Successfully connected
TLS 1.3 OK; HelloRetryRequest used; server-initiated key update accomplished;
Detailed description:
v.0.24.4-p
(This TLS-1.3-only server supports: HelloRetryRequest, KeyUpdate, ECDHE, FFDHE, X25519MLKEM768, SecP256r1MLKEM768, X25519Kyber768, ESNI, etc.)
HelloRetryRequest used to (re)negotiate DH group
First ClientHello, key shares: 0x001D
Second ClientHello, key shares: 0x0017
CRYPTO_CONTEXT
Protocol version: 0x0304
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
Key exchange: 0x0017 (Secp256r1)
(Handshake level)
Handshake secrets:
Client: 0x98E34EDCA46D14B7D8EDF60BD73E9AF01225512F5DB13A7F786B6EB3BDFCE397
Server: 0x38F6577D895B522AC503A2DC26B06E2D6EF02E3C02B8C1AB20B4DB0DAAE089D0
Handshake keys:
Client write: 0x852EDB5014AFCF74A7951C7774A98EE6F66E2A5EF9A9A265001C4E06162830C1
Server write: 0x5D51B32CCC586BA1AFC1CA3F50CC6FDAFFC80D8A0929598EAA2CB55568764C8A
Handshake IVs:
Client write (IV): 0x5531B0883DA16FCEC04F4D66
Server write (IV): 0x4D863962B8CE59DE29F47D77
(Traffic level)
Traffic secrets:
Client: 0xB92706EB39E5484367F8D112AAA9584149220880BBCA1D637F3A4193AA15C700
Server: 0x6A6F0264CFEC6C503BE9E21CE6040A27B258FE5D5C0532B5D84690AE0C09DB89
KeyUpdates log, server:
0: 0x910D53556FD1A75026150F10AD08CA1C01BC8249502EA39A788CBC82485395EF
Traffic keys:
Client write: 0xEE5A801F61257F641DC73D8FF2EC4632F0BA47AE062139907AA50AC284807386
Server write: 0xD01D370ED848D961370339B2B84F63912B7109D1EB0CF5B1DE20B9146706B8D9
KeyUpdates log, server:
0: 0x0B9BFCFB70CCA1E34D5C1D271841AE051D146235351DF5050CDBF54CD509F7FD
Traffic base IVs:
Client write (base IV): 0x208571169629903AB5240C80
Server write (base IV): 0x1645AA533416DEAFE8219A36
KeyUpdates log, server:
0: 0x9D5CBD896A3AE8F66E333103
--- Messages ---
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: D9:11:E4:61:88:71:15:BD:6B:42:AB:36:79:1B:C5:D9:B0:BE:0A:AE:0E:76:59:93:7F:78:D6:DC:89:78:9A:F1
Client SessionID: 5F:4D:B3:AD:D3:D9:48:11:0F:20:4C:BF:BF:3D:2A:AB:08:28:72:E8:87:C7:6B:EB:14:7D:15:8C:78:E5:12:EA
Extensions:
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0x89622A1A1A8D28D0350EF8EB8881FC38A921C413D5793C9516B20661CFE08905
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 23 (0x0017); /non-TLS-1.3/
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 35 (0x0023); /non-TLS-1.3/
HELLO_RETRY_REQUEST (sent, server)
Legacy Version: 0x0303
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
HelloRetryRequest (Server Random): CF:21:AD:74:E5:9A:61:11:BE:1D:8C:02:1E:65:B8:91:C2:A2:11:16:7A:BB:8C:5E:07:9E:09:E2:C8:A8:33:9C
SessionID: 5F:4D:B3:AD:D3:D9:48:11:0F:20:4C:BF:BF:3D:2A:AB:08:28:72:E8:87:C7:6B:EB:14:7D:15:8C:78:E5:12:EA
Extensions:
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
[Legacy ChangeCipherSpec message present (client)]
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: D9:11:E4:61:88:71:15:BD:6B:42:AB:36:79:1B:C5:D9:B0:BE:0A:AE:0E:76:59:93:7F:78:D6:DC:89:78:9A:F1
Client SessionID: 5F:4D:B3:AD:D3:D9:48:11:0F:20:4C:BF:BF:3D:2A:AB:08:28:72:E8:87:C7:6B:EB:14:7D:15:8C:78:E5:12:EA
Extensions:
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
x = 0x20791DCBD24C559A69AA7A2DE9395A0C2760B667D6F2A22F35810FCA6098EAAE
y = 0x7E7FF7A77910D63043678E0971AA4144196F3791F89F8F2B785CA4C8E835C3F6
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 23 (0x0017); /non-TLS-1.3/
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 35 (0x0023); /non-TLS-1.3/
SERVER_HELLO (sent)
Legacy Version: 0x0303
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
Server Random: DE:AD:DE:AD:DE:AD:C0:DE:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
SessionID: 5F:4D:B3:AD:D3:D9:48:11:0F:20:4C:BF:BF:3D:2A:AB:08:28:72:E8:87:C7:6B:EB:14:7D:15:8C:78:E5:12:EA
Extensions:
Type: 51 (0x0033); "key_share"
Secp256r1 (0x0017)
x = 0x1FADAC79156E08C8532CE88DF887273141ACE16E44E9C268CE496596F41B65FA
y = 0xF82394637B6ACF004AB253F956BD2CD6CA6C9AD8454BF1FBF281A6C54A93D99C
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
SERVER_HANDSHAKE_MESSAGES (sent)
Type: 8 (0x08) - "encrypted_extensions"
Length (octets, dec.): 2
00:00
Type: 11 (0x0B) - "certificate"
Length (octets, dec.): 2701
[...] /skipped 2701 data octets/
Type: 15 (0x0F) - "certificate_verify"
Length (octets, dec.): 108
05:03:00:68:30:66:02:31:00:E8:E5:90:9C:35:B6:38:A9:F9:14:E0:97:97:5D:21:D5:07:E0:A4:E7:89:87:25
83:08:B7:C9:F3:5D:AD:F2:21:1E:94:8D:FA:F1:F5:C9:C3:71:C6:69:EF:F4:A0:65:5A:02:31:00:FA:AF:17:C7
C4:A4:47:D1:9E:C6:B5:29:78:42:F6:5F:21:5D:31:DB:D1:38:3A:FE:68:0B:DB:EE:6D:A6:C4:97:90:10:93:AC
E3:84:14:8F:3D:E2:BB:93:F2:43:53:FA
Type: 20 (0x14) - "finished"
Length (octets, dec.): 32
A2:4C:17:B8:3A:46:BE:58:F4:64:0F:36:FC:87:B0:D4:60:95:28:BA:F3:24:43:AC:09:65:BA:E0:3A:E5:E6:10
CLIENT_FINISHED (received)
Finished value: 0x7539CB5415442990FF05A117C848C0F2017E217B5A9F3F15DD746DED07A208A5
Client Finished status: OK
CLIENT_APPLICATION_DATA (recieved)
ASCII dump (filtered):
GET / HTTP/1.1..accept: */*..user-agent: Mozilla/5.0 AppleWebKit
/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebo
t@anthropic.com)..accept-encoding: gzip, br, zstd, deflate..host
: tls13.1d.pw....
[Server KeyUpdate sent /message skipped/]
TCP: server: 194.87.103.72:443; client: 216.73.216.187:53840; timestamp: 1790395384
Contacts: dxdt.ru, alex/()\/abaabb.xyz.
/\_/\
( 0.0 )
= ^ =
/|_|\
(") (")=~
Provide ESNI to get second ASCII cat
Elapsed server side: 300ms; ServerHello sent: 152ms (including HelloRetryRequest time); TLS connection established: 299ms.