远程枚举SMB共享权限遇权限拒绝等问题求助
问题解决方案
1. 规避权限拒绝获取远程SMB共享权限的方法
权限拒绝大多因为当前账户无目标机器本地管理员权限,或远程管理配置未到位,可尝试以下方案:
- 使用具备目标机器管理员权限的账户执行脚本,通过
Invoke-Command的-Credential参数传入凭据:$cred = Get-Credential $Access = Invoke-Command -ComputerName $ComputerName.Name -Credential $cred -ScriptBlock { Get-SmbShareAccess -Name $using:Share } - 若无法获取管理员权限,可尝试WMI查询(部分场景权限要求更低):
$shareSec = Get-WmiObject -Class Win32_LogicalShareSecuritySetting -ComputerName $ComputerName.Name -Filter "Name='$Share'" $permissions = $shareSec.GetSecurityDescriptor().Descriptor.DACL - 确保目标机器开启WinRM服务(
Invoke-Command依赖),可提前执行:Invoke-Command -ComputerName $ComputerName.Name -ScriptBlock { Enable-PSRemoting -Force } -Credential $cred - 检查目标机器防火墙是否允许SMB(445端口)、WinRM(5985/5986端口)的入站连接。
2. 修复同一计算机多共享仅显示最后一个的问题
原脚本的核心问题是在计算机循环中仅创建一个$newRow对象,后续每个共享都会覆盖该对象的属性,最终仅保留最后一条共享数据。调整方案:将对象创建逻辑移至共享循环内部,每个共享生成独立对象:
$ComputersNames = Get-ADComputer -Filter * | Select-Object Name $FileShares = [System.Collections.Generic.List[pscustomobject]]::new() foreach ($ComputerName in $ComputersNames) { try { $connected = Test-Connection -BufferSize 32 -Count 1 -ComputerName $ComputerName.Name -Quiet -ErrorAction Ignore if ($connected) { $Shares = net view \\$ComputerName.Name /all 2>&1 | Select-Object -Skip 7 | Where-Object { $_ -match 'disk' } | ForEach-Object { $_ -match '^(.+?)\s+Disk' | Out-Null $matches[1].Trim() } foreach ($Share in $Shares) { # 每个共享创建独立对象 $newRow = [pscustomobject]@{ Computer_Name = $ComputerName.Name Share_Name = $Share Access = $null } try { $Access = Invoke-Command -ComputerName $ComputerName.Name -ScriptBlock { Get-SmbShareAccess -Name $using:Share } $newRow.Access = $Access | Select-Object AccountName, AccessControlType, AccessRight } catch { $newRow.Access = "查询失败: $($_.Exception.Message)" } $FileShares.Add($newRow) | Out-Null } } } catch { Write-Host "计算机 $($ComputerName.Name) 处理失败: $($_.Exception.Message)" } }
注:原脚本中$ComputerName是Select-Object返回的对象,需用$ComputerName.Name获取实际计算机名;net view路径需写成\\$ComputerName.Name(双反斜杠)。
3. 导出规范的TXT或CSV格式
导出CSV(推荐,便于后续数据处理)
CSV保留结构化数据,直接使用Export-Csv:
$FileShares | Export-Csv -Path "SMB共享权限报告.csv" -NoTypeInformation -Encoding UTF8
导出TXT(可读性优先)
先格式化数据再导出:
$FileShares | Format-Table Computer_Name, Share_Name, Access -AutoSize | Out-File "SMB共享权限报告.txt" -Encoding UTF8
若需展开权限明细,可先转换数据结构再导出:
$FileShares | ForEach-Object { [pscustomobject]@{ Computer_Name = $_.Computer_Name Share_Name = $_.Share_Name Account = $_.Access.AccountName -join "; " Permission = $_.Access.AccessRight -join "; " } } | Export-Csv -Path "SMB共享权限明细.csv" -NoTypeInformation -Encoding UTF8
内容的提问来源于stack exchange,提问作者Biswa
相关产品推荐
相关产品推荐

