rem this script is used to update sniffer rulbase
rem most of this was ibased on / inspired by what other users posted on this list, I thanks everybody for their inputs


rem it calls wget, fgrep, imail1, gzip, snf2check
rem it checks for new files, and can be used by both alias trigger or sheduler
rem it uses compression
rem it checks for error at almost every stage and report result
rem I use alias, but also schedule it once a day, just in case
rem It creates files for last success, failure, ...
rem It email the result of the operation to the admin


The command for the alias is:
E:\sniffer\Scripts\SNFRupdt.bat  > E:\sniffer\Scripts\alias.txt

I have Imail rule to forward the sniffer notification to that alias (with extensive security)

The script is attached,
I will try to answer questions if any
Below is a sample email i get from updater:


mar. 28/12/2004 21:38:16,14 ****** F:\Imail\spool\tmpA568.tmp ****** 21:40:44,93 Renaming and testing gzip OK errorlevel 0 New Rule File Found and Extracted Testing with Snf2check Snf2check Files tested good mar. 28/12/2004 21:40:45,58 Copying and Replacing Files updated successfuly 21:40:46,99 Reloading Sniffer RuleBase mar. 28/12/2004 21:40:48,99 ****** --21:38:16-- http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf => `adcdefg.snf' Resolving www.sortmonster.net... 216.88.37.61 Connecting to www.sortmonster.net[216.88.37.61]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 11,160,480 [application/x-sortmonster] Remote file is newer, retrieving. --21:38:26-- http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf => `adcdefg.snf' Connecting to www.sortmonster.net[216.88.37.61]:80... connected. HTTP request sent, awaiting response... 200 OK Length: 3,181,882 [application/x-sortmonster]

0K .......... .......... .......... .......... .......... 1% 3.23 KB/s
50K .......... .......... .......... .......... .......... 3% 7.05 KB/s
100K .......... .......... .......... .......... .......... 4% 10.29 KB/s
150K .......... .......... .......... .......... .......... 6% 7.69 KB/s
200K .......... .......... .......... .......... .......... 8% 9.27 KB/s
250K .......... .......... .......... .......... .......... 9% 15.46 KB/s
300K .......... .......... .......... .......... .......... 11% 20.51 KB/s
350K .......... .......... .......... .......... .......... 12% 16.67 KB/s
400K .......... .......... .......... .......... .......... 14% 16.00 KB/s
450K .......... .......... .......... .......... .......... 16% 19.63 KB/s
500K .......... .......... .......... .......... .......... 17% 24.81 KB/s
550K .......... .......... .......... .......... .......... 19% 26.01 KB/s
600K .......... .......... .......... .......... .......... 20% 29.36 KB/s
650K .......... .......... .......... .......... .......... 22% 24.24 KB/s
700K .......... .......... .......... .......... .......... 24% 24.43 KB/s
750K .......... .......... .......... .......... .......... 25% 20.78 KB/s
800K .......... .......... .......... .......... .......... 27% 25.39 KB/s
850K .......... .......... .......... .......... .......... 28% 29.36 KB/s
900K .......... .......... .......... .......... .......... 30% 30.47 KB/s
950K .......... .......... .......... .......... .......... 32% 33.69 KB/s
1000K .......... .......... .......... .......... .......... 33% 36.79 KB/s
1050K .......... .......... .......... .......... .......... 35% 38.08 KB/s
1100K .......... .......... .......... .......... .......... 37% 39.53 KB/s
1150K .......... .......... .......... .......... .......... 38% 40.49 KB/s
1200K .......... .......... .......... .......... .......... 40% 41.56 KB/s
1250K .......... .......... .......... .......... .......... 41% 42.12 KB/s
1300K .......... .......... .......... .......... .......... 43% 49.21 KB/s
1350K .......... .......... .......... .......... .......... 45% 49.21 KB/s
1400K .......... .......... .......... .......... .......... 46% 48.50 KB/s
1450K .......... .......... .......... .......... .......... 48% 37.20 KB/s
1500K .......... .......... .......... .......... .......... 49% 32.01 KB/s
1550K .......... .......... .......... .......... .......... 51% 29.09 KB/s
1600K .......... .......... .......... .......... .......... 53% 35.95 KB/s
1650K .......... .......... .......... .......... .......... 54% 37.65 KB/s
1700K .......... .......... .......... .......... .......... 56% 40.00 KB/s
1750K .......... .......... .......... .......... .......... 57% 41.56 KB/s
1800K .......... .......... .......... .......... .......... 59% 44.44 KB/s
1850K .......... .......... .......... .......... .......... 61% 45.70 KB/s
1900K .......... .......... .......... .......... .......... 62% 43.25 KB/s
1950K .......... .......... .......... .......... .......... 64% 46.38 KB/s
2000K .......... .......... .......... .......... .......... 65% 50.81 KB/s
2050K .......... .......... .......... .......... .......... 67% 49.21 KB/s
2100K .......... .......... .......... .......... .......... 69% 54.23 KB/s
2150K .......... .......... .......... .......... .......... 70% 52.47 KB/s
2200K .......... .......... .......... .......... .......... 72% 58.21 KB/s
2250K .......... .......... .......... .......... .......... 74% 58.14 KB/s
2300K .......... .......... .......... .......... .......... 75% 56.18 KB/s
2350K .......... .......... .......... .......... .......... 77% 59.24 KB/s
2400K .......... .......... .......... .......... .......... 78% 43.25 KB/s
2450K .......... .......... .......... .......... .......... 80% 35.16 KB/s
2500K .......... .......... .......... .......... .......... 82% 37.65 KB/s
2550K .......... .......... .......... .......... .......... 83% 38.08 KB/s
2600K .......... .......... .......... .......... .......... 85% 26.01 KB/s
2650K .......... .......... .......... .......... .......... 86% 22.08 KB/s
2700K .......... .......... .......... .......... .......... 88% 30.47 KB/s
2750K .......... .......... .......... .......... .......... 90% 26.44 KB/s
2800K .......... .......... .......... .......... .......... 91% 34.06 KB/s
2850K .......... .......... .......... .......... .......... 93% 31.99 KB/s
2900K .......... .......... .......... .......... .......... 94% 35.97 KB/s
2950K .......... .......... .......... .......... .......... 96% 39.00 KB/s
3000K .......... .......... .......... .......... .......... 98% 39.53 KB/s
3050K .......... .......... .......... .......... .......... 99% 45.05 KB/s
3100K ....... 100% 39.07 KB/s


21:40:44 (24.66 KB/s) - `adcdefg.snf' saved [3181882/3181882]

***********************************************
***********************************************
Received: from mnr1.microneil.com [216.88.36.96] by mail.domaine.com with ESMTP
(SMTPD32-8.14) id A2371F5E0042; Tue, 28 Dec 2004 21:37:59 +0000
Received: by mnr1.microneil.com (Postfix, from userid 93)
id 423393F20C7; Tue, 28 Dec 2004 16:37:56 -0500 (EST)
X-SortMonster-MessageSniffer-Rules: snfrv2r3-v2-3.2
0-74524-1-371-m
0-74524-1-371-f
X-SortMonster-MessageSniffer-Result: 0
Received: from Simple_Mailer_Message (MNR7.MicroNeil.com [216.88.36.18])
by mnr1.microneil.com (Postfix) with ESMTP id 123343F20C1
for <[EMAIL PROTECTED]>; Tue, 28 Dec 2004 16:37:55 -0500 (EST)
Message-ID: <[EMAIL PROTECTED]>
Date: Tue, 28 Dec 2004 20:37:54 +0000
From: [EMAIL PROTECTED]
Subject:adcdefg.snf Update 20041228.2037
To: [EMAIL PROTECTED]
X-RBL-Warning: NOLEGITCONTENT: No content unique to legitimate E-mail detected.
X-RBL-Warning: Failed GIBBERISH Filter
X-RBL-Warning: SIZE-S: Message failed SIZE-S: 11.
X-Declude-Sender: [EMAIL PROTECTED] [216.88.36.96]
X-Declude-Spoolname: Dd2361f5e0042c4bd.SMD
Organization: domaine Internet (Incoming)
X-domaine-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for spam.
X-domaine-Note: Declude version: 1.81
X-domaine-Note: Spam-Tests-Failed: NOLEGITCONTENT [0], GIBBERISH [3], SIZE-S [0], CATCHALLMAILS [0]
X-domaine-Note: weight: -1
X-domaine-Note: This E-mail was sent from mnr1.microneil.com ([216.88.36.96]).
X-domaine-Note: Country Chain: UNITED STATES->destination
X-domaine-Note: MailFrom: [EMAIL PROTECTED]


The adcdefg.snf rule base has been updated.

This is your unique rulebase and license ID.

The authentication code for this license is:

12345678901234

We recommend that you cut and paste this authentication code to avoid
ERROR_RULE_AUTH conditions.

Please see the following URL for installation instructions:

http://www.sortmonster.com/MessageSniffer/Installation/HowTo.html

You can download your rulebase file at:

http://www.sortmonster.net/Sniffer/Updates/adcdefg.snf

or

ftp://ftp.sortmonster.net/adcdefg.snf

Login with: sniffer, ki11sp8m

The file is 11160480 bytes and contains 94438 rules.

For the latest software distribution:

http://www.sortmonster.net/Sniffer/Updates/sniffer-2.tar.gz

or

ftp://ftp.sortmonster.net/sniffer-2.tar.gz

Down/Up-load automation starter scripts for windows are available in
this file (you will need to modify them for your use):

http://www.sortmonster.net/Sniffer/Updates/WindowsTools.zip

or

ftp://ftp.sortmonster.net/WindowsTools.zip

Please upload your Message Sniffer log files daily to
ftp.sortmonster.net

Login With: snifferlog, ki11sp8m

THANKS!
-Support

rem this script is used to update sniffer rulbase
rem most of this was inspired by other users posted on this list, I thanks 
everybody for their inputs

rem it calls wget, gzip, fgrep, and snf2check, imail1
rem it checks for new files, and can be used by both alias trigger or sheduler
rem it uses compression
rem it checks for  error at almost every stage and report
rem I use alias, but also schedule it oncce a day, just in case
rem It creates files for last success, failure, ...
rem It email the result of the operation to the admin



SETLOCAL

rem Set the full path to this file and to wget, gzip, fgrep, and snf2check.

SET DDdrv=E:
SET DDdir=\sniffer\scripts\
SET DD=%DDdrv%%DDdir%


rem Set the full path to your IMail directory. SET IMailDir=E:\imail

rem Set the full path to you Sniffer directory.
set snifferdir=E:\sniffer\

rem Set the e-mail address you would like script results sent to.
SET [EMAIL PROTECTED]

rem Set e-mail "from" domain for your script results.
SET FromDom=domain.net

:CheckDirectories
if not exist %DD% goto end

%DDdrv%
cd %DD%

echo %date% > %DD%mail.txt
echo %time% >> %DD%mail.txt
echo ****** >> %DD%mail.txt
echo %1 >> %DD%mail.txt
echo ****** >> %DD%mail.txt

:goto step2

%DD%wget -N http://www.sortmonster.net/Sniffer/Updates/abcdefg.snf --tries=10 
--wait=5 --random-wait -o %DD%result.txt --header=Accept-Encoding:gzip 
--http-user=sniffer --http-passwd=ki11sp8m

if errorlevel 1 goto wgeterr1
if not exist abcdefg.snf goto nosnf

fgrep "Server file no newer than local file" %DD%result.txt
if not errorlevel 1 goto nonewff

:step2
fgrep "`abcdefg.snf' saved" %DD%result.txt
if not errorlevel 1 goto newff

echo cas wget non prevu >> %DD%mail.txt

goto END


:newff echo %time% >> %DD%mail.txt echo Renaming and testing >> %DD%mail.txt rename abcdefg.snf abcdefg.snf.gz gzip -d -f -t abcdefg.snf.gz

if errorlevel 0 goto gziperr0
if errorlevel 1 goto gziperr1

GOTO END

:gziperr0
Echo gzip OK errorlevel 0 >> %DD%mail.txt
gzip -d -f abcdefg.snf.gz
GOTO New

GOTO END

:gziperr1
Echo gzip errorlevel 1 >> %DD%mail.txt
Echo gzip .gz file did not test OK >> %DD%mail.txt
GOTO END



:New
ECHO New Rule File Found
ECHO New Rule File Found and Extracted >> %DD%mail.txt
ECHO Testing with Snf2check >> %DD%mail.txt

snf2check.exe %DownloadDir%abcdefg.snf k8andq7fxqxgqwj7

if errorlevel 1 goto FileNotGood

echo New File Tested GOOD!
ECHO Snf2check Files tested good >> %DD%mail.txt
ECHO %Date% >> %DD%mail.txt
ECHO %Time% >> %DD%mail.txt

ECHO Copying and Replacing >> %DD%mail.txt

if exist %snifferdir%abcdefg.old del %snifferdir%abcdefg.old
if exist %snifferdir%abcdefg.tmp del %snifferdir%abcdefg.tmp

copy /V /Y abcdefg.snf %snifferdir%abcdefg.tmp

rename %snifferdir%abcdefg.snf abcdefg.old
rename %snifferdir%abcdefg.tmp abcdefg.snf

ECHO Files updated successfuly >> %DD%mail.txt
ECHO %Time% >> %DD%mail.txt

ECHO Reloading Sniffer RuleBase >> %DD%mail.txt
%SNIFFERDIR%abcdefg.exe reload

goto end

:FileNotGood
ECHO Snf2check File abcdefg.snf tested not good >> %DD%mail.txt
ECHO %Time% >> %DD%mail.txt

GOTO END

:wgeterr1
Echo Error level 1 from Wget > %DD%mail.txt
Echo       >> %DD%mail.txt
goto END

:nosnf
Echo no abcdefg.snf file found > %DD%mail.txt
Echo       >> %DD%mail.txt
goto END

:nonewff
Echo no new abcdefg.snf file found on remote server >> %DD%mail.txt
Echo ********      >> %DD%mail.txt
Echo ********      >> %DD%mail.txt
goto END


:END

echo %date% >> %DD%mail.txt
echo %time% >> %DD%mail.txt
echo ****** >> %DD%mail.txt

Type result.txt >> %DD%mail.txt

if not exist %1 goto email
echo ***********************************************>> %DD%mail.txt
echo ***********************************************>> %DD%mail.txt
type %1>> %DD%mail.txt
del %1

:email
rem Remove "rem" from the next line if you would like to receive the script results via e-mail.
%IMailDir%\imail1 -f %DD%mail.txt -s "Sniffer update on mail.domain.com" -t %MailTo% -u postmaster rem -h %FromDom%



cd\


ENDLOCAL



Reply via email to