Successfully connected
TLS 1.3 OK; HelloRetryRequest used; server-initiated key update accomplished;
Detailed description:
v.0.24.4-p
(This TLS-1.3-only server supports: HelloRetryRequest, KeyUpdate, ECDHE, FFDHE, X25519MLKEM768, SecP256r1MLKEM768, X25519Kyber768, ESNI, etc.)
HelloRetryRequest used to (re)negotiate DH group
First ClientHello, key shares: 0x001D
Second ClientHello, key shares: 0x0017
CRYPTO_CONTEXT
Protocol version: 0x0304
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
Key exchange: 0x0017 (Secp256r1)
(Handshake level)
Handshake secrets:
Client: 0x728467A2C22CD41BF59CB626DCF45D1F78E82E0684D8C24FA73133CE4F578D9B
Server: 0x59EA878DAB19491662151337F98750D397EC0F12B2BBAE86CB946CA5B7B46D43
Handshake keys:
Client write: 0xB5DC622ED9570C28DEA5C69D0B454EA9
Server write: 0x5D0FAC7DE9C9C6C5B4061DCDCFDAEEFF
Handshake IVs:
Client write (IV): 0x5F2AC06968ED42F57962707B
Server write (IV): 0xCA34489B8DFB3FB1C2D78A3A
(Traffic level)
Traffic secrets:
Client: 0xAB823DFF71FB39ED7D5A5082F4A2CDB764EAFFCC6064375B8B4405D7FE9B2529
Server: 0x6A69497E79757E12B7ECFA1249AAAE245AD22DE13BD23C3F269D9276CF297CD8
KeyUpdates log, server:
0: 0x25C2D8A517D19626240ADD03D781D2FA2F974984FB068D73B95AA3D8C70C35B3
Traffic keys:
Client write: 0x7B30EEB1C1D79FF0D159259DCAE7D275
Server write: 0x29080765C6051D1EB18881F0D3FA1F7B
KeyUpdates log, server:
0: 0x3CD641298FE6F4585359F0DD4A5268EF
Traffic base IVs:
Client write (base IV): 0xE53BD815CD4DDD25D2093919
Server write (base IV): 0x82D8E7E4261084E25BE8C1AD
KeyUpdates log, server:
0: 0x08E745FAB751A6F5CCE774AD
--- Messages ---
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: B3:EE:EA:3C:30:3E:14:0D:EB:7D:AC:58:C4:D8:48:DC:C5:67:91:C7:55:EF:74:B1:D1:EF:38:F2:C3:75:C3:51
Client SessionID: D6:6C:5F:96:8E:C1:42:DF:C2:A2:04:44:81:C2:79:56:BF:3F:36:40:FE:C4:7A:23:70:DA:DE:3E:AD:A9:68:97
Extensions:
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0x426DC88D3FEE03EEC65C838A12BFFB95868F5B2C2141C46DACB545FBD3A1764D
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 35 (0x0023); /non-TLS-1.3/
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 23 (0x0017); /non-TLS-1.3/
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
HELLO_RETRY_REQUEST (sent, server)
Legacy Version: 0x0303
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
HelloRetryRequest (Server Random): CF:21:AD:74:E5:9A:61:11:BE:1D:8C:02:1E:65:B8:91:C2:A2:11:16:7A:BB:8C:5E:07:9E:09:E2:C8:A8:33:9C
SessionID: D6:6C:5F:96:8E:C1:42:DF:C2:A2:04:44:81:C2:79:56:BF:3F:36:40:FE:C4:7A:23:70:DA:DE:3E:AD:A9:68:97
Extensions:
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
[Legacy ChangeCipherSpec message present (client)]
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: B3:EE:EA:3C:30:3E:14:0D:EB:7D:AC:58:C4:D8:48:DC:C5:67:91:C7:55:EF:74:B1:D1:EF:38:F2:C3:75:C3:51
Client SessionID: D6:6C:5F:96:8E:C1:42:DF:C2:A2:04:44:81:C2:79:56:BF:3F:36:40:FE:C4:7A:23:70:DA:DE:3E:AD:A9:68:97
Extensions:
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
x = 0x96B48297DA8FB321BA24795BE85AE2F10DFC88468D4378EEFD80BC539DEDA6BC
y = 0x0022C818A1CC38E6A0375B99A9AFD8D9008B69FA2DBB07D14558077E58DB1ADD
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 35 (0x0023); /non-TLS-1.3/
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 23 (0x0017); /non-TLS-1.3/
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
SERVER_HELLO (sent)
Legacy Version: 0x0303
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
Server Random: DE:AD:DE:AD:DE:AD:C0:DE:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
SessionID: D6:6C:5F:96:8E:C1:42:DF:C2:A2:04:44:81:C2:79:56:BF:3F:36:40:FE:C4:7A:23:70:DA:DE:3E:AD:A9:68:97
Extensions:
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
x = 0x1FADAC79156E08C8532CE88DF887273141ACE16E44E9C268CE496596F41B65FA
y = 0xF82394637B6ACF004AB253F956BD2CD6CA6C9AD8454BF1FBF281A6C54A93D99C
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
SERVER_HANDSHAKE_MESSAGES (sent)
Type: 8 (0x08) - "encrypted_extensions"
Length (octets, dec.): 2
00:00
Type: 11 (0x0B) - "certificate"
Length (octets, dec.): 2700
[...] /skipped 2700 data octets/
Type: 15 (0x0F) - "certificate_verify"
Length (octets, dec.): 107
05:03:00:67:30:65:02:31:00:D3:3B:44:9B:E5:3A:4E:AF:91:7A:A5:73:A1:BB:7A:86:A1:77:E1:2D:83:E7:EE
B2:3B:FA:34:90:C6:5E:3C:80:0A:66:D6:F7:88:69:4D:C1:9B:9E:23:36:3C:B7:A4:D2:02:30:6F:B6:AE:19:ED
AB:84:2C:6E:CB:67:1D:81:5F:2C:81:4A:90:36:A1:DA:81:64:3F:40:99:6C:75:DB:47:27:D7:F9:9A:91:F0:B4
72:A0:46:15:60:05:4A:EB:79:A7:96
Type: 20 (0x14) - "finished"
Length (octets, dec.): 32
F3:1E:14:3C:13:D3:D4:F6:D6:8C:8B:16:D4:7F:AD:C2:9A:A6:2F:6F:A5:E4:42:7A:37:27:AE:40:86:94:E8:3D
CLIENT_FINISHED (received)
Finished value: 0xC3ED23D006A1B2026DFDF62D9DD7EBEFCE2A7F50D8072C4572824535064DD205
Client Finished status: OK
CLIENT_APPLICATION_DATA (recieved)
ASCII dump (filtered):
GET / HTTP/1.1..accept: */*..user-agent: Mozilla/5.0 AppleWebKit
/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebo
t@anthropic.com)..accept-encoding: gzip, br, zstd, deflate..host
: tls13.1d.pw....
[Server KeyUpdate sent /message skipped/]
TCP: server: 194.87.103.72:443; client: 216.73.217.174:21616; timestamp: 1788611563
Contacts: dxdt.ru, alex/()\/abaabb.xyz.
/\_/\
( 0.0 )
= ^ =
/|_|\
(") (")=~
Provide ESNI to get second ASCII cat
Elapsed server side: 286ms; ServerHello sent: 145ms (including HelloRetryRequest time); TLS connection established: 285ms.