her er scriptene:
hfcheck.wsf:
<package>
<Job id=\"HotfixCheck\">
<script language=\"JScript\" src=\"notify.js\"/>
<script language=\"JScript\">
///////////////////////////////////////////////////////////////////////////////////////////
// CONSTANTS
var HOTFIX= 1;
var WORKAROUND= 2;
var MISSINGINFO= 3;
///////////////////////////////////////////////////////////////////////////////////////////
// Global variables
var DEBUG= 0;
var SHORTNAME = \"HFCHECK\";
var NAME = \"Hotfix Check Script\";
var VERSION = \"1.00 \";
// Hardcoded path, can be changed to intranet URL via commandline parameter /B
var g_BulletinPath = \"
http://www.microsoft.com/technet/security/search/bulletins.xml\";;// FileSystemObject
var g_oFSO;
// XMLDOM object that contains newest hotfix information
var g_oRemXML;
// HFCHECK Version 1.0 is limited to IIS 5.0 only. IIS has ID 15
var g_ID= 15;
var g_Machines = \"\";
var g_User = \"\";
var g_Password = \"\";
///////////////////////////////////////////////////////////////////////////////////////////
//Call main
main();
///////////////////////////////////////////////////////////////////////////////////////////
// main
// loads bulletins.xml file and checks it against locally installed hotfixes
function main()
{
// Check if CSCRIPT.EXE is default engine. Otherwise the script shows dozens of MessageBoxes
if (WScript.FullName.toUpperCase().indexOf(\"CSCRIPT.EXE\")==-1)
{
WScript.Echo(\"CSCRIPT.EXE needs to be default script engine. Change via CSCRIPT.EXE //H:Cscript\");
WScript.Quit();
}
get_args();
banner();
try {
g_oFSO = new ActiveXObject(\"Scripting.FileSystemObject\");
g_oRemXML = new ActiveXObject(\"microsoft.xmldom\");
g_objNet = new ActiveXObject(\"WScript.Network\");
g_oRemXML.async = false;
}
catch(exception)
{
WScript.Echo (\"HFCHECK couldn\'t load necessary ActiveX controls. \");
WScript.Echo (\"This might happen if the machine runs on Windows NT. \\nHFCHECK requires Windows 2000.\");
WScript.Quit();
}
// ValidateArgs relies on instantiated ActiveX Controls above
if (!ValidateArgs(g_objNet.ComputerName))
{
WScript.Echo(\"\\n\");
ShowUsage();
WScript.Quit();
}
Debug(\"Loading \" + g_BulletinPath);
try {
if (g_oRemXML.load(g_BulletinPath) == false)
{
Echo(\"Cannot load \" + g_BulletinPath);
return;
}
// Get the product name (HFCHECK Version 1.0 will display IIS 5.0)
var product = g_oRemXML.selectSingleNode(\"bulletins/products/product[@id=\\\"\" + g_ID + \"\\\"]\");
}
catch(exception)
{
WScript.Echo (\"Exception occurred while loading\\n\" + g_BulletinPath + \"\\n\" + g_BulletinPath + \".\");
WScript.Echo (\"Be sure your browser settings are correct.\\n\");
WScript.Echo (\"To verify, try to load\\n\" + g_BulletinPath + \"\\nin your browser.\");
WScript.Quit();
}
// if we were able to load the bulletins file, we do the actual check
CheckHotfixStatus();
//Legal();
}
///////////////////////////////////////////////////////////////////////////////////////////
// CheckHotfixStatus
// Finds all applied hotfixes via WMI
// and compares them against bulletins.xml. Calls Notify, if a mandatory hotfix is
// not found.
function CheckHotfixStatus()
{
var oXMLFileList,oFileNode, oKBNodes;
var arrHF, strHF;
var sTitle, sBulletin, sLink;
var oQ, oTemp;
var oPreSP, sPreSP;
var aMachines;
var nNotFound = true;
Debug(\"Comparing downloaded XML file with current installation.\");
if (g_Machines != null)
aMachines = g_Machines.split(\",\");
else
{
aMachines = new Array(objNet.ComputerName);
}
for (var i=0;i<aMachines.length;i++)
{
// Do some initial checks
if (aMachines[i] == \"\")
aMachines[i] = g_objNet.ComputerName;
if (!InitialChecks(aMachines[i]))
{
WScript.Echo(\"Hotfix check for machine \" + aMachines[i] + \" failed.\\n\");
continue;
}
Debug(\"Getting SP Version\");
// Get the current Service Pack version
var nSP = GetSPVersion(aMachines[i]);
if (nSP == -1)
{
WScript.Echo(\"Hotfix check for machine \" + aMachines[i] + \" failed.\");
continue;
}
try {
var nHFFound = 0;
// Get the currently installed hotfixes from WMI
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(aMachines[i],\"\",g_User, g_Password );
var arrHF = new Enumerator (Service.InstancesOf(\"Win32_QuickFixEngineering\"));
// only check for the IIS5 hotfixes (ID=15)
oXMLFileList = g_oRemXML.selectNodes(\"bulletins/*/bulletin/affected[$any$ id $eq$ \" + g_ID + \"]\");
oFileNode = new Enumerator(oXMLFileList);
// Compare the hotfixes found via WMI with the hotfixes mentioned in bulletins.xml
for (; !oFileNode.atEnd(); oFileNode.moveNext())
{
var par = oFileNode.item().parentNode;
oTemp = par.selectSingleNode(\"number\");
if (oTemp != null)
sBulletin = oTemp.text;
oTemp = par.selectSingleNode(\"title\");
if (oTemp != null)
sTitle = oTemp.text;
oTemp = par.selectSingleNode(\"ulr\");
if (oTemp != null)
sLink = oTemp.text;
oQ = par.selectNodes(\"kb\");
if (oQ.length == 0)
{
// We can\'t compare if kb field is empty, because the kb number is our key
Notify(MISSINGINFO, sBulletin, sTitle, sLink,aMachines[i]);
nHFFound++;
continue;
}
try {
sPreSP = par.selectSingleNode(\"presp\").text;
}
catch(exception)
{
// if no SP is mentioned, we assume that the HF gets fixed in SP1
sPreSP = \"1\";
}
oKBNode = new Enumerator(oQ);
// Look if a WORKAROUND attribute exists. If yes, we report it and continue with the next
// item in the for loop
for (; !oKBNode.atEnd(); oKBNode.moveNext())
{
try {
if (oKBNode.item().attributes.getNamedItem(\"workaround\").text == \"1\")
{
Notify (WORKAROUND,sBulletin,sTitle,sLink,aMachines[i]);
nHFFound++;
continue;
}
}
catch(exception)
{
// don\'t care
}
}
//Continue, if a SP is installed that already includes the Hotfix
if (nSP >= sPreSP)
continue;
nNotFound = true;
// Iterate through all the hotfixes we found installed on the system
// and compare them with the hotfixes that are required.
oKBNode.moveFirst();
for (; !oKBNode.atEnd(); oKBNode.moveNext())
{
arrHF.moveFirst();
for (;!arrHF.atEnd();arrHF.moveNext())
{
if ( arrHF.item().HotfixID == oKBNode.item().text)
{
nNotFound = false;
break;
}
}
}
if (nNotFound == true)
{
nHFFound++;
Notify (HOTFIX, sBulletin, sTitle, sLink,aMachines[i]);
}
}
if (nHFFound==0)
WScript.Echo(\"No missing Hotfix found.\");
}
catch(exception)
{
WScript.Echo (\"Exception occurred while accessing \" + aMachines[i] + \": \" + exception.description);
continue;
}
} // end of machine for loop
}
///////////////////////////////////////////////////////////////////////////////////////////
// GetSPVersion()
// Gets the currently installed Service Pack version from WMI
// and returns it.
function GetSPVersion(strMachine)
{
try
{
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(strMachine,\"\",g_User, g_Password );
var e = new Enumerator (Service.InstancesOf(\"Win32_OperatingSystem\"));
for (;!e.atEnd();e.moveNext())
{
return e.item().ServicePackMajorVersion;
}
return -1;
}
catch(exception)
{
WScript.Echo(\"Exception occured in GetSPVersion: \" + exception.description);
return -1;
}
}
///////////////////////////////////////////////////////////////////////////////////////////
// IsIISInstalled()
// returns true if IIS 5.0 is installed
// false if not
function IsIISInstalled(strMachine)
{
Debug(\"Checking if IIS is installed\");
var strSrv;
try {
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(strMachine,\"\",g_User, g_Password );
var e = new Enumerator (Service.InstancesOf(\"Win32_Service\"));
for (;!e.atEnd();e.moveNext())
{
strSrv = e.item().Name;
if (strSrv.toUpperCase() == \"W3SVC\")
return true;
}
return false;
}
catch(exception)
{
WScript.Echo(\"Exception occured in IsIISInstalled function: \" + exception.description);
return false;
}
}
///////////////////////////////////////////////////////////////////////////////////////////
// GetOSSVersion
// returns current OS version as string.
function GetOSVersion(strMachine)
{
try {
Debug(\"Getting the OS version\");
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(strMachine,\"\",g_User, g_Password);
var e = new Enumerator (Service.InstancesOf(\"Win32_OperatingSystem\"));
for (;!e.atEnd();e.moveNext())
{
return e.item().Version;
}
}
catch(exception)
{
WScript.Echo(\"GetOSVersion failed: \" + exception.description);
}
return \"\";
}
///////////////////////////////////////////////////////////////////////////////////////////
// CanConnect
// returns false if we can\'t connect to the specified machine
function CanConnect(strMachine)
{
try {
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(strMachine,\"\",g_User, g_Password );
}
catch(exception)
{
return false;
}
return true;
}
///////////////////////////////////////////////////////////////////////////////////////////
// IsServer
// returns true if machine is W2K Server, false if not
// DTC?
function IsServer(strMachine)
{
try
{
var Locator = new ActiveXObject(\"WbemScripting.SWbemLocator\");
var Service = Locator.ConnectServer(strMachine,\"\",g_User, g_Password );
var e = new Enumerator (Service.InstancesOf(\"Win32_OperatingSystem\"));
for (;!e.atEnd();e.moveNext())
{
if (e.item().Caption.search(/Server/i) >= 0)
return true;
}
return false;
}
catch(exception)
{
return false;
}
}
///////////////////////////////////////////////////////////////////////////////////////////
// InitialChecks()
// exits program if environment doesn\'t meet requirements
function InitialChecks(strMachine)
{
// Check if interactive user is Admin. We need to be admin
if (!CanConnect(strMachine))
{
WScript.Echo(\"\\nCan\'t connect to machine \" + strMachine);
WScript.Echo(\"\\nYou might want to check the following:\");
WScript.Echo(\"a) Is your password correct?\");
WScript.Echo(\"b) Did you use the right machinename?\");
WScript.Echo(\"c) Did you specify the username in the right format? \");
WScript.Echo(\" DOMAINNAME\\\\USERNAME or COMPUTERNAME\\\\USERNAME\\n\");
return false;
}
// Check if IIS is installed
if (!IsIISInstalled(strMachine))
{
WScript.Echo(\"\\nIIS is not installed on \" + strMachine + \".\");
return false;
}
// Check if it is 5.0 or higher
var strOSVer = GetOSVersion(strMachine);
if ( strOSVer.search(/5.0/i) != 0)
{
WScript.Echo(\"\\nCurrently only IIS 5.0 on Windows 2000 is supported. You run Windows \" + strOSVer + \" on \" + strMachine + \".\");
return false;
}
if (!IsServer(strMachine))
{
WScript.Echo(\"\\n\" + strMachine + \" is not a Windows 2000 Server. Currently only Windows 2000 Server machines are supported.\");
return false;
}
return true;
}
////////////////////////////////////////////////////////////////////////////////////////////////////
function banner() {
WScript.echo(\"\\n\\n\\n\");
WScript.echo(\"---------------------------------------------------\");
WScript.echo(\"| \" + SHORTNAME + \" \" + NAME + \" \" + VERSION + \" |\");
WScript.echo(\"| Thomas Deml (thomad@microsoft.com) |\");
WScript.echo(\"---------------------------------------------------\\n\");
}
function Debug(strDebug)
{
if (DEBUG == 1)
{
WScript.Echo(\"DEBUG: \" + strDebug);
}
}
///////////////////////////////////////////////////////////////////////////////////////////
// get_args()
// checks the commandline parameters. If user entered /B, g_BulletinsPath gets overwritten.
function get_args()
{
var args = WScript.Arguments;
try
{
for (var i = 0; i < args.Count(); i++)
{
switch (args(i))
{
case \"-?\" :
case \"/?\" :
banner();
WScript.Echo(\"HFCHECK.WSF checks if all necessary \\nIIS 5.0 hotfixes are installed on this machine.\\n\");
ShowUsage();
WScript.Quit();
break;
case \"/B\":
case \"/b\":
case \"-B\":
case \"-b\":
// Might fail if user forgot to add path after /B -> args(i+1) fails
try {
g_BulletinPath = args(i+1);
}
catch(e)
{
banner();
ShowUsage();
}
break;
case \"/M\":
case \"/m\":
case \"-M\":
case \"-m\":
// Might fail if user forgot to add path after /B -> args(i+1) fails
try {
g_Machines = args(i+1);
}
catch(e)
{
banner();
ShowUsage();
}
break;
case \"/U\":
case \"/u\":
case \"-U\":
case \"-u\":
// Might fail if user forgot to add path after /B -> args(i+1) fails
try {
g_User = args(i+1);
}
catch(e)
{
banner();
ShowUsage();
}
break;
case \"/P\":
case \"/p\":
case \"-P\":
case \"-p\":
// Might fail if user forgot to add path after /B -> args(i+1) fails
try {
g_Password = args(i+1);
}
catch(e)
{
g_Password = \"\";
}
break;
}
}
}
catch (e)
{
WScript.echo(\"ERROR: failure to read command-line arguments. Error is \" + e.description);
WScript.Quit();
}
}
///////////////////////////////////////////////////////////////////////////////////////////
// ValidateArgs()
// Validates if all parameters are given
// We have to check due to the following WMI limitations
// WMI ConnectServer function: The strPassword and strUser parameter should only be used
// with connections to remote WMI servers.
// If you attempt to specify strPassword for a local WMI connection, the connection attempt fails.
function ValidateArgs( strComputerName)
{
Debug(\"In ValidateArgs\");
if (g_Machines != \"\")
{
var aMachines = g_Machines.split(\",\");
for (var i=0;i<aMachines.length;i++)
{
if (aMachines[i] == \"\" || aMachines[i].toUpperCase() == strComputerName.toUpperCase())
{
WScript.Echo(\"Local machine name not allowed as machine parameter.\");
return false;
}
}
}
if (g_User != \"\" && g_Machines == \"\")
{
WScript.Echo(\"You can\'t specify a username for checking the local machine.\");
return false;
}
if (g_Password != \"\" && g_Machines == \"\")
{
WScript.Echo(\"You can\'t specify a password for checking the local machine.\");
return false;
}
if (g_Password != \"\")
{
if (g_User == \"\")
{
WScript.Echo(\"You need to specify a username if you specify a password. \");
return false;
}
}
return true;
}
///////////////////////////////////////////////////////////////////////////////////////////
// ShowUsage()
// Shows usage if commandline parameters are incorrect
function ShowUsage()
{
WScript.Echo(\"Usage: \" + WScript.ScriptName + \" </B path to bulletin> </M machine1,machine2>\");
WScript.Echo(\" </U domain\\\\username OR computername\\\\username> </P password> </?>\");
WScript.Echo(\"\\nExample 1: \\\"\" + WScript.ScriptName + \"\\\"\");
WScript.Echo(\"Shows missing IIS 5.0 hotfixes on local machine\\n\");
WScript.Echo(\"Example 2: \\\"\" + WScript.ScriptName + \" /B
http://myserver/bulletins.xml\\\"\");
WScript.Echo(\"Uses different bulletin path.\\n\");
WScript.Echo(\"Example 3: \\\"\" + WScript.ScriptName + \" /M iis1,iis2,iis3 /U IISMain\\\\Administrator /P mypw\\\"\");
WScript.Echo(\"Shows missing hotfixes on machine iis1, iis2 and iis3. Specified username and\\npassword are used to access remote machines.\\n\");
//Legal();
WScript.Quit();
}
///////////////////////////////////////////////////////////////////////////////////////////
// Legal()
// Shows legal statement
function Legal()
{
WScript.Echo(\"\\n\\n\\n-------------------------------------------------------------------------------\");
WScript.Echo(\"|THE INFORMATION PROVIDED IN THIS TOOL IS PROVIDED \\\"AS IS\\\" WITHOUT WARRANTY OF|\");
WScript.Echo(\"|ANY KIND. MICROSOFT DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, |\");
WScript.Echo(\"|INCLUDING THE WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |\");
WScript.Echo(\"|PURPOSE. IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE |\");
WScript.Echo(\"|FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, |\");
WScript.Echo(\"|CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT|\");
WScript.Echo(\"|CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH |\");
WScript.Echo(\"|DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY |\");
WScript.Echo(\"|FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY NOT |\");
WScript.Echo(\"|APPLY. |\");
WScript.Echo(\"| |\");
WScript.Echo(\"|(c) 2000 Microsoft Corporation. All rights reserved. |\");
WScript.Echo(\"-------------------------------------------------------------------------------\");
}
</script>
</Job>
</package>
notify.js:
// NOTIFY.JS
// Description:
// Notify.js can be customized by the user
// Right now it reports a missing hotfix on commandline and writes an event to the eventlog
// But it is also possible to generate a mail, halt IIS or generate other events that are
// relevant to administrators.
function Notify(type,sBulletin, sTitle, sLink, sMachine)
{
var oShell = new ActiveXObject(\"WScript.Shell\");
switch(type)
{
// consts (for instance HOTFIX) are declared in HFCHECK.WSF
case HOTFIX:
WScript.Echo(\"\\nMissing Hotfix on Machine \" + sMachine + \" Detected:\\nMicrosoft Security Bulletin (\" + sBulletin + \")\\n\" + sTitle + \"\\nLink:
http://www.microsoft.com\" + sLink);
oShell.LogEvent(2,\"Missing Hotfix on Machine \" + sMachine + \" Detected:\\nMicrosoft Security Bulletin (\" + sBulletin + \")\\n\" + sTitle + \"\\nLink:
http://www.microsoft.com\" + sLink);
break;
case WORKAROUND:
WScript.Echo(\"\\nWorkaround Notification for Machine \" + sMachine + \":\\nMicrosoft Security Bulletin (\" + sBulletin + \" )\\n\" + sTitle + \"\\nLink:
http://www.microsoft.com\" + sLink);
oShell.LogEvent(2,\"Workaround Notification for Machine \" + sMachine + \":\\nMicrosoft Security Bulletin (\" + sBulletin + \" )\\n\" + sTitle + \"\\nLink:
http://www.microsoft.com\" + sLink);
break;
case MISSINGINFO:
WScript.Echo(\"\\nHotfix Warning for Machine \" + sMachine + \":\\nUnable to verify hotfix install \\nMicrosoft Security Bulletin (\" + sBulletin + \")\\nLink:
http://www.microsoft.com\" + sLink);
oShell.LogEvent(2,\"Hotfix Warning for Machine \" + sMachine + \":\\nUnable to verify hotfix install \\nMicrosoft Security Bulletin (\" + sBulletin + \")\\nLink:
http://www.microsoft.com\" + sLink);
break;
}
}
---------------------------------
Efter hvad det står skal skal jeg også kunne sende en mail med den, men det vil den ikke, hvor fanden skal det scripts sættes ind for at få det til at funke??