在Splinter中强制使用SSLv3或TLSV1

0 投票
2 回答
603 浏览
提问于 2025-04-18 05:50

我正在尝试使用 splinter 访问 gateway.playneverwinter.com

from splinter import Browser

browser = Browser()
browser.visit('https://gateway.playneverwinter.com')

if browser.is_text_present('Neverwinter'):
    print("Yes, we made it to the entrance of the Prime Material Plane!")
else:
    print("Fumble")

browser.quit()

但是连接失败,

 File "gateway_bot.py", line 10, in <module>
    browser.visit('https://gateway.playneverwinter.com')
  File "/usr/local/lib/python3.4/dist-packages/splinter/driver/webdriver/__init__.py", line 53, in visit
    self.connect(url)
  File "/usr/local/lib/python3.4/dist-packages/splinter/request_handler/request_handler.py", line 23, in connect
    self._create_connection()
  File "/usr/local/lib/python3.4/dist-packages/splinter/request_handler/request_handler.py", line 53, in _create_connection
    self.conn.endheaders()
  File "/usr/lib/python3.4/http/client.py", line 1061, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python3.4/http/client.py", line 906, in _send_output
    self.send(msg)
  File "/usr/lib/python3.4/http/client.py", line 841, in send
    self.connect()
  File "/usr/lib/python3.4/http/client.py", line 1205, in connect
    server_hostname=server_hostname)
  File "/usr/lib/python3.4/ssl.py", line 364, in wrap_socket
    _context=self)
  File "/usr/lib/python3.4/ssl.py", line 578, in __init__
    self.do_handshake()
  File "/usr/lib/python3.4/ssl.py", line 805, in do_handshake
    self._sslobj.do_handshake()
  ssl.SSLEOFError: EOF occurred in violation of protocol (_ssl.c:598)

不过,Firefox 浏览器可以顺利连接并浏览这个网站。经过一些诊断后,

$ openssl s_client -connect gateway.playneverwinter.com:443               
CONNECTED(00000003)
139745006343840:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:177:

我发现这看起来像是 OpenSSL 中的一个已修复问题,强制使用 SSLv3 或 TLSv1 可以让我成功连接(然后我可以用 cURL 下载目标内容),例如:

openssl s_client -ssl3 -connect gateway.playneverwinter.com:443
openssl s_client -tls1 -connect gateway.playneverwinter.com:443

根据 OpenSSL 票据中的评论,我认为问题出在服务器端,但因为我没有访问权限,所以这对我帮助不大。那么,作为一个快速解决方案,有没有办法强制 splinter 使用 SSLv3 或 TLSv1 呢?

2 个回答

0

经过研究,我想到的唯一办法就是去修改那个client.py文件,调整他们的SSL设置。

0

根据@Natecat的建议,我写了一个小程序来强制使用SSLv3,当出现这个错误时就会用上它。

# Monkey patch splinter to force SSLv3 on `ssl.SSLEOFError`
from splinter import request_handler
import ssl
from http import client as http_client
_old_req = request_handler.request_handler.RequestHandler._create_connection
def _splinter_sslv3_patch(self):
    try:
        _old_req(self)
    except ssl.SSLEOFError:
        self.conn = http_client.HTTPSConnection(self.host, self.port,
                                                context=ssl.SSLContext(ssl.PROTOCOL_SSLv3))
        self.conn.putrequest('GET', self.path)
        self.conn.putheader('User-agent', 'python/splinter')
        if self.auth:
            self.conn.putheader("Authorization", "Basic %s" % self.auth)
        self.conn.endheaders()
request_handler.request_handler.RequestHandler._create_connection = _splinter_sslv3_patch

撰写回答