Jump to content

Welcome to MSFN Forum
Register now to gain access to all of our features. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more. This message will be removed once you have signed in.
Login to Account Create an Account



Photo

HOWTO create a fully up to date XP x64 DVD (January 2015)

- - - - -

  • Please log in to reply
726 replies to this topic

#726
Kurt_Aust

Kurt_Aust

    Master of trial, error & Google

  • Member
  • PipPipPipPip
  • 565 posts
  • Joined 26-April 07
December updates

Deletions:
Hotfix\328-WindowsServer2003.WindowsXP-KB2478971-x64-ENU.exe
Hotfix\764-WindowsServer2003-KB2998527-x64-ENU.exe
Hotfix\916-IE8-WindowsServer2003.WindowsXP-KB2909210-x64-ENU.exe
Hotfix\920-IE8-WindowsServer2003-KB3003057-x64-ENU.exe

Replace:
# . install_flash_player_ax.exe (link near bottom of page) . . . . 17,541,296 . 16.0.0.235 Updated 9 December

Additions:
@ Hotfix\792-WindowsServer2003-KB3011780-x64-ENU.exe .. . . . . . . . . . . 1,243,352 . MS14-068 - Kerberos
@ Hotfix\796-WindowsServer2003-KB3013126-x64-ENU.exe .. . . . . . . . . . . 2,372,312 . MS14-085 - GDI+
@ Hotfix\800-WindowsServer2003-KB3013410-x64-ENU.exe . . . . . . . . . . . . . 722,136 . Time Zone - Cumulative
@ Hotfix\916-IE8-WindowsServer2003-KB3012176-x64-ENU.exe .. . . . . . . . . . 1,095,896 . MS14-084 - VBScript Engine
# . Hotfix\920-IE8-WindowsServer2003-KB3008923-x64-ENU.exe . . . . . . . . . 22,925,528 . MS14-080 - Cumulative Security Update


Applications:
The latest version of Opera uses the same version of Adobe flash player as Chrome and now cannot be installed prior to user account generation.

As EMET v5.0 is a bit iffy on XP x64 (and 5.1 is completely broken) I've reverted back to 4.1u1. I've also written a new .xml protection profile that fixes the bug listed below as well as adding a number of additional applications to the protected list and fixing compatibility issues in XP x64 (it's always EAF). EMET, while a great idea, seems to suffer the same lack of testing as general Windows Updates of late.

Copy/Paste from Microsoft Technet:
Bug - changing any mitigation via the software.xml protection profiles also disables SEHOP

Bug applies to both 4.1u1 & 5.1 (OS: XP Pro x64 )

Consider this from the "Popular Software.xml" file (4.1u1)

<Product Name="Skype">
<Version Arch="x86" Path="*\Skype\Phone\Skype.exe">
<Mitigation Name="EAF" Enabled="false" />
</Version>
</Product>

For some reason this will also disable SEHOP, in fact any change from the default settings will disable SEHOP, for instance this (from 5.1 popular) will also do it even though it's adding rather than subtracting:

<Product Name="Internet Explorer">
<Version Path="*\Internet Explorer\iexplore.exe">
<Mitigation Name="EAF+" Enabled="true">
<eaf_modules>mshtml.dll;flash*.ocx;jscript*.dll;vbscript.dll;vgx.dll</eaf_modules>
</Mitigation>
<Mitigation Name="ASR" Enabled="true">
<asr_modules>npjpi*.dll;jp2iexp.dll;vgx.dll;msxml4*.dll;wshom.ocx;scrrun.dll</asr_modules>
<!-- 0 = Local; 1 = Intranet; 2 = Trusted; 3 = Internet; 4 = Untrusted; -->
<asr_zones>1;2</asr_zones>
</Mitigation>
</Version>
</Product>

If one adds <Mitigation Name="SEHOP" Enabled="true"/> as the last mitigation for the application, the effect can be overridden, for example:

<Product Name="Skype">
<Version Arch="x86" Path="*\Skype\Phone\Skype.exe">
<Mitigation Name="EAF" Enabled="false" />
<Mitigation Name="SEHOP" Enabled="true"/>
</Version>
</Product>


How to remove advertisement from MSFN

#727
Kurt_Aust

Kurt_Aust

    Master of trial, error & Google

  • Member
  • PipPipPipPip
  • 565 posts
  • Joined 26-April 07
January updates

Deletion:
Hotfix\276-WindowsServer2003.WindowsXP-KB2264107-x64-ENU.exe

Replace:
# . RunOnce\install_flash_player_ax.exe (link near bottom of page) . . . . 17,539,760 . 16.0.0.257 Updated 13 January

Additions:
@ Hotfix\804-WindowsServer2003-KB3020393-x64-ENU.exe . . . . . . . . . . . . . 729,816 . MS15-002 - Telnet
@ Hotfix\808-WindowsServer2003-KB3021674-x64-ENU.exe .. . . . . . . . . . . 1,163,992 . MS15-003 - User Profile
@ Hotfix\812-WindowsServer2003-KB3014029-x64-ENU.exe . . . . . . . . . . . . . 814,296 . MS15-007 - Network RADIUS
@ Hotfix\816-WindowsServer2003-KB3019215-x64-ENU.exe . . . . . . . . . . . . . 796,384 . MS15-008 - Kernel-Mode Driver


A quiet month, not even the usual IE cumulative update. In other Microsoft news they have decided to no longer give advance notification of the number and general types of patches to be released, almost channelling Apple's secretive nature.

Added some notes about the first run of Foxit reader and Vuze bittorrent client/server, most notably Vuze will not find Java if the user account does not have administrator rights on its first run, after the first run one can change the user account to limited without further problems.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users