rem most of this was ibased on / inspired by what other users posted on this list, I thanks everybody for their inputs
rem it calls wget, fgrep, imail1, gzip, snf2check
rem it checks for new files, and can be used by both alias trigger or sheduler
rem it uses compression
rem it checks for error at almost every stage and report result
rem I use alias, but also schedule it once a day, just in case
rem It creates files for last success, failure, ...
rem It email the result of the operation to the admin
The command for the alias is: E:\sniffer\Scripts\SNFRupdt.bat > E:\sniffer\Scripts\alias.txt
I have Imail rule to forward the sniffer notification to that alias (with extensive security)
The script is attached, I will try to answer questions if any Below is a sample email i get from updater:
mar. 28/12/2004 21:38:16,14 ****** F:\Imail\spool\tmpA568.tmp ****** 21:40:44,93 Renaming and testing gzip OK errorlevel 0 New Rule File Found and Extracted Testing with Snf2check Snf2check Files tested good mar. 28/12/2004 21:40:45,58 Copying and Replacing Files updated successfuly 21:40:46,99 Reloading Sniffer RuleBase mar. 28/12/2004 21:40:48,99 ****** --21:38:16-- http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf => `adcdefg.snf' Resolving www.sortmonster.net... 216.88.37.61 Connecting to www.sortmonster.net[216.88.37.61]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 11,160,480 [application/x-sortmonster] Remote file is newer, retrieving. --21:38:26-- http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf => `adcdefg.snf' Connecting to www.sortmonster.net[216.88.37.61]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 3,181,882 [application/x-sortmonster]
0K .......... .......... .......... .......... .......... 1% 3.23 KB/s
50K .......... .......... .......... .......... .......... 3% 7.05 KB/s
100K .......... .......... .......... .......... .......... 4% 10.29 KB/s
150K .......... .......... .......... .......... .......... 6% 7.69 KB/s
200K .......... .......... .......... .......... .......... 8% 9.27 KB/s
250K .......... .......... .......... .......... .......... 9% 15.46 KB/s
300K .......... .......... .......... .......... .......... 11% 20.51 KB/s
350K .......... .......... .......... .......... .......... 12% 16.67 KB/s
400K .......... .......... .......... .......... .......... 14% 16.00 KB/s
450K .......... .......... .......... .......... .......... 16% 19.63 KB/s
500K .......... .......... .......... .......... .......... 17% 24.81 KB/s
550K .......... .......... .......... .......... .......... 19% 26.01 KB/s
600K .......... .......... .......... .......... .......... 20% 29.36 KB/s
650K .......... .......... .......... .......... .......... 22% 24.24 KB/s
700K .......... .......... .......... .......... .......... 24% 24.43 KB/s
750K .......... .......... .......... .......... .......... 25% 20.78 KB/s
800K .......... .......... .......... .......... .......... 27% 25.39 KB/s
850K .......... .......... .......... .......... .......... 28% 29.36 KB/s
900K .......... .......... .......... .......... .......... 30% 30.47 KB/s
950K .......... .......... .......... .......... .......... 32% 33.69 KB/s
1000K .......... .......... .......... .......... .......... 33% 36.79 KB/s
1050K .......... .......... .......... .......... .......... 35% 38.08 KB/s
1100K .......... .......... .......... .......... .......... 37% 39.53 KB/s
1150K .......... .......... .......... .......... .......... 38% 40.49 KB/s
1200K .......... .......... .......... .......... .......... 40% 41.56 KB/s
1250K .......... .......... .......... .......... .......... 41% 42.12 KB/s
1300K .......... .......... .......... .......... .......... 43% 49.21 KB/s
1350K .......... .......... .......... .......... .......... 45% 49.21 KB/s
1400K .......... .......... .......... .......... .......... 46% 48.50 KB/s
1450K .......... .......... .......... .......... .......... 48% 37.20 KB/s
1500K .......... .......... .......... .......... .......... 49% 32.01 KB/s
1550K .......... .......... .......... .......... .......... 51% 29.09 KB/s
1600K .......... .......... .......... .......... .......... 53% 35.95 KB/s
1650K .......... .......... .......... .......... .......... 54% 37.65 KB/s
1700K .......... .......... .......... .......... .......... 56% 40.00 KB/s
1750K .......... .......... .......... .......... .......... 57% 41.56 KB/s
1800K .......... .......... .......... .......... .......... 59% 44.44 KB/s
1850K .......... .......... .......... .......... .......... 61% 45.70 KB/s
1900K .......... .......... .......... .......... .......... 62% 43.25 KB/s
1950K .......... .......... .......... .......... .......... 64% 46.38 KB/s
2000K .......... .......... .......... .......... .......... 65% 50.81 KB/s
2050K .......... .......... .......... .......... .......... 67% 49.21 KB/s
2100K .......... .......... .......... .......... .......... 69% 54.23 KB/s
2150K .......... .......... .......... .......... .......... 70% 52.47 KB/s
2200K .......... .......... .......... .......... .......... 72% 58.21 KB/s
2250K .......... .......... .......... .......... .......... 74% 58.14 KB/s
2300K .......... .......... .......... .......... .......... 75% 56.18 KB/s
2350K .......... .......... .......... .......... .......... 77% 59.24 KB/s
2400K .......... .......... .......... .......... .......... 78% 43.25 KB/s
2450K .......... .......... .......... .......... .......... 80% 35.16 KB/s
2500K .......... .......... .......... .......... .......... 82% 37.65 KB/s
2550K .......... .......... .......... .......... .......... 83% 38.08 KB/s
2600K .......... .......... .......... .......... .......... 85% 26.01 KB/s
2650K .......... .......... .......... .......... .......... 86% 22.08 KB/s
2700K .......... .......... .......... .......... .......... 88% 30.47 KB/s
2750K .......... .......... .......... .......... .......... 90% 26.44 KB/s
2800K .......... .......... .......... .......... .......... 91% 34.06 KB/s
2850K .......... .......... .......... .......... .......... 93% 31.99 KB/s
2900K .......... .......... .......... .......... .......... 94% 35.97 KB/s
2950K .......... .......... .......... .......... .......... 96% 39.00 KB/s
3000K .......... .......... .......... .......... .......... 98% 39.53 KB/s
3050K .......... .......... .......... .......... .......... 99% 45.05 KB/s
3100K ....... 100% 39.07 KB/s
21:40:44 (24.66 KB/s) - `adcdefg.snf' saved [3181882/3181882]
***********************************************
***********************************************
Received: from mnr1.microneil.com [216.88.36.96] by mail.domaine.com with ESMTP
(SMTPD32-8.14) id A2371F5E0042; Tue, 28 Dec 2004 21:37:59 +0000
Received: by mnr1.microneil.com (Postfix, from userid 93)
id 423393F20C7; Tue, 28 Dec 2004 16:37:56 -0500 (EST)
X-SortMonster-MessageSniffer-Rules: snfrv2r3-v2-3.2
0-74524-1-371-m
0-74524-1-371-f
X-SortMonster-MessageSniffer-Result: 0
Received: from Simple_Mailer_Message (MNR7.MicroNeil.com [216.88.36.18])
by mnr1.microneil.com (Postfix) with ESMTP id 123343F20C1
for <[EMAIL PROTECTED]>; Tue, 28 Dec 2004 16:37:55 -0500 (EST)
Message-ID: <[EMAIL PROTECTED]>
Date: Tue, 28 Dec 2004 20:37:54 +0000
From: [EMAIL PROTECTED]
Subject:adcdefg.snf Update 20041228.2037
To: [EMAIL PROTECTED]
X-RBL-Warning: NOLEGITCONTENT: No content unique to legitimate E-mail detected.
X-RBL-Warning: Failed GIBBERISH Filter
X-RBL-Warning: SIZE-S: Message failed SIZE-S: 11.
X-Declude-Sender: [EMAIL PROTECTED] [216.88.36.96]
X-Declude-Spoolname: Dd2361f5e0042c4bd.SMD
Organization: domaine Internet (Incoming)
X-domaine-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for spam.
X-domaine-Note: Declude version: 1.81
X-domaine-Note: Spam-Tests-Failed: NOLEGITCONTENT [0], GIBBERISH [3], SIZE-S [0], CATCHALLMAILS [0]
X-domaine-Note: weight: -1
X-domaine-Note: This E-mail was sent from mnr1.microneil.com ([216.88.36.96]).
X-domaine-Note: Country Chain: UNITED STATES->destination
X-domaine-Note: MailFrom: [EMAIL PROTECTED]
The adcdefg.snf rule base has been updated.
This is your unique rulebase and license ID.
The authentication code for this license is:
12345678901234
We recommend that you cut and paste this authentication code to avoid ERROR_RULE_AUTH conditions.
Please see the following URL for installation instructions:
http://www.sortmonster.com/MessageSniffer/Installation/HowTo.html
You can download your rulebase file at:
http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf
or
ftp://ftp.sortmonster.net/adcdefg.snf
Login with: sniffer, ki11sp8m
The file is 11160480 bytes and contains 94438 rules.
For the latest software distribution:
http://www.sortmonster.net/Sniffer/Updates/sniffer-2.tar.gz
or
ftp://ftp.sortmonster.net/sniffer-2.tar.gz
Down/Up-load automation starter scripts for windows are available in this file (you will need to modify them for your use):
http://www.sortmonster.net/Sniffer/Updates/WindowsTools.zip
or
ftp://ftp.sortmonster.net/WindowsTools.zip
Please upload your Message Sniffer log files daily to ftp.sortmonster.net
Login With: snifferlog, ki11sp8m
THANKS! -Support
rem this script is used to update sniffer rulbase rem most of this was inspired by other users posted on this list, I thanks everybody for their inputs
rem it calls wget, gzip, fgrep, and snf2check, imail1 rem it checks for new files, and can be used by both alias trigger or sheduler rem it uses compression rem it checks for error at almost every stage and report rem I use alias, but also schedule it oncce a day, just in case rem It creates files for last success, failure, ... rem It email the result of the operation to the admin
SETLOCAL
rem Set the full path to this file and to wget, gzip, fgrep, and snf2check.
SET DDdrv=E: SET DDdir=\sniffer\scripts\ SET DD=%DDdrv%%DDdir%
rem Set the full path to your IMail directory. SET IMailDir=E:\imail
rem Set the full path to you Sniffer directory. set snifferdir=E:\sniffer\
rem Set the e-mail address you would like script results sent to. SET [EMAIL PROTECTED]
rem Set e-mail "from" domain for your script results. SET FromDom=domain.net
:CheckDirectories if not exist %DD% goto end
%DDdrv% cd %DD%
echo %date% > %DD%mail.txt echo %time% >> %DD%mail.txt echo ****** >> %DD%mail.txt echo %1 >> %DD%mail.txt echo ****** >> %DD%mail.txt
:goto step2
%DD%wget -N http://www.sortmonster.net/Sniffer/Updates/abcdefg.snf --tries=10 --wait=5 --random-wait -o %DD%result.txt --header=Accept-Encoding:gzip --http-user=sniffer --http-passwd=ki11sp8m
if errorlevel 1 goto wgeterr1 if not exist abcdefg.snf goto nosnf
fgrep "Server file no newer than local file" %DD%result.txt if not errorlevel 1 goto nonewff
:step2 fgrep "`abcdefg.snf' saved" %DD%result.txt if not errorlevel 1 goto newff
echo cas wget non prevu >> %DD%mail.txt
goto END
:newff echo %time% >> %DD%mail.txt echo Renaming and testing >> %DD%mail.txt rename abcdefg.snf abcdefg.snf.gz gzip -d -f -t abcdefg.snf.gz
if errorlevel 0 goto gziperr0 if errorlevel 1 goto gziperr1
GOTO END
:gziperr0 Echo gzip OK errorlevel 0 >> %DD%mail.txt gzip -d -f abcdefg.snf.gz GOTO New
GOTO END
:gziperr1 Echo gzip errorlevel 1 >> %DD%mail.txt Echo gzip .gz file did not test OK >> %DD%mail.txt GOTO END
:New ECHO New Rule File Found ECHO New Rule File Found and Extracted >> %DD%mail.txt ECHO Testing with Snf2check >> %DD%mail.txt
snf2check.exe %DownloadDir%abcdefg.snf k8andq7fxqxgqwj7
if errorlevel 1 goto FileNotGood
echo New File Tested GOOD! ECHO Snf2check Files tested good >> %DD%mail.txt ECHO %Date% >> %DD%mail.txt ECHO %Time% >> %DD%mail.txt
ECHO Copying and Replacing >> %DD%mail.txt
if exist %snifferdir%abcdefg.old del %snifferdir%abcdefg.old if exist %snifferdir%abcdefg.tmp del %snifferdir%abcdefg.tmp
copy /V /Y abcdefg.snf %snifferdir%abcdefg.tmp
rename %snifferdir%abcdefg.snf abcdefg.old rename %snifferdir%abcdefg.tmp abcdefg.snf
ECHO Files updated successfuly >> %DD%mail.txt ECHO %Time% >> %DD%mail.txt
ECHO Reloading Sniffer RuleBase >> %DD%mail.txt %SNIFFERDIR%abcdefg.exe reload
goto end
:FileNotGood ECHO Snf2check File abcdefg.snf tested not good >> %DD%mail.txt ECHO %Time% >> %DD%mail.txt
GOTO END
:wgeterr1 Echo Error level 1 from Wget > %DD%mail.txt Echo >> %DD%mail.txt goto END
:nosnf Echo no abcdefg.snf file found > %DD%mail.txt Echo >> %DD%mail.txt goto END
:nonewff Echo no new abcdefg.snf file found on remote server >> %DD%mail.txt Echo ******** >> %DD%mail.txt Echo ******** >> %DD%mail.txt goto END
:END
echo %date% >> %DD%mail.txt echo %time% >> %DD%mail.txt echo ****** >> %DD%mail.txt
Type result.txt >> %DD%mail.txt
if not exist %1 goto email echo ***********************************************>> %DD%mail.txt echo ***********************************************>> %DD%mail.txt type %1>> %DD%mail.txt del %1
rem Remove "rem" from the next line if you would like to receive the script results via e-mail.
%IMailDir%\imail1 -f %DD%mail.txt -s "Sniffer update on mail.domain.com" -t %MailTo% -u postmaster rem -h %FromDom%
cd\
ENDLOCAL
