Wireshark SSL debug log ssl_association_remove removing TCP 10005 - ssl handle 0x155fbb0 Private key imported: KeyID a7:19:88:df:c9:f4:d7:34:73:30:cf:b6:8a:9e:d2:83:... ssl_load_key: swapping p and q parameters and recomputing u ssl_init IPv4 addr '127.0.0.1' (127.0.0.1) port '10005' filename '/home/tle/openssl/TLS/server.key' password(only for p12 file) '' ssl_init private key file /home/tle/openssl/TLS/server.key successfully loaded. association_add TCP port 10005 protocol ssl handle 0x155fbb0 dissect_ssl enter frame #10 (first time) ssl_session_init: initializing ptr 0x7f6679fa06a8 size 688 conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 99 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 94, ssl state 0x00 association_find: TCP port 33648 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 90 bytes, remaining 99 packet_from_server: is from server - FALSE ssl_find_private_key server 127.0.0.1:10005 dissect_ssl3_hnd_hello_common found CLIENT RANDOM -> state 0x01 dissect_ssl enter frame #19 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 1024 dissect_ssl3_record found version 0x0303(TLS 1.2) -> state 0x11 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 58, ssl state 0x11 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 54 bytes, remaining 63 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 ssl_restore_session can't find stored session trying to use SSL keylog in failed to open SSL keylog cannot find master secret in keylog file either dissect_ssl3_hnd_srv_hello found CIPHER 0x003D -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material record: offset = 63, reported_length_remaining = 961 need_desegmentation: offset = 63, reported_length_remaining = 961 dissect_ssl enter frame #21 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 1324 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 1319, ssl state 0x17 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 1315 bytes, remaining 1324 dissect_ssl enter frame #21 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 113 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 108, ssl state 0x17 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 13 offset 5 length 100 bytes, remaining 113 dissect_ssl3_handshake iteration 0 type 14 offset 109 length 0 bytes, remaining 113 dissect_ssl enter frame #28 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 1965 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 1589, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 1585 bytes, remaining 1594 record: offset = 1594, reported_length_remaining = 371 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 134, ssl state 0x17 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 16 offset 1599 length 130 bytes, remaining 1733 pre master encrypted[128]: | 5a 13 a6 b3 1f 30 2f 56 42 21 6e d3 95 d7 c4 f2 |Z....0/VB!n.....| | e0 78 10 2e d1 1a 56 fc 84 a8 88 67 b5 b0 70 a6 |.x....V....g..p.| | 3d b8 5f 80 79 34 05 70 64 fc d2 39 2f 5c 20 79 |=._.y4.pd..9/\ y| | 69 3f 4f fb c4 56 a6 d7 5b d6 bf 72 69 bc 03 ce |i?O..V..[..ri...| | fd 90 be 9a 08 75 f5 36 d5 98 7b 62 ce b3 8f 7e |.....u.6..{b...~| | e8 83 6d 7b 2a 11 d4 48 c7 45 f8 7d 10 80 89 ac |..m{*..H.E.}....| | 18 34 c6 1b 23 bd 2e 2b c8 98 94 4a fa 37 ef da |.4..#..+...J.7..| | 88 b2 98 c1 ce c1 ab 70 e9 93 0f 39 a1 c5 93 df |.......p...9....| ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 79 bytes, decr_len 127 decrypted_unstrip_pre_master[127]: | 02 62 f3 c1 d5 48 e0 09 56 c1 9f ee 7a fa 7a 78 |.b...H..V...z.zx| | a2 59 3a 04 6a 4a 29 99 cf 07 02 c6 50 91 48 9c |.Y:.jJ).....P.H.| | c7 37 29 29 08 5b e6 47 0e 67 10 37 35 73 9f 33 |.7)).[.G.g.75s.3| | a7 79 35 99 ae 7c fd 87 67 f6 30 6b d9 17 07 8f |.y5..|..g.0k....| | 27 45 60 8f 22 81 d0 32 0a 58 3f 97 a5 c5 00 03 |'E`."..2.X?.....| | 03 14 93 ee ee 04 1b 08 d7 09 78 2b 43 78 4a ff |..........x+CxJ.| | a7 a0 c3 37 61 96 ed e0 15 e2 af 76 6c 0a 2e 77 |...7a......vl..w| | f5 c1 9a 20 1c 86 5e 7c 3b 7d 3d 0c c8 0c d8 |... ..^|;}=.... | pre master secret[48]: | 03 03 14 93 ee ee 04 1b 08 d7 09 78 2b 43 78 4a |...........x+CxJ| | ff a7 a0 c3 37 61 96 ed e0 15 e2 af 76 6c 0a 2e |....7a......vl..| | 77 f5 c1 9a 20 1c 86 5e 7c 3b 7d 3d 0c c8 0c d8 |w... ..^|;}=....| ssl_generate_keyring_material:PRF(pre_master_secret) pre master secret[48]: | 03 03 14 93 ee ee 04 1b 08 d7 09 78 2b 43 78 4a |...........x+CxJ| | ff a7 a0 c3 37 61 96 ed e0 15 e2 af 76 6c 0a 2e |....7a......vl..| | 77 f5 c1 9a 20 1c 86 5e 7c 3b 7d 3d 0c c8 0c d8 |w... ..^|;}=....| client random[32]: | ee f1 58 b0 56 71 0e f6 0a 62 71 d0 f5 ab c3 d4 |..X.Vq...bq.....| | 1a df 1e e5 1c f1 72 d8 eb 90 ca 9e fc 4e a7 f3 |......r......N..| server random[32]: | 9e c9 d9 ae 95 11 49 4f 3f a4 bb 93 00 e7 40 b8 |......IO?.....@.| | 0d 7d 31 cd ea f6 98 8b 06 3f 67 88 1e d9 99 76 |.}1......?g....v| tls12_prf: tls_hash(hash_alg SHA256 secret_len 48 seed_len 77 ) tls_hash: hash secret[48]: | 03 03 14 93 ee ee 04 1b 08 d7 09 78 2b 43 78 4a |...........x+CxJ| | ff a7 a0 c3 37 61 96 ed e0 15 e2 af 76 6c 0a 2e |....7a......vl..| | 77 f5 c1 9a 20 1c 86 5e 7c 3b 7d 3d 0c c8 0c d8 |w... ..^|;}=....| tls_hash: hash seed[77]: | 6d 61 73 74 65 72 20 73 65 63 72 65 74 ee f1 58 |master secret..X| | b0 56 71 0e f6 0a 62 71 d0 f5 ab c3 d4 1a df 1e |.Vq...bq........| | e5 1c f1 72 d8 eb 90 ca 9e fc 4e a7 f3 9e c9 d9 |...r......N.....| | ae 95 11 49 4f 3f a4 bb 93 00 e7 40 b8 0d 7d 31 |...IO?.....@..}1| | cd ea f6 98 8b 06 3f 67 88 1e d9 99 76 |......?g....v | hash out[48]: | 72 1b 80 4c 65 72 15 17 8e 3d 9a b4 92 ee f7 74 |r..Ler...=.....t| | c8 72 82 de d9 d9 85 95 b2 7a 6c 36 58 5a a6 5a |.r.......zl6XZ.Z| | 61 fe 09 62 0a ae 7e 41 cb 10 b6 31 a9 36 f1 e0 |a..b..~A...1.6..| PRF out[48]: | 72 1b 80 4c 65 72 15 17 8e 3d 9a b4 92 ee f7 74 |r..Ler...=.....t| | c8 72 82 de d9 d9 85 95 b2 7a 6c 36 58 5a a6 5a |.r.......zl6XZ.Z| | 61 fe 09 62 0a ae 7e 41 cb 10 b6 31 a9 36 f1 e0 |a..b..~A...1.6..| master secret[48]: | 72 1b 80 4c 65 72 15 17 8e 3d 9a b4 92 ee f7 74 |r..Ler...=.....t| | c8 72 82 de d9 d9 85 95 b2 7a 6c 36 58 5a a6 5a |.r.......zl6XZ.Z| | 61 fe 09 62 0a ae 7e 41 cb 10 b6 31 a9 36 f1 e0 |a..b..~A...1.6..| ssl_generate_keyring_material sess key generation tls12_prf: tls_hash(hash_alg SHA256 secret_len 48 seed_len 77 ) tls_hash: hash secret[48]: | 72 1b 80 4c 65 72 15 17 8e 3d 9a b4 92 ee f7 74 |r..Ler...=.....t| | c8 72 82 de d9 d9 85 95 b2 7a 6c 36 58 5a a6 5a |.r.......zl6XZ.Z| | 61 fe 09 62 0a ae 7e 41 cb 10 b6 31 a9 36 f1 e0 |a..b..~A...1.6..| tls_hash: hash seed[77]: | 6b 65 79 20 65 78 70 61 6e 73 69 6f 6e 9e c9 d9 |key expansion...| | ae 95 11 49 4f 3f a4 bb 93 00 e7 40 b8 0d 7d 31 |...IO?.....@..}1| | cd ea f6 98 8b 06 3f 67 88 1e d9 99 76 ee f1 58 |......?g....v..X| | b0 56 71 0e f6 0a 62 71 d0 f5 ab c3 d4 1a df 1e |.Vq...bq........| | e5 1c f1 72 d8 eb 90 ca 9e fc 4e a7 f3 |...r......N.. | hash out[160]: | c7 9b a9 b7 48 54 08 78 0f 46 4e a2 77 f5 f5 78 |....HT.x.FN.w..x| | bb 92 76 53 92 0a 95 9c f6 c0 b1 98 ed 59 82 17 |..vS.........Y..| | 76 05 33 ff a1 6c 60 83 20 94 34 21 67 e3 83 8c |v.3..l`. .4!g...| | 3a 64 19 2c 0c 01 67 cd a2 67 81 e4 dc 73 a6 29 |:d.,..g..g...s.)| | 6b 42 fc fe e7 96 d6 f1 f5 47 ea a0 3b c9 29 71 |kB.......G..;.)q| | 15 28 88 42 69 13 d0 58 ad 5a 3c 38 44 8a 17 14 |.(.Bi..X.Z<8D...| | d5 bb 75 93 08 71 7d 51 6e 8b b3 62 52 a8 8e 90 |..u..q}Qn..bR...| | 14 db a8 c6 ab 24 a3 c1 05 ed e3 12 32 a1 95 c2 |.....$......2...| | 2e f7 d9 9b 78 a1 5f 51 86 96 b0 0c 20 05 da 82 |....x._Q.... ...| | 23 98 18 0a 38 5e 3a fd 22 e4 4b 51 f8 b5 70 86 |#...8^:.".KQ..p.| PRF out[160]: | c7 9b a9 b7 48 54 08 78 0f 46 4e a2 77 f5 f5 78 |....HT.x.FN.w..x| | bb 92 76 53 92 0a 95 9c f6 c0 b1 98 ed 59 82 17 |..vS.........Y..| | 76 05 33 ff a1 6c 60 83 20 94 34 21 67 e3 83 8c |v.3..l`. .4!g...| | 3a 64 19 2c 0c 01 67 cd a2 67 81 e4 dc 73 a6 29 |:d.,..g..g...s.)| | 6b 42 fc fe e7 96 d6 f1 f5 47 ea a0 3b c9 29 71 |kB.......G..;.)q| | 15 28 88 42 69 13 d0 58 ad 5a 3c 38 44 8a 17 14 |.(.Bi..X.Z<8D...| | d5 bb 75 93 08 71 7d 51 6e 8b b3 62 52 a8 8e 90 |..u..q}Qn..bR...| | 14 db a8 c6 ab 24 a3 c1 05 ed e3 12 32 a1 95 c2 |.....$......2...| | 2e f7 d9 9b 78 a1 5f 51 86 96 b0 0c 20 05 da 82 |....x._Q.... ...| | 23 98 18 0a 38 5e 3a fd 22 e4 4b 51 f8 b5 70 86 |#...8^:.".KQ..p.| key expansion[160]: | c7 9b a9 b7 48 54 08 78 0f 46 4e a2 77 f5 f5 78 |....HT.x.FN.w..x| | bb 92 76 53 92 0a 95 9c f6 c0 b1 98 ed 59 82 17 |..vS.........Y..| | 76 05 33 ff a1 6c 60 83 20 94 34 21 67 e3 83 8c |v.3..l`. .4!g...| | 3a 64 19 2c 0c 01 67 cd a2 67 81 e4 dc 73 a6 29 |:d.,..g..g...s.)| | 6b 42 fc fe e7 96 d6 f1 f5 47 ea a0 3b c9 29 71 |kB.......G..;.)q| | 15 28 88 42 69 13 d0 58 ad 5a 3c 38 44 8a 17 14 |.(.Bi..X.Z<8D...| | d5 bb 75 93 08 71 7d 51 6e 8b b3 62 52 a8 8e 90 |..u..q}Qn..bR...| | 14 db a8 c6 ab 24 a3 c1 05 ed e3 12 32 a1 95 c2 |.....$......2...| | 2e f7 d9 9b 78 a1 5f 51 86 96 b0 0c 20 05 da 82 |....x._Q.... ...| | 23 98 18 0a 38 5e 3a fd 22 e4 4b 51 f8 b5 70 86 |#...8^:.".KQ..p.| Client MAC key[32]: | c7 9b a9 b7 48 54 08 78 0f 46 4e a2 77 f5 f5 78 |....HT.x.FN.w..x| | bb 92 76 53 92 0a 95 9c f6 c0 b1 98 ed 59 82 17 |..vS.........Y..| Server MAC key[32]: | 76 05 33 ff a1 6c 60 83 20 94 34 21 67 e3 83 8c |v.3..l`. .4!g...| | 3a 64 19 2c 0c 01 67 cd a2 67 81 e4 dc 73 a6 29 |:d.,..g..g...s.)| Client Write key[32]: | 6b 42 fc fe e7 96 d6 f1 f5 47 ea a0 3b c9 29 71 |kB.......G..;.)q| | 15 28 88 42 69 13 d0 58 ad 5a 3c 38 44 8a 17 14 |.(.Bi..X.Z<8D...| Server Write key[32]: | d5 bb 75 93 08 71 7d 51 6e 8b b3 62 52 a8 8e 90 |..u..q}Qn..bR...| | 14 db a8 c6 ab 24 a3 c1 05 ed e3 12 32 a1 95 c2 |.....$......2...| Client Write IV[16]: | 2e f7 d9 9b 78 a1 5f 51 86 96 b0 0c 20 05 da 82 |....x._Q.... ...| Server Write IV[16]: | 23 98 18 0a 38 5e 3a fd 22 e4 4b 51 f8 b5 70 86 |#...8^:.".KQ..p.| ssl_generate_keyring_material ssl_create_decoder(client) ssl_create_decoder CIPHER: AES256 decoder initialized (digest len 32) ssl_generate_keyring_material ssl_create_decoder(server) ssl_create_decoder CIPHER: AES256 decoder initialized (digest len 32) ssl_generate_keyring_material: client seq 0, server seq 0 ssl_save_session stored session id[0]: ssl_save_session stored master secret[48]: | 72 1b 80 4c 65 72 15 17 8e 3d 9a b4 92 ee f7 74 |r..Ler...=.....t| | c8 72 82 de d9 d9 85 95 b2 7a 6c 36 58 5a a6 5a |.r.......zl6XZ.Z| | 61 fe 09 62 0a ae 7e 41 cb 10 b6 31 a9 36 f1 e0 |a..b..~A...1.6..| dissect_ssl3_handshake session keys successfully generated record: offset = 1733, reported_length_remaining = 232 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 136, ssl state 0x3F packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 1738 length 132 bytes, remaining 1874 record: offset = 1874, reported_length_remaining = 91 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - FALSE ssl_change_cipher CLIENT record: offset = 1880, reported_length_remaining = 85 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 80, ssl state 0x3F packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder ssl_decrypt_record ciphertext len 80 Ciphertext[80]: | 33 25 1e 30 d3 b6 27 6e ce 50 05 f2 fd 99 9e 1b |3%.0..'n.P......| | 07 e4 ec d2 a9 c4 f7 1f 9c 81 38 1c 97 e8 ee 1c |..........8.....| | 55 d1 a0 92 41 ac 9b f9 1d 26 0d ae 7e b0 02 75 |U...A....&..~..u| | 0e 2d d3 2a bc 0e 6f 72 42 7d a2 e4 e6 4f fb 4e |.-.*..orB}...O.N| | bd dc 7f 4c 3b 46 2d df d7 e5 7e 7f 9b 7f 1f 16 |...L;F-...~.....| ssl_decrypt_record: allocating 112 bytes for decrypt data (old len 32) Plaintext[80]: | 5a d1 4a 3f 81 43 56 8a 12 54 55 c9 53 b9 0a 97 |Z.J?.CV..TU.S...| | 14 00 00 0c 7b e3 35 23 e0 4c c3 8d 05 5c a9 38 |....{.5#.L...\.8| | 9b 42 5c fd 70 c6 5a ee 8f 47 f5 ab 82 92 4c ce |.B\.p.Z..G....L.| | 38 32 f6 78 2e de 33 24 24 ed ac d6 fc 67 a1 8e |82.x..3$$....g..| | 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f |................| ssl_decrypt_record found padding 15 final len 64 checking mac (len 16, version 303, ct 22 seq 0) tls_check_mac mac type:SHA256 md 8 Mac[32]: | 9b 42 5c fd 70 c6 5a ee 8f 47 f5 ab 82 92 4c ce |.B\.p.Z..G....L.| | 38 32 f6 78 2e de 33 24 24 ed ac d6 fc 67 a1 8e |82.x..3$$....g..| ssl_decrypt_record: mac ok dissect_ssl3_handshake iteration 1 type 20 offset 0 length 12 bytes, remaining 16 dissect_ssl enter frame #50 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 1050 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 954, ssl state 0x3F packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 4 offset 5 length 950 bytes, remaining 959 record: offset = 959, reported_length_remaining = 91 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 965, reported_length_remaining = 85 dissect_ssl3_record: content_type 22 Handshake decrypt_ssl3_record: app_data len 80, ssl state 0x3F packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder ssl_decrypt_record ciphertext len 80 Ciphertext[80]: | e3 9a 1e 2f c8 3e c3 20 b5 09 2e 87 68 d8 88 8b |.../.>. ....h...| | 3b d7 d1 7b 01 c9 2a ce 0f 5c 85 04 03 c8 43 e4 |;..{..*..\....C.| | a7 78 db f9 0f b3 3c c3 50 55 31 ff 05 60 35 c1 |.x....<.PU1..`5.| | a1 4c 12 0e 1c 53 ea 6f 15 09 69 ba 22 3c 1f e0 |.L...S.o..i."<..| | 7a 05 38 44 c2 b8 f1 96 ed 5a 89 51 e3 08 33 09 |z.8D.....Z.Q..3.| Plaintext[80]: | 58 49 03 a5 87 53 bf 7b fd 0d e5 5d c7 5f 35 85 |XI...S.{...]._5.| | 14 00 00 0c d2 b2 de e3 04 54 fb c7 39 85 53 d0 |.........T..9.S.| | 4f 49 77 5e 10 b2 29 be 60 5c 31 04 aa 06 a5 29 |OIw^..).`\1....)| | 61 01 5e 06 2a 2d a2 e4 97 8d 01 ba 66 50 13 5e |a.^.*-......fP.^| | 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f 0f |................| ssl_decrypt_record found padding 15 final len 64 checking mac (len 16, version 303, ct 22 seq 0) tls_check_mac mac type:SHA256 md 8 Mac[32]: | 4f 49 77 5e 10 b2 29 be 60 5c 31 04 aa 06 a5 29 |OIw^..).`\1....)| | 61 01 5e 06 2a 2d a2 e4 97 8d 01 ba 66 50 13 5e |a.^.*-......fP.^| ssl_decrypt_record: mac ok dissect_ssl3_handshake iteration 1 type 20 offset 0 length 12 bytes, remaining 16 dissect_ssl enter frame #193 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 69 dissect_ssl3_record: content_type 23 Application Data decrypt_ssl3_record: app_data len 64, ssl state 0x3F packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder ssl_decrypt_record ciphertext len 64 Ciphertext[64]: | 9c 54 f0 75 f6 28 73 48 18 7f 1e 68 42 a3 fc fb |.T.u.(sH...hB...| | c2 a5 3b 58 ed db e2 82 a1 86 b1 58 b4 48 54 83 |..;X.......X.HT.| | 8c b8 d1 8a 71 75 7a c9 25 de 66 40 91 33 d2 87 |....quz.%.f@.3..| | f0 85 c7 01 a3 da 3f f5 ef b5 27 bb a3 97 85 7a |......?...'....z| Plaintext[64]: | 0b 03 b1 a4 9d 10 0e c4 24 e0 6c b2 e2 4d 6c b8 |........$.l..Ml.| | 48 65 6c 6c 6f 20 77 6f 72 6c 64 0a a4 36 40 82 |Hello world..6@.| | b7 71 94 32 3b db 70 1c fe 4a 57 5b 0e 36 81 d1 |.q.2;.p..JW[.6..| | 1f 14 b7 ac d0 5c b5 f7 a3 1b 4e 15 03 03 03 03 |.....\....N.....| ssl_decrypt_record found padding 3 final len 60 checking mac (len 12, version 303, ct 23 seq 1) tls_check_mac mac type:SHA256 md 8 Mac[32]: | a4 36 40 82 b7 71 94 32 3b db 70 1c fe 4a 57 5b |.6@..q.2;.p..JW[| | 0e 36 81 d1 1f 14 b7 ac d0 5c b5 f7 a3 1b 4e 15 |.6.......\....N.| ssl_decrypt_record: mac ok ssl_add_data_info: new data inserted data_len = 12, seq = 0, nxtseq = 12 association_find: TCP port 33648 found (nil) association_find: TCP port 10005 found 0x6ca2fd0 dissect_ssl3_record decrypted len 12 decrypted app data fragment[12]: | 48 65 6c 6c 6f 20 77 6f 72 6c 64 0a |Hello world. | dissect_ssl3_record found association 0x6ca2fd0 dissect_ssl enter frame #193 (first time) conversation = 0x7f6679fa0098, ssl_session = 0x7f6679fa06a8 record: offset = 0, reported_length_remaining = 12 dissect_ssl enter frame #28 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1965 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 11 offset 5 length 1585 bytes, remaining 1594 record: offset = 1594, reported_length_remaining = 371 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 16 offset 1599 length 130 bytes, remaining 1733 record: offset = 1733, reported_length_remaining = 232 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 15 offset 1738 length 132 bytes, remaining 1874 record: offset = 1874, reported_length_remaining = 91 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec record: offset = 1880, reported_length_remaining = 85 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 20 offset 0 length 12 bytes, remaining 16 dissect_ssl enter frame #28 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1965 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 11 offset 5 length 1585 bytes, remaining 1594 record: offset = 1594, reported_length_remaining = 371 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 16 offset 1599 length 130 bytes, remaining 1733 record: offset = 1733, reported_length_remaining = 232 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 15 offset 1738 length 132 bytes, remaining 1874 record: offset = 1874, reported_length_remaining = 91 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec record: offset = 1880, reported_length_remaining = 85 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 20 offset 0 length 12 bytes, remaining 16 dissect_ssl enter frame #21 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1324 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 11 offset 5 length 1315 bytes, remaining 1324 dissect_ssl enter frame #21 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 113 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 13 offset 5 length 100 bytes, remaining 113 dissect_ssl3_handshake iteration 0 type 14 offset 109 length 0 bytes, remaining 113 dissect_ssl enter frame #50 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1050 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 4 offset 5 length 950 bytes, remaining 959 record: offset = 959, reported_length_remaining = 91 dissect_ssl3_record: content_type 20 Change Cipher Spec dissect_ssl3_change_cipher_spec record: offset = 965, reported_length_remaining = 85 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 20 offset 0 length 12 bytes, remaining 16 dissect_ssl enter frame #193 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 69 dissect_ssl3_record: content_type 23 Application Data association_find: TCP port 33648 found (nil) association_find: TCP port 10005 found 0x6ca2fd0 dissect_ssl3_record decrypted len 12 decrypted app data fragment[12]: | 48 65 6c 6c 6f 20 77 6f 72 6c 64 0a |Hello world. | dissect_ssl3_record found association 0x6ca2fd0 dissect_ssl enter frame #193 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 12 dissect_ssl enter frame #19 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1024 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 2 offset 5 length 54 bytes, remaining 63 record: offset = 63, reported_length_remaining = 961 need_desegmentation: offset = 63, reported_length_remaining = 961 dissect_ssl enter frame #10 (already visited) conversation = 0x7f6679fa0098, ssl_session = (nil) record: offset = 0, reported_length_remaining = 99 dissect_ssl3_record: content_type 22 Handshake dissect_ssl3_handshake iteration 1 type 1 offset 5 length 90 bytes, remaining 99