'=============
'Initialize MOM Scripting Variables
'=============
Dim oAPI
Set oAPI = CreateObject("Mom.ScriptAPI")
If Err <> 0 Then
Wscript.Quit -1
End If
'=============
'Helper methods
'=============
' Method: CreateEvent
' Description: Logs Event
' Parameters: source, eventId, eventtype(error/warning/info/success), errormsg
'=============
Sub CreateEvent(lngEventID, lngEventType, strMsg)
Call oAPI.LogScriptEvent(EVENT_SOURCE, lngEventID, lngEventType, strMsg)
End Sub
'=============
' Method: HResultToString
' Description: Returns hresult value in string format 0x00000000(0)
' Parameters: hresult
'=============
Function HResultToString(hresult)
HResultToString = "0x" & Hex(hresult) & "(" & hresult & ")"
End Function
'=============
' Method: RegRead
' Description: Returns registry location value
' Parameters: strKey
'=============
Function RegRead(strKey)
On Error Resume Next
RegRead = "..."
Dim objShell
Set objShell = CreateObject("WScript.Shell")
RegRead = objShell.RegRead(strKey)
Set objShell = Nothing
End Function
ConvertDateTime = FormatDateTime(objDate) & " " & FormatDateTime(objTime)
End Function
'=============
' Method: IsWMIRunning
' Description: Returns true/false
' Parameters: -
'=============
Function IsWMIRunning()
Dim objWMI
On Error Resume Next
Set objWMI = GetObject("winmgmts:root\cimv2")
If Err Then
IsWMIRunning = False
CreateEvent _
9013, _
EVENT_TYPE_ERROR, _
"The 'Windows Management Instrumentation' service (WinMgmt.exe) was not running when MOM tried to run a script that is dependent on this service. Check if the start up mode of this service is not set to 'disabled'."
Else
IsWMIRunning = True
End If
End Function
'=============
' Method: WMIExecQuery
' Description: Returns an object of type SWbemObjectSet
' Parameters:
' sNamespace - A WMI Namespace (ex. winmgmts:\\COMPUTERNAME\ROOT\cimv2).
' sQuery - A SQL Query (ex. SELECT * FROM Win32_OperatingSystem)
' iAlert - To echo/raise error
'=============
Function WMIExecQuery(sNamespace, sQuery, iAlert)
Dim oWMI, oQuery
Dim nErrNumber, sErrDescription
Dim nInstanceCount
On Error Resume Next
Set oWMI = GetObject(sNamespace)
On Error Goto 0
If IsEmpty(oWMI) And iAlert <> 0 Then
WScript.Echo "Unable to open WMI Namespace " & sNamespace
Err.Raise 9100, "Unable to open WMI Namespace " & sNamespace, "Check to see if the WMI service is enabled and running, and ensure this WMI namespace."
End If
On Error Resume Next
Set oQuery = oWMI.ExecQuery(sQuery)
nErrNumber = Err.Number
sErrDescription = Err.Description
On Error Goto 0
If (IsEmpty(oQuery) Or nErrNumber <> 0) And iAlert <> 0 Then
WScript.Echo "The Query '" & sQuery & "' returned an invalid result set. Error:" & nErrNumber & ", " & sErrDescription & "."
Err.Raise 9100, "The Query '" & sQuery & "' returned an invalid result set.", "Please check to see if this is a valid WMI Query. Error:" & nErrNumber & ", " & sErrDescription & "."
End If
'Determine if we queried a valid WMI class - Count will return 0 or empty
On Error Resume Next
nInstanceCount = oQuery.Count
nErrNumber = Err.Number
sErrDescription = Err.Description
On Error Goto 0
If nErrNumber <> 0 And iAlert <> 0 Then
WScript.Echo "The Query '" & sQuery & "' did not return any valid instances. Error:" & nErrNumber & ", " & sErrDescription & "."
Err.Raise 9100, "The Query '" & sQuery & "' did not return any valid instances.", "Please check to see if this is a valid WMI Query. Error:" & nErrNumber & ", " & sErrDescription & "."
End If
Set WMIExecQuery = oQuery
Set oQuery = Nothing
Set oWMI = Nothing
End Function
'=============
' Method: IsRunningAsSystem
' Description: Returns true/false
' Parameters: -
' Comments: If IsRunningAsSystem is False the caller should check if there is any error (If Err Then ...).
'=============
Function IsRunningAsSystem
Dim WshNetwork
Dim WMISystemAcct
IsRunningAsSystem = False
Set WshNetwork = CreateObject("WScript.Network")
' Use the well-known SID of the system account ("S-1-5-18") to get the correspondent object
Set WMISystemAcct = GetObject("WinMgmts:root/cimv2:Win32_SID='S-1-5-18'")
' WshNetwork.UserName gives the account running the current thread
' WMISystemAcct.AccountName gets the localized name of the system account
' No worries with string case in the comparsion below since, if the account is
' system, the name is extracted from the same location for both objects
If WshNetwork.UserName = WMISystemAcct.AccountName Then
IsRunningAsSystem = True
End If
End Function
'=============
'=============
'Exchange specific Helper methods
'=============
'=============
'=============
' Method: GetNamingContext
' Description: Returns propertyValue from rootDSE object
' Parameters: strPropertyName
'=============
Function GetNamingContext(strPropertyName)
GetNamingContext = ""
Dim IADsRootDSE
Set IADsRootDSE = GetObject("LDAP://rootDSE")
GetNamingContext = IADsRootDSE.Get(strPropertyName)
Set IADsRootDSE = Nothing
End Function
'=============
' Method: GetRootGC
' Description: Returns RootGC
' Parameters: -
'=============
Function GetRootGC()
Dim oGCCollection, oGC
Set oGCCollection = GetObject("GC:")
For each oGC in oGCCollection
Set GetRootGC = oGC
Next
End Function
'=============
' Method: GetCNValue
' Description: -
' Parameters: iOcurr, strData
'=============
Function GetCNValue(iOcurr, strData)
GetCNValue = GetTokValue(iOcurr, "CN=", ",", strData)
End Function
'=============
' Method: GetTokValue
' Description: -
' Parameters: iOcurr, strStartTok, strEndTok, strData
'=============
Function GetTokValue(iOcurr, strStartTok, strEndTok, strData)
Dim iIni, iEnd, iTokLen
iTokLen = Len(strStartTok)
iIni = 1
While iOcurr > 0 ' Skip to the desired occurence
iIni = InStr(iIni, strData, strStartTok, vbTextCompare) + iTokLen
iOcurr = iOcurr - 1
WEnd
iEnd = InStr(iIni, strData, strEndTok, vbTextCompare)
GetTokValue = Mid(strData, iIni, (iEnd - iIni))
End Function
'=============
' Format Constants
'=============
Dim REC_DELIM, INFO_DELIM, IDENT
REC_DELIM = vbCr
INFO_DELIM = vbCr & vbCr
IDENT = " "
'=============
' Method: OutputInfo
' Description: -
' Parameters: strValues, strProps, iPropsFrom, iLevel, blnHierarchical
' Remarks: Very similar to OutDiskInfo sub in Disk_Space_Problem.vbs
'=============
Function OutputInfo(strValues, strProps, iPropsFrom, iLevel, blnHierarchical)
Dim arrValues, arrProps, strLvl
Dim i
If strValues = "" Then Exit Function
On Error Resume Next
OutputInfo = ""
arrValues = Split(strValues, ";")
arrProps = Split(strProps, ",")
While iLevel > 0
strLvl = strLvl & IDENT
iLevel = iLevel - 1
WEnd
For i = iPropsFrom To UBound(arrProps)
OutputInfo = OutputInfo & strLvl & arrProps(i) & ": " & arrValues(i) & REC_DELIM
If i = iPropsFrom and blnHierarchical Then strLvl = strLvl & IDENT
Next
On Error GoTo 0
End Function
'Copyright (c) Microsoft Corporation. All rights reserved.
'*******************************************************************************
' $ScriptName: "Verify IIS Lockdown was run" $
'
' Purpose - Verify that the IISLockdown Wizard was ran on the server.
'
' Exchange MOM 8143 Error creating Registry Object.
' Exchange MOM 8144 IIS Lockdown was never ran.
'
' $File: Verify_IISLockDown_Was_Run.vbs $
'*************************************************************************
'Event ID Constants
EVENT_SOURCE = "Verify IIS Lockdown was run"
Const EVENT_ID_BASE_STATE_OK = 10000
'Error creating Registry Object
Const ERROR_CREATING_REGISTRY_OBJECT_EVENT_ID = 8143
Const ERROR_CREATING_REGISTRY_OBJECT_MSG = "Error creating registry object. This script was not run."
'IIS Lockdown was never ran
Const IISLOCKDOWN_NOT_RAN_EVENT_ID = 8144
Const IISLOCKDOWN_NOT_RAN_MSG = "IIS Lockdown has not been run on this server. Please run the IIS Lockdown Wizard. For more information please see the Knowledge Base information associated with this alert."
Const HKEY_LOCAL_MACHINE = &H80000002
Dim TargetNetbiosComputer
if WScript.Arguments.Count = 1 then
TargetNetbiosComputer = WScript.Arguments(0)
else
WScript.quit()
end if
VerifyIISLockDownRegKey
' =====================================================================
' Method: VerifyIISLockDownRegKey
' =====================================================================
Sub VerifyIISLockDownRegKey
Dim sReg_Path, oReg, MajorVersion
If GetOSBuild() > 2195 Then Exit Sub ' This is not necessary on newer OS versions
On Error Resume Next
sReg_Path = "SOFTWARE\Microsoft\IIS Lockdown Wizard"
Set oReg = GetObject("Winmgmts:\\" & TargetNetbiosComputer & "\root\default:StdRegProv")
If (Err) Then
CreateEvent ERROR_CREATING_REGISTRY_OBJECT_EVENT_ID, EVENT_TYPE_INFORMATION, ERROR_CREATING_REGISTRY_OBJECT_MSG
Else
oReg.GetDWORDValue HKEY_LOCAL_MACHINE, sReg_Path, "MajorVersion", MajorVersion
If IsNull(MajorVersion) Then
CreateEvent IISLOCKDOWN_NOT_RAN_EVENT_ID, EVENT_TYPE_WARNING, IISLOCKDOWN_NOT_RAN_MSG
else
CreateEvent EVENT_ID_BASE_STATE_OK, EVENT_TYPE_SUCCESS, " Verification of IISLockdown Wizard Successful"
end if
End If
End Sub
' =====================================================================
' Method: GetOSBuild
' =====================================================================
Function GetOSBuild()
Dim oWMISet, oWMIOS
Set oWMISet = GetObject("WinMgmts:root\cimv2").InstancesOf("Win32_OperatingSystem")
For each oWMIOS in oWMISet
GetOSBuild = CLng(oWMIOS.BuildNumber)
Next
End Function