แสดงบทความที่มีป้ายกำกับ Power Shell Scripts แสดงบทความทั้งหมด
แสดงบทความที่มีป้ายกำกับ Power Shell Scripts แสดงบทความทั้งหมด

วันพุธที่ 19 มิถุนายน พ.ศ. 2562

Powershell: Close Auto Update Local Group Policy


Powershell: Close Auto Update Local Group Policy


##Install Module for Support Policy##
Install-Module -Name PolicyFileEditor



$RegPath = 'Software\Policies\Microsoft\Windows\WindowsUpdate\AU'

$RegName = 'NoAutoUpdate'
$RegData = '1'
$RegType = 'DWord'


Set-PolicyFileEntry -Path \\IP_Target\C$\Windows\System32\GroupPolicy\Machine\Registry.pol -Key $RegPath -ValueName $RegName -Data $RegData -Type $RegType

##Show Policy on Target##
Get-PolicyFileEntry -Path \\IP_Target\c$\Windows\System32\GroupPolicy\Machine\Registry.pol -all

วันพฤหัสบดีที่ 13 มิถุนายน พ.ศ. 2562

Automate Configuration Switch Cisco from Powershell Scripts


Automate Get-Configuration Cisco from Powershell Scripts


###---------------------------------------###
### Author : Yingkamol Prukrattanakul-----###
###---MCP, MCSA, MCSE, MCT, MCST, SEC+----###
###---Email<yingkamol_7@hotmail.com>------###
## Blogger: https://yingkamol.blogspot.com ##
###---------------------------------------###
###//////////////..........\\\\\\\\\\\\\\\###
###/////////////////.....\\\\\\\\\\\\\\\\\###

##powershell for management SW##

param(
    [int] $port = 23,
        [string] $command1 = "terminal length 0",
        [string] $command2 = "en",
        [string] $command4 = "show run",
    [int] $commandDelay = 1000
   )
[string] $output = ""

function GetOutput
{
  ## Create a buffer to receive the response
  $buffer = new-object System.Byte[] 1024
  $encoding = new-object System.Text.AsciiEncoding

  $outputBuffer = ""
  $foundMore = $false

  ## Read all the data available from the stream, writing it to the
  ## output buffer when done.
  do
  {
    ## Allow data to buffer for a bit
    start-sleep -m 1000

    ## Read what data is available
    $foundmore = $false
    $stream.ReadTimeout = 1000

    do
    {
      try
      {
        $read = $stream.Read($buffer, 0, 1024)

        if($read -gt 0)
        {
          $foundmore = $true
          $outputBuffer += ($encoding.GetString($buffer, 0, $read))
        }
      } catch { $foundMore = $false; $read = 0 }
    } while($read -gt 0)
  } while($foundmore)

  $outputBuffer
}


##HQ##
$remoteHost = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip.txt
$username = Get-Content D:\Ying\PowerShell\mgmt_sw\user.txt
$password = Get-Content D:\Ying\PowerShell\mgmt_sw\password.txt
$password1 = Get-Content D:\Ying\PowerShell\mgmt_sw\password-en.txt

##Pak1##
$remoteHost1 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip1.txt

##Pak2##
$remoteHost2 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip2.txt

##Pak3##
$remoteHost3 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip3.txt

##Pak4##
$remoteHost4 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip4.txt

##Pak5##
$remoteHost5 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip5.txt

##Pak6##
$remoteHost6 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip6.txt

##Pak7##
$remoteHost7 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip7.txt

##Pak8##
$remoteHost8 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip8.txt

##Pak9##
$remoteHost9 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip9.txt

##Pak10##
$remoteHost10 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip10.txt

##Pak11##
$remoteHost11 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip11.txt

##Pak12##
$remoteHost12 = Get-Content D:\Ying\PowerShell\mgmt_sw\sw-ip12.txt


function HQ
{
            ForEach ($remoteHosts in $remoteHost)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\HQ-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\HQFailedlogin.txt"
                    }
            }
}

function PAK1
{
            ForEach ($remoteHosts in $remoteHost1)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK1-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK1Failedlogin.txt"
                    }
            }
}

function PAK2
{
            ForEach ($remoteHosts in $remoteHost2)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK2-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK2Failedlogin.txt"
                    }
            }
}

function PAK3
{
            ForEach ($remoteHosts in $remoteHost3)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK3-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK3Failedlogin.txt"
                    }
            }
}

function PAK4
{
            ForEach ($remoteHosts in $remoteHost4)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK4-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK4Failedlogin.txt"
                    }
            }
}

function PAK5
{
            ForEach ($remoteHosts in $remoteHost5)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK1-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK5Failedlogin.txt"
                    }
            }
}

function PAK6
{
            ForEach ($remoteHosts in $remoteHost6)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK6-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK6Failedlogin.txt"
                    }
            }
}

function PAK7
{
            ForEach ($remoteHosts in $remoteHost7)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK7-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK7Failedlogin.txt"
                    }
            }
}

function PAK8
{
            ForEach ($remoteHosts in $remoteHost8)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK8-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK8Failedlogin.txt"
                    }
            }
}

function PAK9
{
            ForEach ($remoteHosts in $remoteHost9)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK9-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK9Failedlogin.txt"
                    }
            }
}

function PAK10
{
            ForEach ($remoteHosts in $remoteHost10)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK10-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK10Failedlogin.txt"
                    }
            }
}

function PAK11
{
            ForEach ($remoteHosts in $remoteHost11)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK11-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK11Failedlogin.txt"
                    }
            }
}

function PAK12
{
            ForEach ($remoteHosts in $remoteHost12)
            {
                try
                {
                write-host "Connecting to $remoteHosts on port $port"     
                trap { Write-Error "Could not connect to remote computer: $_"; exit }
                $socket = new-object System.Net.Sockets.TcpClient($remoteHosts, $port)
                write-host "Connected. Press ^D followed by [ENTER] to exit.`n"
                $stream = $socket.GetStream()
                $writer = new-object System.IO.StreamWriter $stream
                    ## Receive the output that has buffered so far
                            $writer.WriteLine($username)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command2)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($password1)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                            $writer.WriteLine($command4)
                        $writer.Flush()
                        Start-Sleep -m $commandDelay
                        $SCRIPT:output += GetOutput
                ## Close the streams
                $writer.Close()
                $stream.Close()
                $output |Out-File "D:\Ying\PowerShell\mgmt_sw\PAK12-$remoteHosts.txt"
                }
                catch
                    {
                    $Failedlogin = "System FailedUser:$remoteHosts"
    echo $Failedlogin > "D:\Ying\PowerShell\mgmt_sw\PAK12Failedlogin.txt"
                    }
            }
}

วันพุธที่ 5 มิถุนายน พ.ศ. 2562

Powershell Scripts: Get DNS Record


Powershell Scripts: Get DNS Record


Import-Module dnsshell

##FQDN##
$ServerName = "adhq01.contoso.co.th"

##Domain Name##
$ZoneName = "contoso.co.th"

##Date Time##
$ondate = get-date -Format "ddMMyy"

##Get Dns Record##
##Server Name: adhq01.contoso.co.th##
##Zone Name: contoso.co.th## 
##Record Type: A Record##
##Select: String 10.xxx.xxx.xxx##

$results = Get-DnsRecord -Server $ServerName -ZoneName $ZoneName  -RecordType A | out-string -stream | Select-String "10."


##Out Put to File##
$results >"D:\DNSRecord\DNSRecords$ondate.csv"

Powershell Scripts: Scan Patch


Powershell Scripts: Scan Patch


function Hotfixreport {
$computers = Get-Content D:\Ying\Powershell\MS17010\scanlist.csv 
$MS17010= 'KB4012598', #Windows XP, Vista, Server 2003, 2008
               'KB4018466', #Server 2008
               'KB4012212', 'KB4012215', 'KB4015549', 'KB4019264', #Windows 7, Server 2008 R2
               'KB4012214', 'KB4012217', 'KB4015551', 'KB4019216', #Server 2012
               'KB4012213', 'KB4012216', 'KB4015550', 'KB4019215', #Windows 8.1, Server 2012 R2
               'KB4012606', 'KB4015221', 'KB4016637', 'KB4019474', #Windows 10
               'KB4013198', 'KB4015219', 'KB4016636', 'KB4019473', 'KB4016871', #Windows 10 1511
               'KB4013429', 'KB4015217', 'KB4015438', 'KB4016635', 'KB4019472' #Windows 10 1607, Server 2016$ErrorActionPreference = 'Stop' 
ForEach ($computer in $computers) {

  try
    {
Get-HotFix -cn $computer  | out-string -stream | select-string -pattern $MS17010

    }

catch

    {
            $NOPATCH = "System NOPATCH:$computer"
            $NOPATCH | Write-Warning
            $NOPATCH >> "$env:USERPROFILE\Desktop\NOPATCH.txt"

    }
}

}
Hotfixreport > "$env:USERPROFILE\Desktop\Hotfixreport.txt"

Powershell Scripts: Scan Port


Powershell Scripts: Scan Port


function CheckPort
   {
            # Define every server IP you need to test:
            $servers = Get-Content D:\ying\Powershell\MS17010\scanlist.csv 
            # Define the port number you need to test (eg: 3389 for RDP):
            $portToCheck = '49154'
            $ErrorActionPreference = 'Stop' 
                foreach ($server in $servers)
                    {
                        If ( Test-Connection $server -Count 1 -Quiet)
                        {   
                        try
                            {     
                            $null = New-Object System.Net.Sockets.TCPClient -ArgumentList $server,$portToCheck
                            $props = @{
                            Server = $server
                            PortOpen = 'Yes'
                                      }
                            }                             
                        catch
                            {
                            $props = @{
                            Server = $server
                            PortOpen = 'No'
                                      }
                            }
                        }
    Else
        {       
            $props = @{
            Server = $server
            PortOpen = 'Server did not respond to ping'         
                      }
        }
    New-Object PsObject -Property $props
        }
   }
CheckPort > "$env:USERPROFILE\Desktop\CheckPort.csv"

วันอังคารที่ 21 พฤษภาคม พ.ศ. 2562

Copy Trend Micro Office Scan Pattern

    สวัสดีครับ เนื่องจาก ทางลูกค้ามีจำนวน Server Trend Micro Office Scan จำนวนมาก และต้องการกำหนด ให้เครื่อง Server ต่างๆ Update Pattern ช่วงหลังเวลางาน ซึ่งผ่านจาก Web Console นั้นไม่สามารถ ระบุได้ เลยได้ทำการ เขียน Powershell Scripts เพื่อทำการ Copy Pattern ไปยัง Server Trend Micro Office Scan ต่างๆ และได้ทำการเขียนเพื่อ ให้ Check old version และทำการลบ เพื่อไม่ให้เปลือง Disk ที่ Server เองด้วย




$abc=@("ondate","path","lptpath","icrcpath","lptname","locallpt","icrcname","localicrc","Rpath","Rlptpath","Ricrcpath","Rlptname","Ricrcname","abc")
$ondate = get-date -F ddMMyy

remove-item -path d:\powershell\*.txt

<# get pattern number on Local #>
$path='c:\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\'
$lptpath=$path+'lpt$vpn.*'
$icrcpath=$path+'icrc$oth.*'
<# Full name (lpt$vpn.111) #>
$lptname = Get-ChildItem $lptpath -name | select -last 1
<# lpt number #>
$locallpt = $lptname -replace 'lpt\$vpn',''
<# Full name (icrc$oth.111) #>
$icrcname = Get-ChildItem $icrcpath -name | select -last 1
<# icrc number #>
$localicrc = $icrcname -replace 'icrc\$oth',''

<# get pattern number on Remote host #>
("ip,lpt") > d:\Powershell\lpt.txt
("ip,icrc") > d:\Powershell\icrc.txt
Get-Content d:\Powershell\trendlist.csv |Foreach-Object {
($Rpath="\\$_\c$\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\"),
($Rlptpath=$Rpath+'lpt$vpn.*'),
($Ricrcpath=$Rpath+'icrc$oth.*'),
($Rlptname = Get-ChildItem $Rlptpath -name | select -last 1 ),
($Ricrcname = Get-ChildItem $Ricrcpath -name | select -last 1),
("$_,$Rlptname" >> d:\powershell\lpt.txt),
("$_,$Ricrcname" >> d:\powershell\icrc.txt)
    }

<# Prepare output file for compare #>
(Get-Content -Path "d:\Powershell\lpt.txt" -ReadCount 0) -replace 'lpt\$vpn', '' | Set-Content -Path "d:\Powershell\lptnew.txt"
(Get-Content -Path "d:\Powershell\icrc.txt" -ReadCount 0) -replace 'icrc\$oth', '' | Set-Content -Path "d:\Powershell\icrcnew.txt"

Clear-Content -Path "d:\Powershell\lpt.txt"
Clear-Content -Path "d:\Powershell\icrc.txt"
Import-Csv d:\powershell\lptnew.txt | Where-Object {$_.lpt -lt "$locallpt" -and $_.lpt -gt "$null"} | ForEach-Object {($_).ip >> d:\Powershell\lpt.txt}

Get-Content -Path "d:\Powershell\lpt.txt" | ForEach-Object {
    ($Rpath="\\$_\c$\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\"),
    (Copy-Item -Path $path$lptname -Destination $Rpath),
    ((echo "$_,LPT") >> d:\log\$ondate.csv)
    }

Import-Csv d:\powershell\icrcnew.txt | Where-Object {$_.icrc -lt "$localicrc" -and $_.icrc -gt "$null"} |  ForEach-Object {($_).ip >> d:\Powershell\icrc.txt}

Get-Content -Path "d:\Powershell\icrc.txt" | ForEach-Object {
    ($Rpath="\\$_\c$\Program Files (x86)\Trend Micro\OfficeScan\PCCSRV\"),
    (Copy-Item -Path $path$icrcname -Destination $Rpath),
    ((echo "$_,ICRC") >> d:\log\$ondate.csv)
    }


remove-item -path d:\powershell\*.txt
$abc  | foreach-object {remove-variable $_}



Open: Remote Powershell


Open Remote Powershell


     เครื่องทั่วไป จะ run powershell remote ไปยัง เครื่องต่างๆ ได้ครับ เนื่องจากติด policy ให้ run Powershell ได้แค่ local Computer เท่านั้น ซึ่งจะต้องทำการเปิดก่อน ที่จะใช้งานครับ

     โดยวิธีการเปิด ให้ไปที่ powershell แบบ  run as admin แล้ว พิมพ์ set-executionpolicy remotesigned


     ส่วนอันนี้ เสริม ไว้ให้ดูง่าย (ใช้ powershell ISE) ก็ต้องเปิดขึ้นมาเปิด


     ต้องเปิด powershell --> run as admin --> แล้ว พิมพ์  Import-Module ServerManager -->
Add-WindowsFeature PowerShell-ISE

Powershell Scripts: Automate Brute Force,Unload Delete and Install Trend Micro Office Scan

Powershell Scripts: Automate Brute Force,Unload Delete and Install Trend Micro Office Scan

    สวัสดีครับ วันนี้จะมาพูดถึง Automate Scripts การ Brute Force,Unload Delete and Install Trend Micro Office Scan ครับ เนื่องจาก ทางลูกค้ามีเครื่อง Computer จำนวนมาก และมี หลากหลาย Username / Password ซึ่งบางทีก็ไม่สามารถติดต่อไปยังเจ้าของเครื่องได้ครับ ทำให้ทางผมได้ทำการเขียน Scripts ขึ้นมาเพื่อใช้งาน ในการช่วยอำนวย ความสะดวกให้กับลูกค้า (อันนี้เป็น Code ตัวอย่างคร่าวๆนะครับ ยังไงก็ลองเอาไปปรับใช้กันดูครับ)


โดยก่อนที่จะทำการ ใช้งาน Powershell Scripts นี้นะครับ มี Requirement ดังต่อไปนี้
1. ต้องเปิด Policy ให้ Powershell สามารถ Remote Command ได้
https://yingkamol.blogspot.com/2019/05/open-remote-powershell.html

2. psexectools ซึ่งเป็น Tools free จาก Microsoft ครับ
https://docs.microsoft.com/en-us/sysinternals/downloads/psexec

###----------------------------------------------------------###    
### Author : Yingkamol Prukrattanakul---------------###      
###---MCP, MCSA, MCSE, MCT, MCST, SEC+----###    
###-----Email<yingkamol_7@hotmail.com>---------###    
###-----------------------------------------------------------###    
###//////////////////////////...................\\\\\\\\\\\\\\\\\\\\\\\\\\\\###    
###////////////////////////////////.....\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\###


####Get Data In File####

##Get IP Target##
$computers = Get-Content D:\Test_Password_Login\scanlist.txt

##Get Username##
$users = Get-Content D:\Test_Password_Login\user_list.txt

##Get Password##
$passwords = Get-Content D:\Test_Password_Login\password_list.txt

##Get Date##
$ondate = get-date -Format "ddMMyy"

##Check IP from File IP  xxx.xxx. ##
$pattern = "([1-9]|[1-9][0-9]|1[0-9][0-9]|2[0-4][0-9]|25[0-5])(\.([0-9]|[1-9][0-9]|1[0-9][0-9]|2[0-4][0-9]|25[0-5]))$"

$test = $computers -replace $pattern
##IP  xxx.xxx.2.50 ##
$av = "1.2"

$All = "$test$av"
     
##MSI Download and Install## 
        $msi32 = "msiexec /i 'http://$All':8080/officescan/download/agent_cloud_x86.msi PROPERTY=VALUE /qn"
        $msi64 = "msiexec /i 'http://$All':8080/officescan/download/agent_cloud_x64.msi PROPERTY=VALUE /qn"
     
        $trend64 = "http://192.168.1.2:8080/officescan/download/agent_cloud_x64.msi PROPERTY=VALUE /qn"
        $trend32 = "http://192.168.1.2:8080/officescan/download/agent_cloud_x86.msi PROPERTY=VALUE /qn"


##Loop IP -->Try Username -->Try Password --> ##
##Check OS Architecture -->Unload --> Uninstall --> Install Trend Micro OfficeScan##

ForEach ($computer in $computers)
{ 
   try
{
ForEach ($user in $users)
{
try
{
ForEach ($password in $passwords)
{
                                psexec "\\$computer" -u $user -p $password cmd /c "whoami"
                                IF ($LASTEXITCODE -eq '0')
{
echo "$computer $user $password" >> "D:\Test_Password_Login\COMPUTERPASSLIST.txt"

###Check OS Version###
psexec "\\$computer" -u $user -p $password /accepteula cmd /c "cd D:\Program Files (x86)"

IF ($LASTEXITCODE -eq '0')
{
###OS Version 64 Bit###
###Uninstall###
Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c 'D:\Program Files (x86)\Trend Micro\OfficeScan Client\pccntmon' -n" -Wait -Passthru
       
##Sleep 25 = Deley 25 Sec##        sleep 25
                                         
        Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c reg add HKLM\SOFTWARE\Wow6432node\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc. /v 'Allow Uninstall' /t REG_DWORD /d 1 /f" -Wait -Passthru -WindowStyle Hidden
         sleep 5

         Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c 'D:\Program Files (x86)\Trend Micro\OfficeScan Client\NTRmv.exe"  -Wait -Passthru -WindowStyle Hidden
          sleep 60

         Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c msiexec /i $trend64  " -Wait -Passthru -WindowStyle Hidden
         sleep 60
}
else
{
###OS Version 32 Bit###
###Uninstall###
Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c 'D:\Program Files\Trend Micro\OfficeScan Client\pccntmon' -n"   -Wait -Passthru                                     
        sleep 25

        Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer reg add HKEY_LOCAL_MACHINE\SOFTWARE\TrendMicro\PC-cillinNTCorp\CurrentVersion\Misc. /v 'Allow Uninstall' /t REG_DWORD /d 1 /f" -Wait -Passthru
       sleep 5
                                         
       Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c D:\Program Files\Trend Micro\OfficeScan Client\NTRmv.exe" -Wait -Passthru
         sleep 60
                                         
        Start-Process -FilePath 'D:\PSexec.exe' -ArgumentList "-s -u $user -p $password \\$computer cmd /c msiexec /i $trend32" -Wait -Passthru
         sleep 60

}
}
else
       {
$FailedPassword = "System FailedPassword:$password"
$FailedPassword | Write-Warning
       }
        }
}
        catch   
{
$FailedUser = "System FailedUser:$user"
$FailedUser | Write-Warning
}
}
}
catch   
{
$NOTCONNECT = "System NOPATCH:$computer"
        $NOTCONNECT | Write-Warning
         }
}