You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Curl 7.21连接SSLV3时提示blocklist问题求助

Fixing SSLv3 Connection Blocklist Error with Curl on Ubuntu 14.04

Alright, let's tackle this problem step by step. You're trying to connect to a site that testssl confirms has the POODLE vulnerability (so it should support SSLv3), but curl is throwing a "blocklist" error. Let's break down the possible causes and fixes, tailored to your environment (OpenSSL 1.0.2k, Curl 7.21, Ubuntu 14.04).

First, Verify SSLv3 Support in Your Tools

Before troubleshooting the block, make sure your curl and OpenSSL actually have SSLv3 enabled:

  • Check curl's supported SSL protocols:
    curl -V | grep -i ssl
    
    Look for SSLv3 in the output (e.g., Protocols: ... SSLv3 ...). If it's missing, your curl was compiled without SSLv3 support, and you'll need to recompile it (more on that later).
  • Check OpenSSL's available SSLv3 cipher suites:
    openssl ciphers -v | grep SSLv3
    
    If no results show up, SSLv3 is disabled in your OpenSSL config.

Fix 1: Bypass Cipher Suite Restrictions

Most modern systems block SSLv3's CBC ciphers (the ones vulnerable to POODLE) by default. The target site might only allow non-CBC SSLv3 ciphers like RC4. Try specifying a compatible cipher:

sudo curl https://orlandofringe.showare.co -3 -k --ciphers 'RC4-SHA'

RC4 was a common workaround for POODLE back in the day, so the site's server might still allow it even if other SSLv3 ciphers are blocked.

Fix 2: Adjust OpenSSL Configuration

Ubuntu 14.04's default OpenSSL config might restrict SSLv3. Edit the config file:

sudo nano /etc/ssl/openssl.cnf

Find the [system_default_sect] section. Look for lines like:

MinProtocol = TLSv1.0
CipherString = DEFAULT@SECLEVEL=2

Modify them to allow SSLv3:

MinProtocol = SSLv3
CipherString = DEFAULT@SECLEVEL=1:!aNULL:!MD5

Save the file and retry your curl command. The SECLEVEL=1 lowers the security threshold enough to allow older SSLv3 ciphers.

Fix 3: Spoof a Browser User-Agent

Many WAFs (Web Application Firewalls) or CDNs block requests from curl's default user-agent, especially when using outdated protocols like SSLv3. Try mimicking a browser that supported SSLv3:

sudo curl https://orlandofringe.showare.co -3 -k -A "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0"

Firefox 40 is old enough that it supported SSLv3, so this might bypass the blocklist.

Fix 4: Recompile Curl with SSLv3 Support (If Needed)

If your curl was compiled without SSLv3 support (from the first verification step), you'll need to recompile it:

  1. Install dependencies:
    sudo apt-get install build-essential libssl-dev libcurl4-openssl-dev
    
  2. Download curl 7.21 source:
    wget https://curl.se/download/curl-7.21.0.tar.gz
    tar -xzf curl-7.21.0.tar.gz
    cd curl-7.21.0
    
  3. Configure with SSLv3 enabled:
    ./configure --with-ssl --enable-ssl3
    
  4. Compile and install:
    make && sudo make install
    
  5. Verify the new build:
    curl -V | grep -i sslv3
    

Why This Happens

The "blocklist" error is almost certainly from the target site's security layer (WAF/CDN), not your local system. Even though testssl says the site has POODLE (so it supports SSLv3), many providers automatically block all SSLv3 requests to avoid attacks—regardless of server support. The fixes above work by either using a cipher the site allows, spoofing a trusted user-agent, or ensuring your tools actually send valid SSLv3 traffic.

内容的提问来源于stack exchange,提问作者Jack Huang

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:20:24