Ruby Mechanize在身份验证重定向期间崩溃; sslv3警告非法参数

时间:2010-11-15 13:46:31

标签: ruby ssl mechanize

我的脚本尝试通过表单登录网站。在身份验证期间多次重定向后,它会以sslv3 alert非法参数崩溃。我想知道是否有奇怪的事情发生了,所以我用DEBUG输出检查了HTML标题。这两个输出粘贴在下面。

其他一些奇怪的事情:click_buttonsubmit方法似乎做了不同的事情;即,click_button使重定向的执行持续一段时间,但它也会因上述错误而崩溃。 submit不会使程序崩溃,但登录似乎也不起作用。我尝试在较旧版本的Ruby上运行它,并且在使用connection_refused时错误变为click_button错误,并且在使用submit时行为相同。

Here are outputs I mentioned in the first paragraph in .txt, in case you find the text below difficult to read.

运行脚本时

DEBUG OUTPUT:

`I, [2010-11-15T17:52:20.462201 #22853]  INFO -- : follow redirect to: htps://xx2web1.apps.XXXXXXXXX.com/BANPROD1/xxauthent.ss_md5_login?timestamp_in=1289814682&uin_in=XXXXXXXXX&digest_in=be34b4b470a0da1831c7c432e353c320
/usr/lib/ruby/1.9.1/net/http.rb:677:in 'connect': SSL_connect returned=1 errno=0 state=SSLv2/v3 read server hello A: sslv3 alert illegal parameter (OpenSSL::SSL::SSLError)
        from /usr/lib/ruby/1.9.1/net/http.rb:677:in 'connect'
        from /usr/lib/ruby/1.9.1/net/http.rb:637:in 'do_start'
        from /usr/lib/ruby/1.9.1/net/http.rb:632:in 'start'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:527:in 'fetch_page'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:611:in 'fetch_page'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:611:in 'fetch_page'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:464:in 'post_form'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:370:in 'submit'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize/form.rb:141:in 'submit'
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize/form.rb:147:in 'click_button'
        from ./courseChecker.rb:33:in 'block in '
        from /usr/lib/ruby/gems/1.9.1/gems/mechanize-1.0.0/lib/mechanize.rb:262:in 'get'
        from ./courseChecker.rb:26:in ''`

HTML HEADERS TRACE成功登录Firefox:

`htps://xx2web1.apps.XXXXXXXXX.com/BANPROD1/xxauthent.ss_md5_login?timestamp_in=1289814134&uin_in=XXXXXXXXX&digest_in=d75483c390a2ab4ec0b939eaef7ecb1f`

`GET /BANPROD1/xxauthent.ss_md5_login?timestamp_in=1289814134&uin_in=XXXXXXXXX&digest_in=d75483c390a2ab4ec0b939eaef7ecb1f HTTP/1.1
Host: xx2web1.apps.XXXXXXXXX.com
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.12) Gecko/20101027 Firefox/3.6.12
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Connection: keep-alive
Referer: htps://eas.admin.XXXXXXXXX.com/eas/servlet/EasLogin?redirect=htps://webprod.admin.XXXXXXXXX.com/ssa/servlet/SelfServiceLogin?appName=com.XXXXXXXXX.aits.SelfServiceLogin&dad=BANPROD1
Cookie: RedirectString=https://webprod.admin.XXXXXXXXX.com/ssa/servlet/SelfServiceLogin?appName=com.XXXXXXXXX.aits.SelfServiceLogin&dad=BANPROD1; EnterpriseSessionId=8cc56f29-28de-4a01-96b8-6f58c30d6b6e-155.69.191.54; TESTID=test`

`HTTP/1.1 200 OK
Date: Mon, 15 Nov 2010 09:42:03 GMT
Server: Oracle-Application-Server-10g/10.1.2.3.0 Oracle-HTTP-Server
Content-Length: 228
Set-Cookie: SESSID=RTlCTzQ4MTc5NDAzOQ==
Connection: close
Content-Type: text/html; charset=UTF-8`

1 个答案:

答案 0 :(得分:0)

您是否尝试通过代理获取Mechanize,例如Charles,并查看与Firefox相比来回发送的内容?

可以将其配置为查看https交互。

玩得开心,克里斯