Successfully connected
TLS 1.3 OK; HelloRetryRequest used; server-initiated key update accomplished;
Detailed description:
v.0.24.4-p
(This TLS-1.3-only server supports: HelloRetryRequest, KeyUpdate, ECDHE, FFDHE, X25519MLKEM768, SecP256r1MLKEM768, X25519Kyber768, ESNI, etc.)
HelloRetryRequest used to (re)negotiate DH group
First ClientHello, key shares: 0x001D
Second ClientHello, key shares: 0x0018
CRYPTO_CONTEXT
Protocol version: 0x0304
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
Key exchange: 0x0018 (Secp384r1)
(Handshake level)
Handshake secrets:
Client: 0xA36828A196A705AD8A3C13D2889CFFBAE5612536743BE79BBFE85A3429E85540
Server: 0x0B06A4B299D28F246C6BB227B9D1CC81AB453E37064FF5C1CCDD5747DF3C6238
Handshake keys:
Client write: 0xFA3176302F9B3F1555B3252E73F9B3B22727FE60180C063DC8D7859F6F55C7B4
Server write: 0x241A25D2816863C44AF14C77FD876C256B378B68910F502651D0B4BC911902CE
Handshake IVs:
Client write (IV): 0x7936DFC9FC9FD79647134594
Server write (IV): 0x566030EB36C2FAA1014663CD
(Traffic level)
Traffic secrets:
Client: 0x4ED2E7B14CB1A1FD482D4FCEBA2FB85FFF6862E4D0CDDA58AD4051B2CF193760
Server: 0x093DFA9A698703880278BAA4F0F35623C489B2FCFDCFAA69FD1B403E4A8C4B89
KeyUpdates log, server:
0: 0xE3D8B69D6C5A39478B095B274719633C9E5C5726C287AAC906353C6E8DEFC784
Traffic keys:
Client write: 0x5CCA2B0384976ED48E26BB416ED4EA9F5F0DD73FE576D7D1843929BB4E469B72
Server write: 0xEA347EB6176ED8674EC1FFD8010B3A7BC8F81DAF4BB9B21227436E36F2A0278F
KeyUpdates log, server:
0: 0x26CA9E94C955EA04A10F9BAC42C08E35959EA657ED26AED0F9B1B82B63856ACF
Traffic base IVs:
Client write (base IV): 0xBFB02EE7E390DE725C3FB16C
Server write (base IV): 0x070D3122E4DB520747955DC3
KeyUpdates log, server:
0: 0x1E912CE8A0EEE5448B72B7D4
--- Messages ---
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 9D:A6:D9:E0:EC:9E:32:80:0C:ED:C5:6A:55:9C:07:8B:A3:31:61:1B:D2:C8:7D:8C:F2:DF:B6:14:5A:B4:AD:96
Client SessionID: 71:C6:CD:15:43:93:A2:B0:77:1E:8A:93:28:27:E5:8B:52:CD:D0:0D:39:44:D5:51:D4:A3:4D:F3:FB:47:BB:4E
Extensions:
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 51 (0x0033); "key_share"
X25519 (0x001D)
x = 0xF52E5C7367508457869CCD4C0D9720D270F2355103DA23774DC4009C3D092407
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 23 (0x0017); /non-TLS-1.3/
Type: 35 (0x0023); /non-TLS-1.3/
HELLO_RETRY_REQUEST (sent, server)
Legacy Version: 0x0303
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
HelloRetryRequest (Server Random): CF:21:AD:74:E5:9A:61:11:BE:1D:8C:02:1E:65:B8:91:C2:A2:11:16:7A:BB:8C:5E:07:9E:09:E2:C8:A8:33:9C
SessionID: 71:C6:CD:15:43:93:A2:B0:77:1E:8A:93:28:27:E5:8B:52:CD:D0:0D:39:44:D5:51:D4:A3:4D:F3:FB:47:BB:4E
Extensions:
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
[Legacy ChangeCipherSpec message present (client)]
CLIENT_HELLO (recieved)
Version: 0x0303
Cipher suites:
0x1302,0x1301,0x1303,0xC02C,0xC02B,0xCCA9,0xC030,0xC02F
0xCCA8,0x00FF
Client Random: 9D:A6:D9:E0:EC:9E:32:80:0C:ED:C5:6A:55:9C:07:8B:A3:31:61:1B:D2:C8:7D:8C:F2:DF:B6:14:5A:B4:AD:96
Client SessionID: 71:C6:CD:15:43:93:A2:B0:77:1E:8A:93:28:27:E5:8B:52:CD:D0:0D:39:44:D5:51:D4:A3:4D:F3:FB:47:BB:4E
Extensions:
Type: 11 (0x000B); /non-TLS-1.3/
01:00
Type: 05 (0x0005); "status_request"
01:00:00:00:00
Type: 10 (0x000A); "supported_groups"
0x001D (X25519)
0x0017 (Secp256r1)
0x0018 (Secp384r1)
Type: 43 (0x002B); "supported_versions"
0x0304 (TLS 1.3)
0x0303 (TLS 1.2)
Type: 13 (0x000D); "signature_algorithms"
0x0503 (ECDSA_SECP384R1_SHA384)
0x0403 (ECDSA_SECP256R1_SHA256)
0x0807 (ED25519)
0x0806 (RSA_PSS_RSAE_SHA512)
0x0805 (RSA_PSS_RSAE_SHA384)
0x0804 (RSA_PSS_RSAE_SHA256)
0x0601 (RSA_PKCS1_SHA512)
0x0501 (RSA_PKCS1_SHA384)
0x0401 (RSA_PKCS1_SHA256)
Type: 16 (0x0010); "application_layer_protocol_negotiation"
68:32 (HTTP/2/TLS)
68:74:74:70:2F:31:2E:31 (HTTP/1.1)
Type: 45 (0x002D); "psk_key_exchange_modes"
01:01
Type: 44 (0x002C); "cookie"
00:08:0C:00:FE:E1:C0:DE:FA:57
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
x = 0x4A775F81AC7D28F1A830B67C6ACFA35AFBBE39BF41D832759D848C9503D5A11C03953C98D1CA3A8CD919004FF29CD9A5
y = 0x58CAB628AD098326B755FAD17A0C77FAF9B6C571593A1DE0FA09C20E998E0A3EE56670C3B2B0E5FD13147C894F730279
Type: 00 (0x0000); "server_name"
00:00:0E:00:00:0B:74:6C:73:31:33:2E:31:64:2E:70:77
hostname: tls13.1d.pw
Type: 23 (0x0017); /non-TLS-1.3/
Type: 35 (0x0023); /non-TLS-1.3/
SERVER_HELLO (sent)
Legacy Version: 0x0303
Cipher suite: 0x1303 (TLS_CHACHA20_POLY1305_SHA256)
Server Random: DE:AD:DE:AD:DE:AD:C0:DE:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
SessionID: 71:C6:CD:15:43:93:A2:B0:77:1E:8A:93:28:27:E5:8B:52:CD:D0:0D:39:44:D5:51:D4:A3:4D:F3:FB:47:BB:4E
Extensions:
Type: 51 (0x0033); "key_share"
Secp384r1 (0x0018)
x = 0x884DFC0FE9602539133D59E3779E9DE8644D3532211C1061EFD16D15BE349D6723496325775E87CF3D396F1C02FCC5CF
y = 0x063315C18E34D26B9085A96A495F17B8557DB379DB6ABED0788C60417FCE917ADD8976BB955D9E7E1B1CC6C06F577280
Type: 43 (0x002B); "supported_versions"
0x0304
[Legacy ChangeCipherSpec message sent (server)]
SERVER_HANDSHAKE_MESSAGES (sent)
Type: 8 (0x08) - "encrypted_extensions"
Length (octets, dec.): 2
00:00
Type: 11 (0x0B) - "certificate"
Length (octets, dec.): 2699
[...] /skipped 2699 data octets/
Type: 15 (0x0F) - "certificate_verify"
Length (octets, dec.): 107
05:03:00:67:30:65:02:30:79:5B:54:11:1C:94:85:5F:DD:8A:0C:29:5B:8C:D1:BE:A6:FA:F1:DC:A7:66:A0:09
3E:83:21:13:7B:64:AD:BA:73:18:8E:6B:C3:75:BA:73:6E:2F:80:A7:DF:B5:67:CA:02:31:00:D0:9E:4B:FD:D3
25:99:55:E1:6A:4B:4C:BB:93:CF:BE:0D:91:BD:7A:B7:0A:92:92:1C:C7:D0:B6:40:55:2B:63:D1:30:27:49:79
AB:2E:D8:29:42:B6:83:8C:2C:CA:3F
Type: 20 (0x14) - "finished"
Length (octets, dec.): 32
86:70:81:AE:A3:89:84:9A:50:CC:A0:81:AB:87:97:25:9E:2A:1C:8A:66:07:99:3D:50:02:AF:FC:B9:9A:E5:B0
CLIENT_FINISHED (received)
Finished value: 0xE7129219EDC51385EF9EC59A089AE2AA4A8C4E6B7F7AB1BEB14EF0E86F0AF814
Client Finished status: OK
CLIENT_APPLICATION_DATA (recieved)
ASCII dump (filtered):
GET / HTTP/1.1..accept: */*..user-agent: Mozilla/5.0 AppleWebKit
/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebo
t@anthropic.com)..accept-encoding: gzip, br, zstd, deflate..host
: tls13.1d.pw....
[Server KeyUpdate sent /message skipped/]
TCP: server: 194.87.103.72:443; client: 216.73.217.114:2858; timestamp: 1791158767
Contacts: dxdt.ru, alex/()\/abaabb.xyz.
/\_/\
( 0.0 )
= ^ =
/|_|\
(") (")=~
Provide ESNI to get second ASCII cat
Elapsed server side: 344ms; ServerHello sent: 171ms (including HelloRetryRequest time); TLS connection established: 343ms.