Mostrando entradas con la etiqueta Lectura Obligada. Mostrar todas las entradas
Mostrando entradas con la etiqueta Lectura Obligada. Mostrar todas las entradas

jueves, 21 de enero de 2010

Security Advisory KB979352

Buenas tardes.Os informo de la próxima publicación de un nuevo boletín de seguridad considerado como Crítico y que afecta a todas las versiones de Internet Explorer, el cual será lanzado hoy 21 de Enero, fuera del ciclo mensual de boletines, debido a su alto impacto y criticidad.

Por este motivo, os recomiendo su revisión y la instalación de la actualización correspondiente.
A continuación os dejo los detalles técnicos de este boletín de seguridad.

--------------------------------------------------------

What is the purpose of this alert?

This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers using Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.

The purpose of the notification is to assist customers with resource planning for this security bulletin release. The information offered in the notification is purposely general in nature to provide enough information for customers to plan for deployment without disclosing vulnerability details or other information that could put them at risk.

New Bulletin Summary
Bulletin Identifier Internet Explorer
Maximum Severity Rating Critical
Impact of Vulnerability Remote Code Execution
Restart Requirement The update will require a restart.
Affected Software All supported versions of Internet Explorer on Windows 2000, Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008*, Windows 7, and Windows Server 2008 R2*.

* Where indicated in the Affected Software table on the Advance Notification Web Page, the vulnerabilities addressed by this update do not affect supported editions of Windows Server 2008 or Windows Server 2008 R2, when installed using the Server Core installation option. Please see the Advance Notification Web page at the link below for more details.

Although we do not anticipate any changes, the information provided in this summary is subject to change until the release.

The full version of the Microsoft Security Bulletin Advance Notification for this release can be found at http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx.

Public Bulletin Webcast

Microsoft will host a webcast to address customer questions on these bulletins:
Title: Information about Microsoft January (OOB) Security Bulletin (Level 200)
Date: Thursday, January 21, 2010, at 1:00 PM Pacific Time (U.S. & Canada).
URL: http://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032440627
At this time no additional information on these bulletins, such as details regarding severity or details regarding the vulnerability, will be made available until the bulletin is published.

Resources related to this alert

1. Security Advisory 979352 – Vulnerability in Internet Explorer Could Allow Remote Code Execution: http://www.microsoft.com/technet/security/advisory/979352.mspx

2. Microsoft Knowledge Base Article 979352: http://support.microsoft.com/kb/979352

3. Issue Landing Page: http://www.microsoft.com/security/updates/ie.aspx

4. Microsoft Security Response Center (MSRC) Blog: http://blogs.technet.com/msrc/

5. Microsoft Security Research & Defense (SRD) Blog: http://blogs.technet.com/srd/

6. Microsoft Malware Protection Center (MMPC) Blog: http://blogs.technet.com/mmpc/

7. Microsoft Security Development Lifecycle (SDL) Blog: http://blogs.msdn.com/sdl/

jueves, 10 de diciembre de 2009

Boletines de seguridad de Diciembre 2009



Este pasado martes Microsoft ha publicado seis boletines de seguridad (del MS09-069 y MS09-074) correspondientes a su ciclo habitual de actualizaciones, que corrigen un total de doce vulnerabilidades. Según la propia clasificación de Microsoft tres de los boletines presentan un nivel de gravedad "crítico", mientras que los tres restantes son "importantes".

Los boletines "críticos" son:

* MS09-071: Actualización destinada a corregir dos vulnerabilidades en el Servicio de autenticación de Internet al tratar los intentos de autenticación PEAP. Sólo están afectados los servidores con el Servicio de Autenticación de Internet cuando usan PEAP con la autenticación MS-CHAP v2. Estos problemas que afectan a Windows 2000, XP, Vista, Server 2003 y Server 2008, podrían permitir la ejecución remota de código.

* MS09-072: Actualización acumulativa para Microsoft Internet Explorer que además soluciona cinco nuevas vulnerabilidades que podrían permitir la ejecución remota de código arbitrario. Afecta a Internet Explorer 5.01, 6, 7 y 8.

* MS09-074: Actualización de seguridad para evitar una vulnerabilidad Microsoft Office Project, que podría permitir la ejecución remota de código si un usuario abre un archivo de Project especialmente creado. Afecta a Project 2000, 2002 y Office Project 2003.

Los boletines clasificados como "importantes" son:

* MS09-069: Actualización destinada a corregir una vulnerabilidad de denegación de servicio, si en un sistema afectado un usuario remoto autenticado envía mediante protocolo IPSEC un mensaje ISAKMP especialmente diseñado al Servicio LSASS (Subsistema de Autenticación de la Autoridad de Seguridad Local).

* MS09-070: Actualización que soluciona dos vulnerabilidades en Servicios de federación de Active Directory (ADFS, Active Directory Federation Services). Un usuario remoto autenticado podría lograr la ejecución remota de código si envía una petición http especialmente diseñada a un servidor web habilitado para ADFS.

* MS09-073: Actualización que soluciona una vulnerabilidad en Microsoft WordPad y Office Word, que podría permitir la ejecución remota de código si un usuario abre un archivo Word 97 específicamente manipulado.

Las actualizaciones publicadas pueden descargarse a través de Windows Update o consultando los boletines de Microsoft donde se incluyen las direcciones de descarga directa de cada parche. Dada la gravedad de las vulnerabilidades se recomienda la actualización de los sistemas con la mayor brevedad posible


Más Información:

Boletín de seguridad de Microsoft MS09-071 - Crítico
Vulnerabilidades en el Servicio de autenticación de Internet podría permitir la ejecución remota de código (974318)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-071.mspx

Boletín de seguridad de Microsoft MS09-072 - Crítico
Actualización de seguridad acumulativa para Internet Explorer (976325)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-072.mspx

Boletín de seguridad de Microsoft MS09-074 - Crítico
Una vulnerabilidad en Microsoft Office Project podría permitir la ejecución remota de código (967183)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-074.mspx

Boletín de seguridad de Microsoft MS09-069 - Importante
Una vulnerabilidad en el servicio del subsistema de autoridad de seguridad local podría permitir la denegación de servicio (974392)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-069.mspx

Boletín de seguridad de Microsoft MS09-070 - Importante
Vulnerabilidades en Servicios de federación de Active Directory podrían permitir la ejecución remota de código (971726)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-070.mspx

Boletín de seguridad de Microsoft MS09-073 - Importante
Una vulnerabilidad en los convertidores de texto de WordPad y Office podría permitir la ejecución remota de código (975539)
http://www.microsoft.com/spain/technet/security/Bulletin/ms09-073.mspx

viernes, 21 de agosto de 2009

Windows Server 2008 R2 Evaluation for Intel-Based, Itanium, Virtual Hard Drive for Hyper-V, and Remote Server Administration Tools for Windows® 7







Windows Server 2008 R2 Evaluation for Itanium-Based Systems (180 days)
Brief Description
Windows Server 2008 R2 builds on the award-winning foundation of Windows Server 2008, expanding existing technology and adding new features to enable organizations to increase the reliability and flexibility of their server infrastructures.

Overview
This software is for evaluation and testing purposes. The evaluation is available in ISO format. Evaluating any version of Windows Server 2008 R2 software does not require entering a product key, however will require activation within 10 days. Failing to activate the evaluation will cause the licensing service to shut the machine down every hour (The 10 day activation period can be reset five (5) times by using the rearm command. See below for further information on activation rearm). Once activated, the evaluation will run for 180 days. After this time, you will need to uninstall the software or upgrade to a fully-licensed version of Windows Server 2008 R2 for Itanium-Based Systems.
This download is also available through our new Download Manager. This will ensure 100% completion rate, and accelerate download times on slower links.
To start this download via the Download Manager, please click here.

http://www.microsoft.com/downloads/en/results.aspx?displaylang=en&period=30&nr=50&sortCriteria=Date&sortOrder=Ascending&stype=s_adv

Windows Server 2008 R2 Evaluation (180 days)
Brief Description
Windows Server 2008 R2 builds on the award-winning foundation of Windows Server 2008, expanding existing technology and adding new features to enable organizations to increase the reliability and flexibility of their server infrastructures.

Overview
This software is for evaluation and testing purposes. The evaluation is available in ISO format. Web, Standard, Enterprise and Datacenter editions are available via the same download. You will be prompted for edition installation at setup. Evaluating any version of Windows Server 2008 R2 software does not require entering a product key, however will require activation within 10 days. Failing to activate the evaluation will cause the licensing service to shut the machine down every hour (The 10 day activation period can be reset five (5) times by using the rearm command. See below for further information on activation rearm). Once activated, the evaluation will run for 180 days. After this time, you will need to uninstall the software or upgrade to a fully-licensed version of Windows Server 2008 R2.
This download is also available through our new Download Manager. This will ensure 100% completion rate, and accelerate download times on slower links.
To start this download via the Download Manager, please click here.

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=96a3a4b4-9453-4d30-97aa-c977560a0da4

Windows Server 2008 R2 Evaluation Virtual Hard Drive Images for Hyper-V (180 Days)
Brief Description
Windows Server 2008 R2 Evaluation Enterprise Edition and Server Core Virtual Hard Drive Images for Hyper-V

Overview
The Microsoft VHD format is the common virtualization file format for Hyper-V that provides a uniform product support system, and provides more seamless manageability, security, reliability and cost-efficiency for customers.
This VHD release is available in English only and is for evaluation and testing purposes. Evaluating any version of Windows Server 2008 R2 software does not require entering a product key, however will require activation within 10 days. Failing to activate the evaluation will cause the licensing service to shut the machine down every hour (The 10 day activation period can be reset four (4) times by using the rearm command. See below for further information on activation rearm). Once activated, the evaluation will run for 180 days. After this time, you will need to uninstall the software or upgrade to a fully-licensed version of Windows Server 2008 R2.
As this installation requires Hyper-V, you will need to have a base install of Windows Server 2008 (64-bit edition) or Windows Server 2008 R2, running Hyper-V. For more information on obtaining and installing the latest version of Hyper-V, please visit the Hyper-V Homepage.
Both virtual machines available here are running Windows Server 2008 R2 Enterprise Edition Evaluation. One is the default full installation, and the other has been configured as a default Core installation. For more information on the difference between full and core installation please see the Windows Server 2008 Editions Overview pages. For download options please see the IMAGE SELECTION section in the instructions below.
As both virtual machines do not have anti-virus installed, they should not be connected to any network until it has anti-virus installed.

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=9040a4be-c3cf-44a5-9052-a70314452305

Remote Server Administration Tools for Windows 7
Brief Description
Remote Server Administration Tools for Windows® 7 enables IT administrators to manage roles and features that are installed on computers that are running Windows Server® 2008 R2, Windows Server® 2008, or Windows Server® 2003, from a remote computer that is running Windows 7.

Overview
Remote Server Administration Tools for Windows 7 enables IT administrators to manage roles and features that are installed on remote computers that are running Windows Server 2008 R2 (and, for some roles and features, Windows Server 2008 or Windows Server 2003) from a remote computer that is running Windows 7. It includes support for remote management of computers that are running either the Server Core or full installation options of Windows Server 2008 R2, and for some roles and features, Windows Server 2008. Some roles and features on Windows Server 2003 can be managed remotely by using Remote Server Administration Tools for Windows 7, although the Server Core installation option is not available with the Windows Server 2003 operating system.
This feature is comparable in functionality to the Windows Server 2003 Administrative Tools Pack and Remote Server Administration Tools for Windows Vista with Service Pack 1 (SP1).

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=7d2f6ad7-656b-4313-a005-4e344e43997d

jueves, 13 de agosto de 2009

Diagnosticos de Directorio Activo con Microsoft IT Environment Health Scanner



Microsoft IT Environment Health Scanner es una herramienta de diagnóstico diseñada para administradores de pequeñas o medianas empresas que necesitan comprobar la salud de sus servidores de directorio y de sus clientes.
Os añado la información original de Microsoft.

This tool identifies common problems that can prevent your network environment from functioning properly as well as problems that can interfere with infrastructure upgrades, deployments, and migration.

When run from a computer with the proper network access, the tool takes a few minutes to scan your IT environment, perform more than 100 separate checks, and collect and analyze information about the following:


- Configuration of sites and subnets in Active Directory
- Replication of Active Directory, the file system, and SYSVOL shared folders
- Name resolution by the Domain Name System (DNS)
- Configuration of the network adapters of all domain controllers, DNS servers, and e-mail servers running Microsoft Exchange Server
-Health of the domain controllers
- Configuration of the Network Time Protocol (NTP) for all domain controllers


If a problem is found, the tool describes the problem, indicates the severity, and links you to guidance at the Microsoft Web site (such as a Knowledge Base article) to help you resolve the problem. You can save or print a report for later review. The tool does not change anything on your computer or your network

System Requirements
Supported Operating Systems: Windows Server 2003 Service Pack 2; Windows Server 2008; Windows Vista Service Pack 1; Windows XP Service Pack 2

Note: make sure that you have installed the latest service packs and Windows operating system updates.

Required Software:

-.NET Framework 2.0
- Minimum Screen Resolution: 800 x 600

Descarga de la Herramienta:

http://www.microsoft.com/downloads/details.aspx?FamilyID=dd7a00df-1a5b-4fb6-a8a6-657a7968bd11&displaylang=en

Video de la Herramienta

jueves, 21 de mayo de 2009

Windows Server 2008 R2 Release Candidate



Estimados todos,
ya está aquí la nueva generación del sistema operativo de Microsoft.
Microsoft Windows Server 2008 R2 RC te permitirá probar y evaluar esta versión.

Overview
This software is for evaluation and testing purposes. Evaluating any version of Windows Server 2008 R2 Release Candidate software does not require product activation or entering a product key. Any edition of Windows Server 2008 R2 Release Candidate may be installed without activation and evaluated for an initial 30 days. If you need more time to evaluate Windows Server 2008 R2 Release Candidate, the initial 30 day evaluation can be extended to March 1, 2010 (at which time the OS will become inoperable) by entering the product key below for your selected edition.
Windows Server 2008 R2 Release Candidate Product Keys for Evaluation
Windows Server 2008 R2 Release Candidate Enterprise

 Product Code : Q7Y83-W4FVQ-6MC6C-6QQTD-TPM88
Windows Server 2008 R2 Release Candidate Standard

 Product Code : V4KRB-QDWK2-GVT4X-BV4XG-34TV4
Windows Server 2008 R2 Release Candidate Datacenter

 Product Code : WXGKX-XXW8X-P8KTJ-PFX7T-DPYYW
Windows Web Server 2008 R2 Release Candidate

 Product Code: RBBKH-BVD6B-74FV9-RYPJ7-TCFXB
Download the evaluation version below. Images are ISO formats. Web, Standard, Enterprise and Datacenter editions are available via the same download Windows_Server_2008_R2_RC_EN.iso

http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=a4e21e2e-e992-4aec-9ed4-086de21632a2

miércoles, 15 de abril de 2009

Disponible la Beta de Microsoft Exchange Server 2010



Estimados todos,
hoy se ha publicado la primera Beta disponible para su descarga y que podréis testear durante 360 días.
Os dejo el enlace de descarga ,las novedades incluidas en ésta Beta, enlaces al sitio de TechNet donde se publicará la documentación técnica y el foro oficial de TechNet.

Microsoft Exchange Server 2010 helps you achieve new levels of reliability and performance by delivering features that help to simplify your administration, protect your communications, and delight your users by meeting their demands for greater business mobility.

http://technet.microsoft.com/en-us/exchange/2010/default.aspx



What’s New in Exchange Server 2010 Beta?

New Rights-Protected E-Mail Functionality with Active Directory RMS
· Transport rules to apply AD RMS protection to messages based on conditions
· Persistent protection of attachments in rights-protected messages
· Support for AD RMS templates
· An Internet confidential AD RMS template for protection over the Internet
· AD RMS protection for Unified Messaging voice mail messages

New Transport and Routing Functionality
· Cross-premises mail routing - An organization can choose to outsource some of their mailboxes to a hosted solution while maintaining their on-premises deployment. Exchange 2010 allows routing of messages between the on-premises and hosted mailboxes.
· Enhanced disclaimers - Exchange 2010 lets you add disclaimers that can include hyperlinks, images, and HTML-formatted text. You can also insert Active Directory attributes that are substituted for the sender's attributes when a disclaimer rule is triggered.
· Transport rules integration with AD RMS - Exchange 2010 gives you the ability to create rules that require AD RMS protection based on keywords or patterns.
· Moderated Transport - Exchange 2010 provides an approval workflow for sending messages to recipients. When you configure a recipient for moderation, all messages sent to that recipient must go through an approval process.
· Shadow redundancy - Messages that are submitted to an Exchange 2010 Hub Transport server are stored in the transport database until the next hop reports successful delivery of the message. If the next hop doesn't report successful delivery and it fails, the message is resubmitted for delivery.
· Transport dumpster truncation based on log copy status - When messages that are in the dumpster are replicated to all mailbox databases, they're removed from the dumpster.
· Latency SLA management - Exchange 2010 Transport lets you measure service levels delivered relative to your service level agreement (SLA) goals. Exchange 2010 gives you the ability to measure latencies for each hop, as well as end-to-end latency.
· Transport database improvements - Performance improvements in the Transport database result in reduced database I/O per second (IOPS) per message, which increases message throughput.

New Permissions Functionality
In Exchange 2010, Role Based Access Control (RBAC) has replaced the permissions model that was used in Exchange 2007. RBAC lets you define extremely broad or extremely precise roles and assignments based on the roles of your administrators and users, and the tasks they perform. Access to the cmdlets and parameters required to perform a task is granted by assigning the related RBAC management role to a user or universal security group. If you want to grant an administrator or user the ability to perform tasks in Exchange 2010, you must either add the administrator or user to a universal security group that already has been assigned a specific RBAC role, or you must assign the role directly to the administrator or user.

New High Availability Functionality
Exchange 2010 combines the key availability and resilience features of cluster continuous replication (CCR) and standby continuous replication (SCR) into a single high availability solution that handles both on-site data replication and off-site data replication. Mailbox servers can be defined as part of a Database Availability Group to provide automatic recovery at the individual mailbox database level instead of at the server level. Each mailbox database can have up to 16 copies.
The following features in Exchange 2007 and Exchange 2007 Service Pack 1 (SP1) no longer exist in Exchange 2010:
· Local continuous replication (LCR)
· Single copy clusters (SCC)

New Messaging Policy and Compliance Features
· Exchange 2010 compliance features make retention independent of users' mailbox management and filing habits, and these features ensure retention policies are applied continuously
· interface for applying retention policies
· Auto tagging for retention policies
· Mailbox search features for cross-mailbox search with Advanced Query Syntax (AQS) support
· New transport rules predicates and actions

New Outlook Web Access Features
· Favorites in the Navigation Pane
· Search folders
· Message filtering
· The ability to set categories in the message list
· Options in the Web management interface for Outlook Web Access
· A side-by-side view for calendars
· Multi-client language support
· The ability to attach messages to messages
· Expanded right-click capabilities
· Integration with Office Communicator, including presence, chat, and a contact list
· Conversation view
· The ability to send and receive text (SMS) messages from Outlook Web Access
· Outlook Web Access mailbox policies

New Unified Messaging Features
· Personal auto attendants (call answering rules)
· Additional language support including in Outlook Voice Access and Voice Mail Preview
· Enhancements to name lookup from caller ID
· Voice Mail Preview
· Messaging Waiting Indicator
· Missed call and voice mail notifications using text messaging (SMS)
· Protected Voice Mail
· Built-in Unified Messaging administrative roles

Web Management Interface
· Text messaging (SMS) integration
· Voice messaging integration
· Mailbox Search
· Distribution list creation and management
· Moderation and approval for distribution list submission

New Exchange Core Store Functionality
· Storage groups are deprecated
· Mailbox databases are no longer connected to the server object
· Extensible Storage Engine (ESE) has many improvements for high availability, performance, and database mobility
· The Store schema has been flattened

New Administration Functionality in the Exchange Management Console
The core EMC refers to new functionality that affects how you use the Exchange Management Console that includes:
· Customer Experience Improvement Program (CEIP)
· Organizational Health
· Community and Resources
· Command logging
· Property dialog command exposure

New Administration Functionality in the Exchange Management Shell
· Remote administration - With the new Shell, you can connect to remote Exchange 2010 servers across the network with only Windows PowerShell V2 CTP3 and Windows Remote Management 2.0 CTP installed.
· Administrator audit logging - Actions that result in the modification of Exchange organization configuration and other object properties in the Exchange Management Console, the Web management interface, and the Shell can now be logged for later review.


FAQ
What is the release schedule for Exchange 2010? That information will be published very soon – stay tuned!
How long does the beta last? This time-limited, free beta version of Microsoft® Exchange Server 2010 will end 360 days after installation.

Can I upgrade from Exchange 2003 directly to Exchange Server 2010?

http://technet.microsoft.com/en-us/library/aa998604(EXCHG.140).aspx

Where can I find more about Exchange Server 2010?

http://technet.microsoft.com/en-us/library/bb124558(EXCHG.140).aspx

Is there a forum where I can ask questions? Yes -

http://social.technet.microsoft.com/Forums/en-US/exchange2010/threads

miércoles, 26 de noviembre de 2008

Lectura Obligada para esta semana (21-11-2008)

Extraido del artículo de Chris Avis , os dejo estos interesantes artículos.


Infrastructure Development, Operations & Maintenance

Active Directory Migration Tool v3.0

Brief Description

The Active Directory Migration Tool version 3 (ADMT v3) provides an integrated toolset to facilitate migration and restructuring tasks in an Active Directory infrastructure.
Overview
The Active Directory Migration Tool version 3 (ADMT v3) simplifies the process of restructuring your operating environment to meet the needs of your organization. You can use ADMT v3 to migrate users, groups, and computers from Microsoft® Windows NT® 4.0 domains to Active Directory® directory service domains; between Active Directory domains in different forests (interforest migration); and between Active Directory domains in the same forest (intraforest migration). ADMT v3 also performs security translation from Windows NT 4.0 domains to Active Directory domains and between Active Directory domains in different forests.
http://www.microsoft.com/downloads/details.aspx?FamilyID=6f86937b-533a-466d-a8e8-aff85ad3d212&DisplayLang=en

Update Rollup 5 for Exchange Server 2007 Service Pack 1 (KB953467)

Brief Description


Update Rollup 5 for Exchange Server 2007 Service Pack 1 (KB953467)

Overview

Update Rollup 5 for Exchange Server 2007 Service Pack 1 (SP1) resolves issues that were found in Exchange Server 2007 SP1 since the software was released. This update rollup is highly recommended for all Exchange Server 2007 SP1 customers. For a list of changes that are included in this update rollup, see KB953467. This update rollup does not apply to Exchange Server 2007 Release To Manufacturing (RTM). For a list of update rollups applicable to Exchange Server 2007 RTM, refer to the section Update rollups for Exchange Server 2007 RTM in the Knowledge Base article KB937052. This is a cumulative update rollup and replaces the following:
KB945684 Update Rollup 1 for Exchange Server 2007 Service Pack 1 (KB945684)
KB948016 Update Rollup 2 for Exchange Server 2007 Service Pack 1 (KB948016)
KB949870 Update Rollup 3 for Exchange Server 2007 Service Pack 1 (KB949870)
KB952580 Update Rollup 4 for Exchange Server 2007 Service Pack 1 (KB952580)
http://www.microsoft.com/downloads/details.aspx?FamilyID=652ed33a-11a1-459c-8ffe-90b9cbfe7903&DisplayLang=en

Microsoft .NET Framework 3.5 Service Pack 1

Brief Description


Microsoft .NET Framework 3.5 Service Pack 1 is a full cumulative update that contains many new features building incrementally upon .NET Framework 2.0, 3.0, 3.5, and includes cumulative servicing updates to the .NET Framework 2.0 and .NET Framework 3.0 subcomponents.
Overview
.NET Framework version 3.5 Service Pack 1 provides the following new features and improvements:
ASP.NET Dynamic Data, which provides a rich scaffolding framework that enables rapid data driven development without writing code, and a new addition to ASP.NET AJAX that provides support for managing browser history (back button support). For more information, see What’s New in ASP.NET and Web Development.
Core improvements to the CLR (common language runtime) that include better layout of .NET Framework native images, opting out of strong-name verification for fully trusted assemblies, improved application startup performance, better generated code that improves end-to-end application execution time, and opting managed code to run in ASLR (Address Space Layout Randomization) mode if supported by the operating system. Additionally, managed applications that are opened from network shares have the same behavior as native applications by running with full trust.
Performance improvements to WPF (Windows Presentation Foundation), including a faster startup time and improved performance for Bitmap effects. Additional functionality for WPF includes better support for line of business applications, native splash screen support, DirectX pixel shader support, and the new WebBrowser control.
ClickOnce application publishers can decide to opt out of signing and hashing as appropriate for their scenarios, developers can programmatically install ClickOnce applications that display a customized branding, and ClickOnce error dialog boxes support links to application-specific support sites on the Web.
The Entity Framework is an evolution of the existing suite of ADO.NET data access technologies. The Entity Framework enables developers to program against relational databases in according to application-specific domain models instead of the underlying database models. For more information, see Getting Started with the Entity Framework. The Entity Framework introduces some additional features, including support for new SQL Server 2008 types, default graph serialization of Entities, and the Entity Data Source. This release of the Entity Framework supports the new date and file stream capabilities in SQL Server 2008. The graph serialization work helps developers who want to build Windows Communication Foundation (WCF) services that model full graphs as data contracts. The Entity Data Source provides a traditional data source experience for ASP.NET Web application builders who want to work with the Entity Framework.
LINQ to SQL includes new support for the new date and file stream capabilities in SQL Server 2008.
The ADO.NET Data Services Framework consists of a combination of patterns and libraries, which enable data to be exposed as a flexible REST (Representational State Transfer)-based data service that can be consumed by Web clients in a corporate network or across the Internet. The ADO.NET Data Services Framework makes data service creation over any data source. A conceptual view model of the underlying storage schema can easily be exposed through rich integration with the ADO.NET Entity Framework. Services created by using the ADO.NET Data Services Framework, and also compatible Windows Live (dev.live.com) services, can be easily accessed from any platform. For client applications that are running on Microsoft platforms, a set of client libraries are provided to make interaction with data services simple. For example, .NET Framework-based clients can use LINQ to query data services and a simple .NET Framework object layer to update data in the service.
Windows Communication Foundation now makes the DataContract Serializer easier to use by providing improved interoperability support, enhancing the debugging experience in partial trust scenarios, and extending syndication protocol support for wider usage in Web 2.0 applications.
The .NET Framework Data Provider for SQL Server (SqlClient) adds new support for file stream and sparse column capabilities in SQL Server 2008.
http://www.microsoft.com/downloads/details.aspx?FamilyID=ab99342f-5d1a-413d-8319-81da479ab0d7&DisplayLang=en

Visual Round Trip Analyzer

Brief Description


Tool to view web page performance Web page performance visualizer and analyzer

Overview

The Visual Round Trip Analyzer tool helps web developers and testers visualize the download of their page, identify best practices and changes that improve web performance. The network Round-Trip between the client and server(s) is the single biggest impact to web page performance – much greater than server response time. VRTA examines the communications protocol, identifying the causes of excessive round-trips, and recommending solutions. Performance engineers, testers, developers, operations personnel should use VRTA to conduct their web performance analysis.
http://www.microsoft.com/downloads/details.aspx?FamilyID=119f3477-dced-41e3-a0e7-d8b5cae893a3&DisplayLang=en

Security, Policy & Compliance

Microsoft® Forefront™ codename "Stirling" Beta

Brief Description

An integrated security system that is easier to manage and control Microsoft® Forefront™ codename "Stirling" is an integrated security system that delivers comprehensive, coordinated protection across endpoints, messaging and collaboration servers and the network edge that is easier to manage and control.
Overview
Microsoft® Forefront™ codename “Stirling” is an integrated security system that delivers comprehensive, coordinated protection across endpoints, messaging and collaboration servers and the network edge that is easier to manage and control. By delivering simplified management and providing critical visibility into threats, vulnerabilities, and configuration risks, Forefront codename "Stirling" helps reduce costs and achieve greater insight into the enterprise security state. At release, “Stirling” will include:
 A central management console and dashboard for security configuration and enterprisewide visibility.
 The next-generation versions of Forefront products: the next generation of Forefront Client Security, Forefront Security for Exchange Server, Forefront Security for SharePoint and the Internet Security & Acceleration Server (to be renamed the Forefront Threat Management Gateway).
 Dynamic Response, an innovative Microsoft technology built into each component of "Stirling" that allows the entire system to share and use security information to dynamically respond to threats across multiple layers of the organization.
http://www.microsoft.com/downloads/details.aspx?FamilyID=65bd5f8a-d94c-457a-9f88-2046597130e1&DisplayLang=en