i guess no ones touched "raw sockets" yet. in case u dont know what raw sockets are (on any OS), this 'featre' provides full and direct "packet level" Internet access to any Unix sockets programmer.(grc.com) as opposed to win9x which lacked the ability to send raw packets, this open a whole new door to DoS from compromised windows boxes. once a windows 9x box was compromised, they are used to do massive ping floods or other benign packets (since the hacker didnt have raw access) with. although ping floods are largely inneficient they can be used en-masse to create a competent DDoS. with raw sockets, these DoS packets could be anything the hacker wants to send, creating a very powerful platform for DDoS.
now to stop the threat of raw sockets, microsoft would have to implement perfect security in WinXP home edition. as anyone who has seen a scan for open file shares, the home users are morons. they will break the security of the system, especially if microsoft follows its past levels of security. so with raw sockets feature, every compromised windows xp will serve as a brutally effective DDoS platform. in a corporate setting, where win2k was targeted, raw sockets are rather harmless since most companies have minimally competent IT staff. but if XP is targeted and shipped to home users, they will not know how to secure their box. so now we have significantly more powerful boxes falling into the hands of malicious hackers.
before i get flamed, remember im not criticizing win2k/xp's level of security if its properly implemented (my win2k box is safe). im saying that a large number of home users allow their systems to be compromised since they lack understanding of how to protect themselves. raw sockets also exist in *nix machines, but more people who use *nix know how to protect themselves than the AVERAGE windows users.
hopefully, if they do ship with raw sockets (which they will), i hope the first big attack will be against microsoft.com. it would be fitting.