Successfully connected
TLS 1.3 OK; HelloRetryRequest used; server-initiated key update accomplished;
Detailed description:
v.0.24.4-p
(This TLS-1.3-only server supports: HelloRetryRequest, KeyUpdate, ECDHE, FFDHE, X25519MLKEM768, SecP256r1MLKEM768, X25519Kyber768, ESNI, etc.)
HelloRetryRequest used to (re)negotiate DH group
First ClientHello, key shares: 0x001D
Second ClientHello, key shares: 0x0018
CRYPTO_CONTEXT
Protocol version: 0x0304
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
Key exchange: 0x0018 (Secp384r1)
(Handshake level)
Handshake secrets:
Client: 0x9DC5107D5BA456420035BF77A2732667F8F0D694D611F1A9947D7C6F11EBADB6
Server: 0xF5A269D13295F582BFF33BAFF329E06FB05959FFAD635459C739FF63ADEFAA7D
Handshake keys:
Client write: 0xC0EF1C2F7C617D1A3C9682A52B8F6832
Server write: 0x761FBA18781913C33776F9007D279AF2
Handshake IVs:
Client write (IV): 0xCA827FBCDA1EDDC32CECF498
Server write (IV): 0xEEA6D187D2C56FC2BC840A94
(Traffic level)
Traffic secrets:
Client: 0x20FD84DAA4946A8A0290E17543EF4C72B7B231ED931ED428F40B6181AEE80511
Server: 0x02BCCBEFF7265AE31209D65833069F5B3B19E3276052EBA314DAA02DB3846619
KeyUpdates log, server:
0: 0xE6A68F4015AEB21DD6FE095CDCE85E287C0972C3E77C3C38F308D53F4FB8D13B
Traffic keys:
Client write: 0x37390CD25270451A5937E44BEB40ED7E
Server write: 0x5EC4B48394CBB82BF514C1AF96B67251
KeyUpdates log, server:
0: 0x0F65084090EF10F91EE8EC98CA6C2EB6
Traffic base IVs:
Client write (base IV): 0xD53F97BEBC17E9D755953BF6
Server write (base IV): 0x2AB91EF0EDE41A9E64D17BCA
KeyUpdates log, server:
0: 0xF1E9E264D799670734477B4B
--- Messages ---
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 92:9E:82:D6:66:07:86:C2:BC:0D:99:39:BF:05:62:22:33:C7:CE:1F:85:79:84:E5:EE:BA:95:48:C1:CF:E4:BF
Client SessionID: 0F:F6:60:AB:A2:CE:80:8D:36:30:7A:02:3C:A7:4B:AC:58:8D:EF:86:BE:7C:9F:74:C6:86:B6:20:69:E0:72:26
Extensions:
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0x8CF9B86BA900B0288CB10445A7400A4AB9B9EF93A977656A14066708AE2DA617
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 23 (0x0017); /non-TLS-1.3/
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 35 (0x0023); /non-TLS-1.3/
Type: 05 (0x0005); "status_request"
01:00:00:00:00
HELLO_RETRY_REQUEST (sent, server)
Legacy Version: 0x0303
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
HelloRetryRequest (Server Random): CF:21:AD:74:E5:9A:61:11:BE:1D:8C:02:1E:65:B8:91:C2:A2:11:16:7A:BB:8C:5E:07:9E:09:E2:C8:A8:33:9C
SessionID: 0F:F6:60:AB:A2:CE:80:8D:36:30:7A:02:3C:A7:4B:AC:58:8D:EF:86:BE:7C:9F:74:C6:86:B6:20:69:E0:72:26
Extensions:
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
[Legacy ChangeCipherSpec message present (client)]
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 92:9E:82:D6:66:07:86:C2:BC:0D:99:39:BF:05:62:22:33:C7:CE:1F:85:79:84:E5:EE:BA:95:48:C1:CF:E4:BF
Client SessionID: 0F:F6:60:AB:A2:CE:80:8D:36:30:7A:02:3C:A7:4B:AC:58:8D:EF:86:BE:7C:9F:74:C6:86:B6:20:69:E0:72:26
Extensions:
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
x = 0x5D09608900406FB3D3EEC7D3E832AB0CD513D5EC7D5121169DB69AD5DF8F66F9F69FA6D50191F2882B0DD0CA2D681074
y = 0xABBD2A0108370517678B52D3EEDB1E49CD9D625923B3C4209CD6DFC78BF998D936B97806952EC7FCC8CEF2BA05E071EB
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 23 (0x0017); /non-TLS-1.3/
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 35 (0x0023); /non-TLS-1.3/
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
SERVER_HELLO (sent)
Legacy Version: 0x0303
Cipher suite: 0x1301 (TLS_AES_128_GCM_SHA256)
Server Random: DE:AD:DE:AD:DE:AD:C0:DE:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
SessionID: 0F:F6:60:AB:A2:CE:80:8D:36:30:7A:02:3C:A7:4B:AC:58:8D:EF:86:BE:7C:9F:74:C6:86:B6:20:69:E0:72:26
Extensions:
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
x = 0x884DFC0FE9602539133D59E3779E9DE8644D3532211C1061EFD16D15BE349D6723496325775E87CF3D396F1C02FCC5CF
y = 0x063315C18E34D26B9085A96A495F17B8557DB379DB6ABED0788C60417FCE917ADD8976BB955D9E7E1B1CC6C06F577280
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
SERVER_HANDSHAKE_MESSAGES (sent)
Type: 8 (0x08) - "encrypted_extensions"
Length (octets, dec.): 2
00:00
Type: 11 (0x0B) - "certificate"
Length (octets, dec.): 2697
[...] /skipped 2697 data octets/
Type: 15 (0x0F) - "certificate_verify"
Length (octets, dec.): 106
05:03:00:66:30:64:02:30:1E:12:B9:59:65:7A:EA:78:B7:DA:79:C9:CE:CB:A2:C7:E1:D5:A4:62:E3:44:7A:95
56:D0:32:B1:0D:ED:AE:FA:10:8F:7B:BE:CB:20:7F:E6:98:9C:E7:E7:20:4F:33:D0:02:30:7E:0D:28:B9:69:C0
3C:2E:4E:70:F3:71:DB:CA:99:FB:DB:FF:88:94:D2:35:AD:F2:EB:2F:10:F3:05:02:A5:33:3C:7D:12:9B:BC:A5
46:3B:C8:72:06:17:80:80:64:6B
Type: 20 (0x14) - "finished"
Length (octets, dec.): 32
CD:DB:55:1E:ED:27:AF:01:07:39:F3:B4:4A:79:BC:38:C8:7A:AD:DB:4D:4D:76:F3:53:40:76:2F:F2:CC:C3:41
CLIENT_FINISHED (received)
Finished value: 0xF368D78C69CFD5A9E3A7C06854127DD5C41FB4C4F3DAB86FA4722BFC933FF755
Client Finished status: OK
CLIENT_APPLICATION_DATA (recieved)
ASCII dump (filtered):
GET / HTTP/1.1..accept: */*..user-agent: Mozilla/5.0 AppleWebKit
/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebo
t@anthropic.com)..accept-encoding: gzip, br, zstd, deflate..host
: tls13.1d.pw....
[Server KeyUpdate sent /message skipped/]
TCP: server: 194.87.103.72:443; client: 216.73.217.78:13561; timestamp: 1791504167
Contacts: dxdt.ru, alex/()\/abaabb.xyz.
/\_/\
( 0.0 )
= ^ =
/|_|\
(") (")=~
Provide ESNI to get second ASCII cat
Elapsed server side: 299ms; ServerHello sent: 149ms (including HelloRetryRequest time); TLS connection established: 298ms.