Windows Security
  Home arrow Windows Security arrow Page 3 - Windows XP Security
ASP Free Forums 
.NET  
ASP  
ASP Code  
ASP.NET  
ASP.NET Code  
BrainDump  
C#  
Code Examples  
Database  
Database Code  
IIS  
Microsoft Access  
MS SQL Server  
Silverlight  
Visual Basic.NET  
Windows Scripting  
Windows Security  
XML  
Mobile Linux 
App Generation ROI 
IBM® developerWorks 
ASP Web Hosting  
ASP.NET Web Hosting 
Windows Web Hosting
 
Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
WINDOWS SECURITY

Windows XP Security
By: Apress Publishing
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 3 stars3 stars3 stars3 stars3 stars / 21
    2005-05-19

    Table of Contents:
  • Windows XP Security
  • Changes to Services
  • List of Windows XP Services
  • Microsoft Baseline Security Analyzer Patch Check and Security Tests
  • File System Security
  • Checkpoints

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    Windows XP Security - List of Windows XP Services


    (Page 3 of 6 )

     

    Table 4-1 contains a nearly complete list of all services that ship with Windows XP and the recommended state that each should be in on your computer, assuming normal office functions are being performed on the machine.

    Table 4-1. Common Services and Recommended Settings

    SERVICE NAMEDESCRIPTIONRECOMMENDED STATE
    AlerterRaises administrative alerts for selected users and computers.Disabled.
    Application Layer Gateway ServiceRequired if you use Internet Connection Sharing (ICS) or XP’s included Internet Connection Firewall to connect to the Internet.Automatic if using ICS; disabled if not.
    Application ManagementUsed to assign, publish, and remove software through Group Policy.Disabled unless you participate in an Active Directory domain.
    Automatic Updates ServicesUsed to check if there are any critical updates available for download.

    Requires Cryptographic to be running. Automatic if you don’t wish to use Windows Update manually.

    Background Intelligent Transfer ServiceUsed by Windows Update to transfer data in the background using otherwise idle available network bandwidth.Disabled.
    ClipBookEnables the ClipBook Viewer to create and share data to be viewed by remote computers.Disabled.
    COM+ Event SystemProvides automatic distribution of events to subscribing programmatic components.Disabled.
    COM+ System ApplicationProvides automatic distribution of events to subscribing programmatic components.Disabled.
    Computer BrowserMaintains an up-to-date list of computers on your network, and supplies the list to programs that request it.Disabled.
    Cryptographic ServicesConfirms signatures of Windows files. Required for Windows Update to function in manual and automatic mode, and required for Windows Media Player as well.Automatic.
    DHCP ClientManages network configuration by registering and updating IP addresses and DNS server information.Automatic if required; disabled if not.
    Distributed Link Tracking ClientMaintains links between the NTFS file system files within a computer or across computers in a network domain.Disabled.
    Distributed Transaction CoordinatorCoordinates transactions that are distributed across multiple computer systems and/or resource managers, such as databases, message queues, file systems, or other transaction-protected resource managers.Disabled.
    DNS ClientResolves and caches DNS names. The DNS client service must be running on every computer that will perform DNS name resolution.Automatic.
    Error Reporting ServiceCalls home to Microsoft when errors occur.Disabled.
    Event LogLogs event messages issued by programs and Windows. This can be useful in diagnosing problems.Automatic.
    Fax ServiceEnables you to send and receive faxes. Disabling this service will render the computer unable to send or receive faxes.Disabled; or don’t install from distribution media.
    TelephonyProvides Java Telephony API (TAPI) support for programs that control telephony devices and IP-based voice connections on the local computer and through the LAN on servers that are also running the service.Disabled unless required.
    FTP Publishing ServiceNot available on Windows XP Home. Not installed by default on Windows XP Pro. Enables FTP service.Disabled; or don’t install from distribution media.
    Help and SupportRequired for Microsoft’s online help documents.Automatic.
    Human Interface Device AccessIf all your devices function then disable it.Disabled.
    IIS AdminNot available on Windows XP Home. Not installed by default on Windows XP Pro. Allows administration of Internet Information Services (IIS).Disabled; or don’t install from distribution media.
    IMAPI CD-Burning COM ServiceUsed for the “drag-and-drop” CD-burn capability. You’ll need this service to burn CDs.Automatic.
    Indexing ServiceIndexes contents and properties of files on local and remote computers and provides rapid access to files through a flexible querying language.Disabled.
    Internet Connection Firewall and Internet Connection SharingProvides network address translation (NAT), addressing and name resolution services for all computers on your home or small-office network through a dial-up or broadband connection.Automatic if sharing connection, disabled if not required.
    IPSEC ServicesManages IP security (IPsec) policy, starts the Internet Key Exchange (IKE), and coordinates IPsec policy settings with the IP security driver.Disabled.
    Logical Disk ManagerWatches Plug & Play events for new drives to be detected and passes volume and/or disk information to the Logical Disk Manager Administrative Service to be configured.
    If disabled, the Disk Management snap-in display will not change when disks are added or removed.
    Manual.
    Logical Disk Manager Administrative ServiceSee previous item’s description.Manual.
    Message QueuingA messaging infrastructure and development tool for creating distributed messaging applications for Windows.Disabled; or don’t install from distribution media.
    Message Queuing TriggersRequired only if you use Message Queuing Service.Disabled; or don’t install from distribution media. Disabled.
    MessengerSends and receives messages to or from users and computers, or those transmitted by administrators or by the Alerter Service.Disabled.
    MS Software Shadow Copy ProviderUsed in conjunction with the Volume Shadow Copy Service. Microsoft Backup uses these services.Enabled.
    NetMeeting Remote Desktop SharingAllows authorized users to remotely access your Windows desktop from another PC over a corporate intranet by using NetMeeting.Disabled.
    Network ConnectionsManages objects in the Network and Dial-Up Connections folder, in which you can view both network and remote connections.Automatic.
    Network DDEUseless service unless you use remote ClipBook.Disabled.
    Network DDE DSDMSee previous item’s description.Disabled.
    Network Location Awareness (NLA)Required for use with the Internet Connection Sharing Service (server only).Disabled unless running ICS or ICF.
    NTLM Security Support ProviderEnables users to log on to the network using the NTLM Authentication Protocol.
    If this service is stopped, users will be unable to log on to the domain and access services. NTLM is used mostly by Windows versions prior to Windows 2000.
    Automatic.
    Performance Logs and AlertsConfigures performance logs and alerts.Disabled.
    Plug & PlayEnables a computer to recognize and adapt to hardware changes with little or no user input.Automatic.
    Portable Media Serial NumberRetrieves serial numbers from portable music players connected to your computer.Disabled.
    Print SpoolerQueues and manages print jobs locally and remotely.
    If you don’t have a printer attached, then disable.
    Automatic.
    Protected StorageProvides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services processes or users.Disabled.
    QoS RSVPProvides network signaling and local, traffic-control functionality.Disabled unless required by your network administrator.
    Remote Access Auto Connection ManagerCreates a connection to a remote network whenever a program references a remote DNS or NetBIOS name or address.Disabled.
    Remote Access Connection ManagerCreates a network connection.Automatic if using Dial-Up Networking; disabled otherwise.
    Remote Desktop Help Session ManagerManages and controls Remote Assistance.Disabled.
    Remote Procedure Call (RPC)Provides the endpoint mapper and other miscellaneous RPC services.Automatic.
    Remote Procedure Call LocatorManages the RPC name service database.Disabled.
    Remote Registry ServiceNot available on Windows XP Home.
    Allows users to connect to a remote registry and read and/or write keys to it—providing they have the required permissions.
    Disabled.
    Removable StorageManages removable media drives and libraries.
    This service maintains a catalog of identifying information for removable media used by a system, including tapes, CDs, and so on.
    Disabled.
    RIP ListenerNot installed by default.Disabled; or don’t install from distribution media.
    Routing and Remote AccessOffers routing services in local area and wide area network environments.Disabled; or don’t install from distribution media.
    Secondary LogonAllows you to run specific tools and programs with different permissions than your current logon provides.Automatic.
    Security Accounts ManagerStartup of this service signals other services that the Security Accounts Manager subsystem is ready to accept requests.Automatic.
    ServerProvides RPC support and file print and named pipe sharing over the network. The Server Service allows the sharing of your local resources (such as disks and printers) so that other users on the network can access them.Automatic if you’re sharing files; disabled if not.
    Shell Hardware DetectionUsed for the autoplay of devices like memory cards, some CD drives, and so on.Disabled unless required.
    Simple Mail Transport Protocol (SMTP)Transports email across the network.Disabled; or don’t install from distribution media.
    Simple TCP/IP ServicesImplements support for a number of IP protocols.Disabled; or don’t install from distribution media.
    Smart CardManages and controls access to a smart card inserted into a smart card reader attached to the computer.Disabled unless using a smart card reader.
    Smart Card HelperProvides support for earlier smart card readers attached to the computer.Disabled unless using a smart card reader.
    SNMP ServiceAllows Simple Network Management Protocol (SNMP) requests to be serviced by the local computer.Disabled; or don’t install from distribution media.
    SNMP Trap ServiceReceives trap messages generated by local or remote SNMP agents and forwards the messages to SNMP management programs running on the computer.Disabled; or don’t install from distribution media.
    SSDP Discovery ServiceUsed to locate UPnP devices on your home network.Disabled.
    System Event NotificationTracks system events such as Windows logon network and power events.Disabled.
    System Restore ServiceCreates system snapshots or restore points for returning to at a later time.Disabled.
    Task SchedulerEnables a program to run at a designated time.Disabled unless absolutely required.
    TCP/IP NetBIOS Helper ServiceEnables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Only required if you need to share files with others.Disabled unless sharing is enabled.
    TCP/IP Printer ServerUsed for setting up a local UNIX print server.Disabled; or don’t install from distribution media.
    TelephonyProvides Telephony API (TAPI) support for programs that control telephony devices and IP-based voice connections on the local computer and through the LAN on servers that are also running the service.Disabled.
    TelnetAllows a remote user to log on to the system and run console programs by using the command line.Disabled; or don’t install from distribution media.
    Terminal ServicesProvides a multisession environment that allows client devices to access a virtual Windows 2000 Professional desktop session and Windows-based programs running on the server.Disabled; or don’t install from distribution media.
    ThemesUsed to display all those new XP themes and colors on your desktop. Lots of space needed.Automatic or manual, depending on your preferences.
    Uninterruptible Power Supply (UPS)Used in conjunction with SSDP Discovery Service, it detects and configures UPnP devices on your home network.Disabled unless using a UPS.
    Universal Plug & Play Device HostUsed in conjunction with SSDP Discovery Service, it detects and configures UPnP devices on your home network.Disabled.
    Upload ManagerAs with BITS, this service manages file transfers between clients and servers on the network. This service is NOT required for basic File and Print sharing.Disabled.
    Volume Shadow CopyUsed in conjunction with the MS Software Shadow Copy Provider Service. Microsoft Backup uses these services.Disabled.
    WebClientDisable this for security reasons.Disabled.
    Windows AudioUsed to produce audio.Automatic.
    Windows Image Acquisition (WIA)Used for some scanners and cameras.
    If, after disabling this service, your scanner or camera fails to function properly, enable this service.
    Disabled.
    Windows InstallerInstalls, repairs, or removes software according to instructions contained in MSI files provided with the applications.Manual.
    Windows Management Instrumentation (WMI)Provides system management information. WMI is an infrastructure for building management applications and instrumentation shipped as an integral part of the current generation of Microsoft operating systems.Automatic.
    Windows Management Instrumentation Driver ExtensionTracks all of the drivers that have registered WMI information to publish.Manual.
    Windows TimeSets the computer clock. W32Time maintains date and time synchronization on all computers running on a Microsoft Windows network.Automatic.
    Wireless Zero ConfigurationAutomatic configuration for wireless network devices.Disabled.
    WMI Performance AdapterOptimizes the speed of WMI queries.Disabled.
    WorkstationProvides network connections and communications.
    If this service is turned off, no network connections can be made to remote computers using Microsoft Networks.
    Automatic.
    World Wide Web Publishing ServiceProvides HTTP services for applications on the Windows platform.Disabled; or don’t install from distribution media.

    As you can see from the previous list, not very much is actually needed to keep your Windows XP installation functioning in a home environment. Most of the enabled services just pose an enormous security risk, bring little or no benefit, consume resources, and can be safely turned off.

    More Windows Security Articles
    More By Apress Publishing


       · I am still waiting for that day when Windows will not allow viruses to execute on my...
       · then u must be waiting for the windows untill u r breath.
       · maybe you meant.... don't hold your breath?
     

    Buy this book now. This article is taken from chapter four of the book Hardening Windows, written by Jonathan Hassell (Apress, 2004; ISBN: 1590592662). Check it out at your favorite bookstore. Buy this book now.

    WINDOWS SECURITY ARTICLES

    - Which Version of Windows 7 Should You Use?
    - Choosing the Best Windows XP Firewall
    - Finding the Correct Drivers for Windows XP D...
    - Windows Network Troubleshooting: Tips and Te...
    - Windows XP Home Network Setup: Essential Ste...
    - Using Windows Recovery Console to Fix Blue S...
    - Fix Blue Screen of Death in Windows XP: Corr...
    - Storing Data with Windows Skydrive
    - Windows System Administrator`s Toolbox
    - Solving Windows Genuine Advantage Problems
    - Encrypted Browsing in Windows using OpenSSH
    - Working with the Hosts File on Windows XP
    - Inventorying HDDs Remotely on Windows
    - Inventorying RAMs Remotely on Windows
    - Vital Windows Security Guidelines





    © 2003-2009 by Developer Shed. All rights reserved. DS Cluster 1 Hosted by Hostway
    For more Enterprise Application Development news, visit eWeek