You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

VB.NET中如何在触发System.UnauthorizedAccessException前传入凭证访问受保护文件

解决方案:用域凭证访问受保护的网络文件

要批量访问域内机器的受保护文件,无需手动修改权限,可通过模拟授权域用户身份来执行文件读取操作,以下是具体实现方案:

1. 实现Windows身份模拟辅助类

通过Windows API实现用户身份模拟,创建专用类处理身份验证逻辑:

Imports System.Runtime.InteropServices
Imports System.Security.Principal

Public Class ImpersonationHelper
    ' Windows API 函数声明
    <DllImport("advapi32.dll", SetLastError:=True, CharSet:=CharSet.Unicode)>
    Private Shared Function LogonUser(lpszUsername As String, lpszDomain As String, lpszPassword As String,
                                      dwLogonType As Integer, dwLogonProvider As Integer, ByRef phToken As IntPtr) As Boolean
    End Function

    <DllImport("advapi32.dll", CharSet:=CharSet.Auto, SetLastError:=True)>
    Private Shared Function DuplicateToken(hToken As IntPtr, impersonationLevel As Integer, ByRef hNewToken As IntPtr) As Boolean
    End Function

    <DllImport("kernel32.dll", CharSet:=CharSet.Auto, SetLastError:=True)>
    Private Shared Function CloseHandle(hObject As IntPtr) As Boolean
    End Function

    Private Const LOGON32_LOGON_INTERACTIVE As Integer = 2
    Private Const LOGON32_PROVIDER_DEFAULT As Integer = 0

    Private _impersonationContext As WindowsImpersonationContext

    ' 启动用户身份模拟
    Public Function ImpersonateUser(domain As String, username As String, password As String) As Boolean
        Dim tokenHandle As IntPtr = IntPtr.Zero
        Dim dupeTokenHandle As IntPtr = IntPtr.Zero

        Try
            ' 获取用户登录令牌
            If Not LogonUser(username, domain, password, LOGON32_LOGON_INTERACTIVE, LOGON32_PROVIDER_DEFAULT, tokenHandle) Then
                Return False
            End If

            ' 复制令牌用于模拟
            If Not DuplicateToken(tokenHandle, 2, dupeTokenHandle) Then
                CloseHandle(tokenHandle)
                Return False
            End If

            ' 创建身份上下文并开始模拟
            Dim newId As New WindowsIdentity(dupeTokenHandle)
            _impersonationContext = newId.Impersonate()
            Return True
        Catch
            ' 清理资源
            If tokenHandle <> IntPtr.Zero Then CloseHandle(tokenHandle)
            If dupeTokenHandle <> IntPtr.Zero Then CloseHandle(dupeTokenHandle)
            Return False
        End Try
    End Function

    ' 结束身份模拟
    Public Sub UndoImpersonation()
        _impersonationContext?.Undo()
        _impersonationContext?.Dispose()
    End Sub
End Class

2. 修改原有代码逻辑

在文件读取操作前启动身份模拟,完成后必须取消模拟,避免身份泄漏:

主循环部分调整

' 替换为你的授权域用户信息
Dim domainName As String = "你的域名称"
Dim userName As String = "授权用户名"
Dim password As String = "用户密码"

Dim impersonator As New ImpersonationHelper()
Dim impersonationSuccess As Boolean = impersonator.ImpersonateUser(domainName, userName, password)

If impersonationSuccess Then
    Try
        Do
            If day_dif >= 0 Then
                sum_iteraciones = sum_iteraciones + iteraciones(patho)
                num = num + 1
                patho = "\" & Eqp & "\Log_SG2X\" & Strings.Right("000" & Year(today), 4) & "\" & Strings.Right("00" & Month(today), 2) & "\" & Strings.Right("00" & Microsoft.VisualBasic.DateAndTime.Day(today), 2) & "\Sequence\" & Mesa & "\" & Strings.Right("000" & Year(today), 4) & Strings.Right("00" & Month(today), 2) & Strings.Right("00" & Microsoft.VisualBasic.DateAndTime.Day(today), 2) & Strings.Right("00" & num, 2) & ".log"

                If Not File.Exists(patho) Then
                    num = 0
                    today = today.AddDays(1)
                    day_dif = day_dif - 1
                End If
            End If
        Loop Until today >= day_fin

        Label1.Text = sum_iteraciones
    Catch ex As Exception
        MessageBox.Show("文件访问出错:" & ex.Message)
    Finally
        ' 必须执行,取消身份模拟
        impersonator.UndoImpersonation()
    End Try
Else
    MessageBox.Show("身份模拟失败,无法访问受保护文件")
End If

读取函数保持不变

Private Function iteraciones(path As String) As Integer
    Dim texto As String = File.ReadAllText(path)
    Dim count As Integer = Split(texto, "Probe down.").Length - 1
    Return count
End Function

3. 关键注意事项

  • 确保使用的域用户对所有目标机器的文件夹拥有读取权限,这是操作前提。
  • 不要硬编码密码,建议通过加密配置文件或用户输入框安全获取。
  • 模拟操作必须在Finally块中取消,防止身份残留引发权限问题。
  • 若LogonUser调用失败,检查域、用户名、密码正确性,以及该用户是否允许交互式登录。

内容的提问来源于stack exchange,提问作者Ricardo Martinez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 17:05:41