Successfully connected
TLS 1.3 OK; HelloRetryRequest used; server-initiated key update accomplished;
Detailed description:
v.0.24.4-p
(This TLS-1.3-only server supports: HelloRetryRequest, KeyUpdate, ECDHE, FFDHE, X25519MLKEM768, SecP256r1MLKEM768, X25519Kyber768, ESNI, etc.)
HelloRetryRequest used to (re)negotiate DH group
First ClientHello, key shares: 0x0018
Second ClientHello, key shares: 0x001D
CRYPTO_CONTEXT
Protocol version: 0x0304
Cipher suite: 0x1302 (TLS_AES_256_GCM_SHA384)
Key exchange: 0x001D (X25519)
(Handshake level)
Handshake secrets:
Client: 0xFE8EF122D9920A41E316B2516CCA287866ABEFA1476C03ECEB03B96E37E75989112657ED1B7D0DF52A261F426DA94CB5
Server: 0xF59686BD87B75816D0406FAAFCBFAF532D3AD66BA13BCFE51950CC6D1E88D454A190F90FB627A355BB42E01DD316D1F0
Handshake keys:
Client write: 0xB575A90E856F9C465EB1B857F2E68A5F6D49DA3DEFE5890FE8746FA96DABC420
Server write: 0x2E8C089A56F31CC7065EE120A20475C3E0D15F13F99C238EED6AA3E30D1A6F02
Handshake IVs:
Client write (IV): 0x9BF25DA2057F555AE7FA2982
Server write (IV): 0x0A7A892F997D4463A321ADEB
(Traffic level)
Traffic secrets:
Client: 0xC38E55202FF6AB67DBEEB7D9B0DC313AC578A9ADAC00E2A53A71A9074345601E0C3BE4D43BBC9D1D30EE7CB3DD78F64F
Server: 0x9C9537628BFC5EB93951E1C050ACFA5A5D184B64DF5D60D5A27CD48CDFE49C7A942C732B2C1ADB3EA576A2E55CD645DE
KeyUpdates log, server:
0: 0x5B71EF9FD9C773A5D41E0A1B16111F2E3A2214CD2F5557BD11AC901762C3D07376E0B2833D615D66E4713018FA58770E
Traffic keys:
Client write: 0x88C3033EAA53FA03119E85A4584C35BFF69C33B453F985446E13C95C1A340E29
Server write: 0x6EB5D78366D70E02C957200BD8D297DC206B64FD98A0631B45E3992C93F73514
KeyUpdates log, server:
0: 0xA1C92C0D2167136EE0B0C6BFF13023D19BE44D46CFC07B606A6B7661629E45C3
Traffic base IVs:
Client write (base IV): 0x6A0AADE7152C347DA3997B08
Server write (base IV): 0x1B51611DCDFE0F811E4CE942
KeyUpdates log, server:
0: 0x049DCD46C9B0004155DDA5AF
--- Messages ---
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 1B:20:68:18:84:36:CE:6D:8E:B3:84:D6:45:1B:27:08:D8:0A:77:74:09:8F:89:B8:5A:C1:24:CD:50:71:E9:45
Client SessionID: FF:C7:A6:DB:0B:21:C9:3C:C3:8D:7A:9C:C4:E6:6A:81:34:B4:62:87:5D:CD:01:E5:93:DC:AC:C0:C4:CC:E3:0A
Extensions:
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
x = 0xFFF9A6FF00E77EE167D4445EB3EFADB47F1C7BB827EA99807DD3377F85F79F4BAA78D4B132A0B9A12D5D24261614DE3C
y = 0x37CFF5D5AA6B5F21BBB5E70EA9118EC4F3886039F0939F70C07CE233A5A77557444947667184A471CC0016B41C0D5B5B
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 35 (0x0023); /non-TLS-1.3/
Type: 23 (0x0017); /non-TLS-1.3/
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
HELLO_RETRY_REQUEST (sent, server)
Legacy Version: 0x0303
Cipher suite: 0x1302 (TLS_AES_256_GCM_SHA384)
HelloRetryRequest (Server Random): CF:21:AD:74:E5:9A:61:11:BE:1D:8C:02:1E:65:B8:91:C2:A2:11:16:7A:BB:8C:5E:07:9E:09:E2:C8:A8:33:9C
SessionID: FF:C7:A6:DB:0B:21:C9:3C:C3:8D:7A:9C:C4:E6:6A:81:34:B4:62:87:5D:CD:01:E5:93:DC:AC:C0:C4:CC:E3:0A
Extensions:
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
[Legacy ChangeCipherSpec message present (client)]
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 1B:20:68:18:84:36:CE:6D:8E:B3:84:D6:45:1B:27:08:D8:0A:77:74:09:8F:89:B8:5A:C1:24:CD:50:71:E9:45
Client SessionID: FF:C7:A6:DB:0B:21:C9:3C:C3:8D:7A:9C:C4:E6:6A:81:34:B4:62:87:5D:CD:01:E5:93:DC:AC:C0:C4:CC:E3:0A
Extensions:
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0x336B5F489D653049267810890D617132ECA76F0B1CC400CDF3ACBC3671E7BD5F
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 35 (0x0023); /non-TLS-1.3/
Type: 23 (0x0017); /non-TLS-1.3/
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
SERVER_HELLO (sent)
Legacy Version: 0x0303
Cipher suite: 0x1302 (TLS_AES_256_GCM_SHA384)
Server Random: DE:AD:DE:AD:DE:AD:C0:DE:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
SessionID: FF:C7:A6:DB:0B:21:C9:3C:C3:8D:7A:9C:C4:E6:6A:81:34:B4:62:87:5D:CD:01:E5:93:DC:AC:C0:C4:CC:E3:0A
Extensions:
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0x145891E6697DAA111BD9A43EB39FA860847D09303D603128F82CE7451DAE456B
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
SERVER_HANDSHAKE_MESSAGES (sent)
Type: 8 (0x08) - "encrypted_extensions"
Length (octets, dec.): 2
00:00
Type: 11 (0x0B) - "certificate"
Length (octets, dec.): 2697
[...] /skipped 2697 data octets/
Type: 15 (0x0F) - "certificate_verify"
Length (octets, dec.): 106
05:03:00:66:30:64:02:30:2C:E8:B6:27:CF:C3:EC:03:01:33:27:D5:64:0D:3A:3B:B8:3A:EA:53:81:DC:A4:24
11:8B:A0:17:3C:AE:CB:75:40:9D:09:DE:6C:7E:B4:C6:A4:B9:3E:A9:BC:38:F3:DA:02:30:28:44:C8:0A:BA:33
1E:44:E4:76:40:0D:5D:51:5A:0A:74:B6:9F:8B:BD:E2:86:E7:DA:14:0B:80:D8:D3:B5:1E:5F:CA:DF:B1:F6:60
A6:1F:7B:F0:3E:13:39:D1:50:0F
Type: 20 (0x14) - "finished"
Length (octets, dec.): 48
A8:C8:79:6F:14:92:85:D6:0A:73:06:4D:D6:9C:34:7D:7F:E2:92:15:C4:C4:4E:6E:4C:C4:EF:06:E3:26:E0:61
63:98:62:D2:BF:F0:BD:B7:3B:D1:39:B0:E1:EE:8C:A6
CLIENT_FINISHED (received)
Finished value: 0xDF2D1D7B10A2DB0146EB8B77920150DCB70BE1EFBFB38EE32C53BD823DDAB3164CC28D3C6706CC364DC6C474E5A28C53
Client Finished status: OK
CLIENT_APPLICATION_DATA (recieved)
ASCII dump (filtered):
GET / HTTP/1.1..accept: */*..user-agent: Mozilla/5.0 AppleWebKit
/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebo
t@anthropic.com)..accept-encoding: gzip, br, zstd, deflate..host
: tls13.1d.pw....
[Server KeyUpdate sent /message skipped/]
TCP: server: 194.87.103.72:443; client: 216.73.217.114:53699; timestamp: 1790986147
Contacts: dxdt.ru, alex/()\/abaabb.xyz.
/\_/\
( 0.0 )
= ^ =
/|_|\
(") (")=~
Provide ESNI to get second ASCII cat
Elapsed server side: 290ms; ServerHello sent: 143ms (including HelloRetryRequest time); TLS connection established: 289ms.