needed to push down a ghost client
Symantec AntiVirus Corporate Edition 8.0 Symantec File and Printer Sharing Checking the “Allow file and printer sharing” check box opens these ports: UDP 137, 138; TCP 139, 445. Needed to install client
SMS 2003 Server Microsoft Enable File and Printer Sharing ports See the documentation Needed to view Windows XP SP2 Client Event Viewer
Cute FTP 5.0 XP GlobalSCAPE 21 or FTP server See the documentation Needed to FTP in to a Windows XP SP2-based computer
Exceed 7.0, 8.0 Hummingbird 21 or FTP server See the documentation Needed so that FTP for Windows Explorer can connect to remote computers
KEA! 340 5.1 Attachmate 23 or 'Telnet server' See the documentation Needed to establish Telnet session to remote host
WRQ Reflection X 10 and 11 WRQ 23 or 'Telnet server' See the documentation Needed to establish Telnet session to remote host
Reflection for IBM 9, 9.03, 10 and Reflection X 10 and 11 WRQ 21 or FTP server See the documentation Needed so that FTP client can connect to remote computers
Smarterm Office 10 and Smarterm 11 Esker Software 23 or 'Telnet server' See the documentation Needed to establish Telnet session to remote host
Smarterm Office 10 and Smarterm 11 Esker Software 21 or FTP server See the documentation Needed so that the FTP tool can connect to remote computers
ViewNow 1.05 Netmanage FTP server or 21 See the documentation Needed so that FTP tool can connect to remote computers
ViewNow 1.0 and 1.05 Netmanage 6000 (TCP/IP) and 177 (UDP) See the documentation Needed to establish X-Windows Sessions
ViewNow 1 or 1.05 Netmanage Telnet Server or 23 See the documentation Needed to establish Telnet session to remote host
Microsoft Operations Manager 2000 SP1 Microsoft Enable ICMP echo request, File and Printer Sharing and UDP See the documentation Needed to push MOM Agent onto a Windows XP SP2-based client that has Windows Firewall enabled
AutoCAD 2000, 2002, 2004 Autodesk 21 See the documentation Needed to browse projects using FTP viewer (File Open dialog) when remote FTP host has Windows Firewall enabled.
Backup Exec 9.1.4691 Veritas See the documentation %Program Files%\Veritas\Backup Exec\RANT\beremote.exe Needed to back up Windows XP SP2-based client
Windows Scanner and Camera Wizard Xerox Network Scanners 21 See the documentation Needed so that the Scanner and Camera Wizard starts and the scanned images are available for the user to access.
Symantec Corporate AntiVirus 9.0 Symantec See the documentation See the documentation Needed so that while pushing anti virus Definition to clients, the client computer will accept the updates and can be scanned.
ColdFusion MX Server Edition 6 Macromedia TCP (by default, 8500) See the documentation Needed to allow remote access as Web server
CA ARCserve Computer Associates 137-UDP-NetBIOS Name Service; 138-UDP-NetBIOS Datagram Service; 139-TCP-NetBIOS Session Service; 704-UDP; 1478-UDP-MS-sna-base; 1900-UDP-SSDP; 6050-TCP-ARCserve Service; 6051-TCP-ARCserve Service See the documentation Needed for remote installs, licensing, and client communications
EDM File System Agent 4.0 EMC 3895 See the documentation Needed to install EDM client from server to Windows XP SP2
Microsoft Systems Management Server 2003 Microsoft TCP:2701 %WINDIR%\System32\CCM\CLICOMP\RemCtrl\Wuser32.exe Needed so that Remote Tool can remote control a Windows XP SP2-based client computer
Aelita ERdisk for Active Directory 6.7 Quest Software See the documentation File and Printer Sharing Needed to contact a remote computer
Hummingbird Host Explorer 8 Hummingbird 23 TCP and 21 TCP See the documentation Needed to Telnet in to a Windows XP SP2-based client
BV-Admin Mobile Bind View See the documentation File and Printer Sharing Needed to contact a remote computer
SQL 2000a Microsoft 1433 and 1434 See the documentation Needed to connect to remote computer
Backup Exec 8.6.1 Needed so that the server can push remote agent to a Windows XP SP2-based client
Microsoft SNA 4.0 SP3 Microsoft See documentation File and Printer Sharing Needed to see a Windows XP SP2-based client
Extra! Personal Client 6.5 and 6.7 Attachmate Telnet Server or port 23 See the documentation Needed to establish Telnet session to remote host
Extra! Enterprise 2000 Attachmate Telnet Server or port 23 See the documentation Needed to establish Telnet session to remote host
Extra! Bundle for TCP/IP 6.6 Attachmate Telnet Server or port 23 See the documentation Needed to establish Telnet session to remote host
Volume Manager 3.1 Veritas 2148 c:\Progam Files\Veritas\Veritas Object Bus\Bin\vxsvc.exe Needed to connect to a Windows XP SP2-based client
BMC Patrol for Windows 2000 BMC Software On the Windows XP SP2-based (client) computer: TCP ports 3181, 10128 and 25; UDP ports 3181, 10128 and 25 \\<Server Name>\BMC Software\Patrol 3-4\Best1\6.5.00\bgs\bin\Best1CollectGroup.exe Needed to allow connection of server to client computer. Make sure that you have shared the BMC Patrol file on the server before you try to move to the default exception path on the client.
eTrust 6.0.100 Computer Associates File and Printer Sharing ports and ICMP echo request and port TCP 42510 See the documentation Needed to remote install to Windows XP SP2
NetShield 4.5 McAfee Security See the documentation File and Printer sharing Needed to Remote Connect to a Windows XP SP2-based client
Computer Associates eTrust 7.0 Computer Associates Add the File and Printer Sharing ports and ICMP echo request See the documentation Needed so that a Windows Server 2003 eTrust 7.0 server can remotely test logon to a Windows XP SP2-based client
Computer Associates eTrust 7.0 Needed so that a Windows Server 2003 eTrust 7.0 server can remotely install the client eTrust software on Windows XP SP2-based computers. Resolved by setting the following to 0 and then rebooting: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\RPC\RestrictRemoteClients (DWORD value)
Games

Game Vendor Ports Default exception
Chess Advantage III: Lego Chess Encore See the documentation See the documentation
Need for Speed Hot Pursuit 2 EA Games See the documentation See the documentation
Unreal Tournament 2003 Atari See the documentation See the documentation
Unreal Tournament Game of the Year Edition Atari See the documentation See the documentation
Midnight Outlaw: Illegal Street Drag 1.0 VALUSoft See the documentation Defwatch.exe
Scrabble 3.0 Atari See the documentation See the documentation
Star Trek StarFleet Command III 1.0 Activision See the documentation See the documentation
Nothing Safe!
User avatar
earthmofo
Senior Member
Posts: 1128
Joined: Fri Nov 17, 2000 12:00 am
Location: Providence, RI USA

Post by earthmofo »

The tcpip.sys that was included with SP2 had been updated for security reasons. It now allows only 10 concurrent incomplete open outbound connections. It is supposed to help stop the spread of worms and trojans. Applications with many connection attemps may be very slow or not work at all. Even web browsers, eMail clients, P2P or antiviris programs and administrative diagnostic programs can also be affected.

To see if you have a problem look in the event viewer under System for Event ID: 4226. This is from my own event log:

Image

Image

There is a hotfix from Microsoft, Microsoft Knowledge Base Article - 884020, where it allows 50 concurrent open connections but it appears to work for the local host only.

Someone else has patched that hotfix and you can read about it here:

www.lvllord.de

I have used lvllord's patch and I haven't had any problems.
"A never ending quest for knowledge as with knowledge comes wisdom"

Main System running Windows XP Pro: Intel Celeron 2.4 Ghz, 1 Gig Ram, 2 80 gig WD 7200 rpm HD's, Radeon 9200 Pro, Envision EN9110 19" LCD Display, HP 9500 CD-RW, D-Link DFE-530TX+ PCI Adapter, D-Link DI-704P Router, Motorola SB5100 Cable Modem with Cox HSI
Post Reply