From 815d417a9e46be2c7947c9addb17538e45085dbe Mon Sep 17 00:00:00 2001 From: Miroslav Stampar Date: Fri, 4 Dec 2020 11:40:09 +0100 Subject: [PATCH] Fixes #4462 --- lib/core/settings.py | 2 +- lib/request/httpshandler.py | 6 ++++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/lib/core/settings.py b/lib/core/settings.py index b4fd02771..44145cea1 100644 --- a/lib/core/settings.py +++ b/lib/core/settings.py @@ -18,7 +18,7 @@ from lib.core.enums import OS from thirdparty.six import unichr as _unichr # sqlmap version (...) -VERSION = "1.4.12.7" +VERSION = "1.4.12.8" TYPE = "dev" if VERSION.count('.') > 2 and VERSION.split('.')[-1] != '0' else "stable" TYPE_COLORS = {"dev": 33, "stable": 90, "pip": 34} VERSION_STRING = "sqlmap/%s#%s" % ('.'.join(VERSION.split('.')[:-1]) if VERSION.count('.') > 2 and VERSION.split('.')[-1] == '0' else VERSION, TYPE) diff --git a/lib/request/httpshandler.py b/lib/request/httpshandler.py index 841b0069e..03e3c3c27 100644 --- a/lib/request/httpshandler.py +++ b/lib/request/httpshandler.py @@ -67,6 +67,12 @@ class HTTPSConnection(_http_client.HTTPSConnection): sock = create_sock() if protocol not in _contexts: _contexts[protocol] = ssl.SSLContext(protocol) + try: + # Reference(s): https://askubuntu.com/a/1263098 + # https://askubuntu.com/a/1250807 + _contexts[protocol].set_ciphers("DEFAULT@SECLEVEL=1") + except ssl.SSLError: + pass result = _contexts[protocol].wrap_socket(sock, do_handshake_on_connect=True, server_hostname=self.host) if result: success = True