如何使用curl、wget或Python requests跳过SSL握手?
问题描述
我需要连接某服务器,但遇到SSL连接问题:服务器完全不返回证书,执行openssl s_client命令输出如下:
$ openssl s_client -connect the-host-I-test.com:443 CONNECTED(00000003) write:errno=0 --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 0 bytes and written 345 bytes Verification: OK --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated Early data was not sent Verify return code: 0 (ok) ---
目前网络人员正在调试该问题,同时我想验证API调用是否能返回正确信息,需在443端口发起请求但完全跳过SSL握手。我知道curl的-k参数和wget的--no-check-certificate参数可忽略证书,但这些参数仅针对已收到证书的情况,当前无证书返回导致连接超时。请问是否可通过curl、wget、Python requests或其他工具实现完全跳过SSL握手的请求?
免责声明:我知晓此操作不安全,存在被监听、中间人攻击等风险,但连接已通过VPN,无敏感信息,仅作临时验证。
解决方案
核心思路:跳过SSL握手本质是在443端口发送纯HTTP请求
HTTPS的基础是SSL/TLS握手+HTTP传输,跳过握手后就是直接把普通HTTP流量发送到443端口,以下是各工具的实现方式:
curl
直接指定HTTP协议和443端口,部分服务器需手动指定Host头:
# 基础请求 curl http://the-host-I-test.com:443/path/to/api # 带Host头的请求 curl -H "Host: the-host-I-test.com" http://the-host-I-test.com:443/path/to/api
Python requests
指定HTTP协议与443端口即可,必要时自定义请求头:
import requests # 基础GET请求 response = requests.get("http://the-host-I-test.com:443/path/to/api") print(response.status_code) print(response.text) # 自定义请求头的场景 headers = {"Host": "the-host-I-test.com", "Accept": "application/json"} response = requests.get("http://the-host-I-test.com:443/path/to/api", headers=headers)
wget
直接指定HTTP协议+443端口的目标地址:
wget http://the-host-I-test.com:443/path/to/api
Netcat(nc)
手动构造HTTP请求并发送,适合调试原始流量:
echo -e "GET /path/to/api HTTP/1.1\r\nHost: the-host-I-test.com\r\nConnection: close\r\n\r\n" | nc the-host-I-test.com 443
内容的提问来源于stack exchange,提问作者kramer65
相关产品推荐
相关产品推荐

