Batch scripting "Scanreg.exe" on W2K platform

From: Iheagwara, Charles (ciheagwara@finsys.com)
Date: 10/03/01


Message-ID: <E5B3448D642AD311A5F0009027848F76875209@MAIL>
From: "Iheagwara, Charles" <ciheagwara@finsys.com>
To: "'FOCUS-IDS@SECURITYFOCUS.COM'" <FOCUS-IDS@SECURITYFOCUS.COM>
Subject: Batch scripting "Scanreg.exe" on W2K platform
Date: Wed, 3 Oct 2001 08:31:19 -0400 

Ladies and Gentlemen:

I want to come up with a batch script using "Scanreg.exe" that can search for any strings or rogue files that are left in the registry after an
attack. The two possibilities I have considered include

1. Coming up with a script that can detect strings that don't match the registry. For example, in the script below I am searching for a specific
string "windows"

scanreg /s windows /r \lm /kvde
Pause
scanreg /s windows /r \cu /kvde
pause
scanreg /s windows /r \cr /kvde
pause
scanreg /s windows /r \us /kvde
pause

But in a Web production environment where the registry is constantly changing, this becomes a problem. It seems then that only a script that can
identify any string or filename that is incompatible with the registry will work.

2. Coming up with a script that will compare two registries: one standard, the other rogue. The problem here is how do I generate any of these
scripts.

Please help.

Thanks.

Charles



Relevant Pages

  • Where are the strings in gc.get_objects?
    ... script to show the numbers of each different type of object. ... for key in keys: ... I get similar results on both Python 2.4 and Python 2.5. ... Can anyone explain were the strings are? ...
    (comp.lang.python)
  • Python, MS SQL, and batch inserts
    ... com object, does a little formatting, and then inserts that data into ... ADODB.command objects for working with SQL. ... machine running the script. ... The overhead for recreating the strings was monster. ...
    (comp.lang.python)
  • Re: buffer interface problem
    ... I have run into a problem running a Python script that is part of the ... The purpose of the script is to walk a directory tree, unzipping files, ... I get the message "expected an object with the buffer ... either Unicode strings or bytestrings, ...
    (comp.lang.python)
  • ruby/tk and script encoding
    ... I have big problems with supporting the iso8859-2 characters in my ... The TixCombobox can be configured to callback a proc when the ... have inserted to the combobox earlier from my script (i.e., ... So, it seems, that on one machine, the strings from my script are ...
    (comp.lang.tcl)
  • Session losing variables?
    ... I have a script start.php and a second script proceed.php ... <?PHP ... // Strings match, so open logfile, exit if this fails. ...
    (comp.lang.php)