Unable to update the SpyEye Tracker feed

  • 7017596
  • 10-May-2016
  • 10-May-2016

Environment

NetIQ Sentinel 7.x Sentinel Server

Situation

If I go to the Sentinel web interface\plugins\feeds and try to update the SpyEye Tracker it errors out with the following. 

java.lang.Throwable: Error executing the command /usr/bin/curl https://spyeyetracker.abuse.ch/blocklist.php?download=domainblocklist | sed -e s/#.*// -e s/[ ^I]*$// -e /^$/ d | sed s_\(.*\)_1,0,\1_ > ./map_data/SpyEye_Botnet_Domain_ListData:java.lang.Exception: Couldnt resolve host or URL provided. Please verify if it is correct. URL undefinedWrapped java.lang.RuntimeException: Error executing the command '/usr/bin/curl https://spyeyetracker.abuse.ch/blocklist.php?download=domainblocklist | sed -e 's/#.*//' -e 's/[ ^I]*$//' -e '/^$/ d' | sed 's_\(.*\)_1,0,\1_' > ./map_data/SpyEye_Botnet_Domain_ListData':java.lang.Exception: Couldn't resolve host or URL provided. Please verify if it is correct. URL undefined (/var/opt/novell/sentinel/data/server.cache/javascript_action_plugins/SpyEye_Tracker_FB2ABBA014B5103190CE005056A70248_2396794512280355362/main.script#180)

When I check https://spyeyetracker.abuse.ch, it says that it is discontinued.

Resolution

Uninstall the Feed, then update to the latest Threat Intelligence Solution pack to prevent that feed from ever accidently being re-installed.

To uninstall the feed go to the Sentinel web interface\plugins\catalog\feeds\  choose to uninstall the spy tracker feed. 

Note: there may be dependancies assiciated with the feed that have to be removed before Sentinel will allow you to uninstall SpyEye Tracker. 


1. To download the most current Threat Intelligence Solution pack go to https://www.netiq.com/support/sentinel/plugins/ solutions pack tab.

2. Once downloaded click the the install plugin button. 

3. Browse to the Threat Intelligence Solution pack download and install. 

Cause

SpyEye has been discontinued and the old/original feed had a defect that caused the map to be corrupted.