在splinter中强制使用SSLv3或TLSV1

时间:2014-05-08 14:21:29

标签: python ssl splinter

我正在尝试使用splinter

访问gateway.playneverwinter.com
from splinter import Browser

browser = Browser()
browser.visit('https://gateway.playneverwinter.com')

if browser.is_text_present('Neverwinter'):
    print("Yes, we made it to the entrance of the Prime Material Plane!")
else:
    print("Fumble")

browser.quit()

失败了

 File "gateway_bot.py", line 10, in <module>
    browser.visit('https://gateway.playneverwinter.com')
  File "/usr/local/lib/python3.4/dist-packages/splinter/driver/webdriver/__init__.py", line 53, in visit
    self.connect(url)
  File "/usr/local/lib/python3.4/dist-packages/splinter/request_handler/request_handler.py", line 23, in connect
    self._create_connection()
  File "/usr/local/lib/python3.4/dist-packages/splinter/request_handler/request_handler.py", line 53, in _create_connection
    self.conn.endheaders()
  File "/usr/lib/python3.4/http/client.py", line 1061, in endheaders
    self._send_output(message_body)
  File "/usr/lib/python3.4/http/client.py", line 906, in _send_output
    self.send(msg)
  File "/usr/lib/python3.4/http/client.py", line 841, in send
    self.connect()
  File "/usr/lib/python3.4/http/client.py", line 1205, in connect
    server_hostname=server_hostname)
  File "/usr/lib/python3.4/ssl.py", line 364, in wrap_socket
    _context=self)
  File "/usr/lib/python3.4/ssl.py", line 578, in __init__
    self.do_handshake()
  File "/usr/lib/python3.4/ssl.py", line 805, in do_handshake
    self._sslobj.do_handshake()
  ssl.SSLEOFError: EOF occurred in violation of protocol (_ssl.c:598)

Firefox可以毫无问题地连接和浏览这个网站。经过一些诊断

$ openssl s_client -connect gateway.playneverwinter.com:443               
CONNECTED(00000003)
139745006343840:error:140790E5:SSL routines:SSL23_WRITE:ssl handshake failure:s23_lib.c:177:

我发现它看起来像a fixed issue in OpenSSL并且强制SSLv3或TLSv1允许我连接(然后我可以用cURL下载目标),例如

openssl s_client -ssl3 -connect gateway.playneverwinter.com:443
openssl s_client -tls1 -connect gateway.playneverwinter.com:443

根据OpenSSL票证中的评论,我希望问题出在服务器端,但由于我无法访问它,因此无用。那么,为了快速解决问题,有没有办法强制分裂使用SSLv3或TLSv1?

2 个答案:

答案 0 :(得分:0)

在查看之后,我能想到的唯一方法就是进入client.py文件并更改其ssl内容的初始化。

答案 1 :(得分:0)

根据@Natecat的建议,我发现了一个猴子补丁,以便在发生此错误时强制使用SSLv3

# Monkey patch splinter to force SSLv3 on `ssl.SSLEOFError`
from splinter import request_handler
import ssl
from http import client as http_client
_old_req = request_handler.request_handler.RequestHandler._create_connection
def _splinter_sslv3_patch(self):
    try:
        _old_req(self)
    except ssl.SSLEOFError:
        self.conn = http_client.HTTPSConnection(self.host, self.port,
                                                context=ssl.SSLContext(ssl.PROTOCOL_SSLv3))
        self.conn.putrequest('GET', self.path)
        self.conn.putheader('User-agent', 'python/splinter')
        if self.auth:
            self.conn.putheader("Authorization", "Basic %s" % self.auth)
        self.conn.endheaders()
request_handler.request_handler.RequestHandler._create_connection = _splinter_sslv3_patch