About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Window Manager
Brian Livingston

Putting XP in the zone

I GET A LOT fewer messages from readers saying how happy they are with Windows XP and a lot more messages saying how they're grappling with one or another new behavior they hadn't expected.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
The latest example of this love/hate relationship involves readers who've installed the software firewall called ZoneAlarm. It's my product of choice to protect users against zombie and Trojan horse software that gets into your PC and silently connects to the Internet for advertising or more nefarious purposes. ZoneAlarm permits only programs on a user-defined list to call home across the Net.

So far, so good. But readers are, well, alarmed that the firewall's default configuration allows components of Windows XP to silently connect with Microsoft's servers without displaying an alert. One reader installed ZoneAlarm to augment XP's weaker, built-in firewall, removed all named programs and components from ZoneAlarm's OK list, and then rebooted. But XP could still contact the mother ship.

This is a concern because Microsoft added numerous features to XP that report information about you or your activities to centralized databases. I wrote four months ago that XP contains a dozen or so components that automatically connect to the Internet (See "Sneaky service packs"). Microsoft describes 11 of these programs in a white paper that's available at www.microsoft.com/WindowsXP/pro/techinfo/administration/manageautoupdate.

Windows Media Player in XP, for example, reports to a Microsoft server every DVD movie you play, including its title and a string that uniquely identifies your player (http://online.securityfocus.com/archive/1/257283).

ZoneAlarm product manager Jordy Berson explains that the firewall's standard behavior is by design and isn't necessarily a problem. If you install ZoneAlarm using its quick-start wizard, the XP file named SvcHost.exe is recognized as a standard component of Microsoft's operating system. Because XP is considered legitimate, and not a Trojan horse, XP features that use SvcHost to connect to the Internet do not trigger warning alerts if ZoneAlarm is set up this way.

"By us preconfiguring those hosts, we're making sure that people can connect to the Internet properly," Berson said in an interview. "If people want to configure it manually, they can do that also."

Stripping down ZoneAlarm's list of permitted programs, however, isn't the best way to defeat XP applications you don't like. I recommend instead that you use Administrative Tools to disable each unwanted XP service. A step-by-step tutorial for this is at www.blkviper.com/WinXP/supertweaks.htm (the address is case-sensitive). I discussed this method at length a couple of months ago(see "Services with a smile,").

There may be a lot of things we can find about XP to criticize, but we can't expect ZoneAlarm to fix them all.


Brian Livingston is co-author of 10 Windows Secrets books. Send tips to brian@secretspro.com. Subscribe to Window Manager and E-Business Secrets at www.iwsubscribe.com/newsletters.




RELATED ARTICLES

Sneaky service packs


RELATED SUBJECTS

Security
Operating Systems

Click here for all of Brian Livingston's past columns.


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no