You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用PowerShell发现带Web界面的网络设备?

解决方案

针对你遇到的非200状态码无法获取页面内容的问题,分两种PowerShell版本给出具体解决方法:

PowerShell 7+ 版本(推荐)

PowerShell 7及以上版本新增了-SkipHttpErrorCheck参数,允许直接获取非200状态码的响应内容,无需捕获异常。结合模拟浏览器请求头,能解决大部分403/401场景:

# 模拟Edge浏览器的请求头(可根据实际浏览器调整)
$browserHeaders = @{
    "User-Agent"      = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
    "Accept"          = "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8"
    "Accept-Language" = "zh-CN,zh;q=0.9,en;q=0.8"
}

# 发起请求,跳过HTTP错误检查并禁用SSL证书验证
try {
    $webResponse = Invoke-WebRequest -Uri "https://目标设备IP" `
                                    -Headers $browserHeaders `
                                    -SkipHttpErrorCheck `
                                    -DisableSslCertificateValidation
    # 无论状态码是200、403还是401,都能访问响应内容
    Write-Host "响应内容:`n$($webResponse.Content)"
} catch {
    # 处理连接失败等非HTTP错误
    Write-Error "请求异常: $_"
}

PowerShell 5.x 版本

如果仍在使用PowerShell 5.x,没有-SkipHttpErrorCheck参数,可以从异常对象中提取响应流来获取页面内容:

# 同样模拟浏览器请求头
$browserHeaders = @{
    "User-Agent"      = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0"
    "Accept"          = "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8"
}

# 禁用SSL警告(你已实现的代码)
add-type @"
    using System.Net;
    using System.Security.Cryptography.X509Certificates;
    public class TrustAllCertsPolicy : ICertificatePolicy {
        public bool CheckValidationResult(
            ServicePoint srvPoint, X509Certificate certificate,
            WebRequest request, int certificateProblem) {
            return true;
        }
    }
"@
[System.Net.ServicePointManager]::CertificatePolicy = New-Object TrustAllCertsPolicy
[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12 -bor [Net.SecurityProtocolType]::Tls11 -bor [Net.SecurityProtocolType]::Tls

try {
    $webResponse = Invoke-WebRequest -Uri "https://目标设备IP" -Headers $browserHeaders
    Write-Host "响应内容:`n$($webResponse.Content)"
} catch {
    # 判断是否为HTTP错误响应,提取内容
    if ($_.Exception.Response) {
        $responseStream = $_.Exception.Response.GetResponseStream()
        $streamReader = New-Object System.IO.StreamReader($responseStream)
        $responseContent = $streamReader.ReadToEnd()
        Write-Host "非200状态码响应内容:`n$responseContent"
    } else {
        Write-Error "请求失败: $_"
    }
}

额外优化建议

  • Host头检查:部分设备Web服务器会验证请求的Host头,可在$browserHeaders中添加"Host" = "目标设备IP"或设备主机名。
  • 401响应利用:多数需要凭证的设备,其401登录页面会包含厂商logo、设备型号等标识信息,无需登录即可提取这些内容用于设备识别。
  • 重定向处理:如果设备存在重定向,可添加-MaximumRedirection 5参数允许自动跳转(根据实际情况调整次数)。

内容的提问来源于stack exchange,提问作者bfob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 10:25:26