powershell httpwebrequest GET方法cookiecontainer问题?

fou*_*t84 9 powershell httpwebrequest httpwebresponse cookiecontainer

我正在试图抓住一个拥有用户身份验证的网站.我能够发一个POST来发送我的登录信息并存储一个cookie.但是,登录后,我在尝试访问受保护的页面时收到403错误.

$url = "https://some_url"

$CookieContainer = New-Object System.Net.CookieContainer

$postData = "User=UserName&Password=Pass"

$buffer = [text.encoding]::ascii.getbytes($postData)

[net.httpWebRequest] $req = [net.webRequest]::create($url)
$req.method = "POST"
$req.Accept = "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"
$req.Headers.Add("Accept-Language: en-US")
$req.Headers.Add("Accept-Encoding: gzip,deflate")
$req.Headers.Add("Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7")
$req.AllowAutoRedirect = $false
$req.ContentType = "application/x-www-form-urlencoded"
$req.ContentLength = $buffer.length
$req.TimeOut = 50000
$req.KeepAlive = $true
$req.Headers.Add("Keep-Alive: 300");
$req.CookieContainer = $CookieContainer
$reqst = $req.getRequestStream()
$reqst.write($buffer, 0, $buffer.length)
$reqst.flush()
$reqst.close()
[net.httpWebResponse] $res = $req.getResponse()
$resst = $res.getResponseStream()
$sr = new-object IO.StreamReader($resst)
$result = $sr.ReadToEnd()
$res.close()



$url2 = "https://some_url/protected_page"

[net.httpWebRequest] $req2 = [net.webRequest]::create($url2)
$req2.Method = "GET"
$req2.Accept = "text/html"
$req2.AllowAutoRedirect = $false
$req2.CookieContainer = $CookieContainer
$req2.TimeOut = 50000
[net.httpWebResponse] $res2 = $req2.getResponse()
$resst = $res2.getResponseStream()
$sr = new-object IO.StreamReader($resst)
$result = $sr.ReadToEnd()
Run Code Online (Sandbox Code Playgroud)

解决方法:所以在尝试了几乎所有的东西后,我最终尝试了不同的东西,它确实有效.

在发布登录并获取会话cookie之后,我使用webclient通过将cookie字符串添加到标头来访问安全页面.

$web = new-object net.webclient
$web.Headers.add("Cookie", $res.Headers["Set-Cookie"])
$result = $web.DownloadString("https://secure_url")
Run Code Online (Sandbox Code Playgroud)

关于此的一个很酷的事情是webclient保存cookie.要访问另一个安全页面,您只需调用$ web.downloadstring("https:// another_secure_url"):)

Pau*_*aul 6

我发现由于cookie可以附加其他信息(如URL或仅限HTTP),$ res.Headers ["Set-Cookie"]对我不起作用.但是使用$ CookieContainer变量,您可以轻松地将其更改为使用GetCookieHeader(url),这将删除额外信息并为您提供格式正确的cookie字符串:

$web = new-object net.webclient
$web.Headers.add("Cookie", $CookieContainer.GetCookieHeader($url))
$result = $web.DownloadString($url)
Run Code Online (Sandbox Code Playgroud)