ssl_init keys string: 10.11.0.111,4433,http,/home/dirkx/xx/privkey.pem ssl_init found host entry 10.11.0.111,4433,http,/home/dirkx/xx/privkey.pem ssl_init addr '10.11.0.111' port '4433' filename '/home/dirkx/xx/privkey.pem' password(only for p12 file) '(null)' ssl_init private key file /home/dirkx/xx/privkey.pem successfully loaded association_add TCP port 4433 protocol http handle 0x2b634b40 association_find: TCP port 993 found 0x2bf83b20 ssl_association_remove removing TCP 993 - imap handle 0x2b727080 association_add TCP port 993 protocol imap handle 0x2b727080 association_find: TCP port 995 found 0x2bf83b40 ssl_association_remove removing TCP 995 - pop handle 0x2b727450 association_add TCP port 995 protocol pop handle 0x2b727450 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x2c311a48 size 564 association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE dissect_ssl server 10.11.0.111:4433 conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 151 ssl, state 0x00 association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 1 offset 5 length 147 bytes, remaining 156 dissect_ssl3_hnd_hello_common found CLIENT RANDOM -> state 0x01 dissect_ssl enter frame #6 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record found version 0x0300 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 74 ssl, state 0x11 association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 79 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0035 -> state 0x17 dissect_ssl3_hnd_srv_hello not enough data to generate key (required 0x37) dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 553 ssl, state 0x17 association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 84 length 549 bytes, remaining 637 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 4 ssl, state 0x17 association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 14 offset 642 length 0 bytes, remaining 646 dissect_ssl enter frame #8 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 132 ssl, state 0x17 association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 16 offset 5 length 128 bytes, remaining 137 dissect_ssl3_handshake found SSL_HND_CLIENT_KEY_EXCHG state 0x17 pre master encrypted[128]: 9a ac ca c8 93 a8 a7 fd 09 64 d1 04 00 8b 0d 1f be f1 67 73 82 68 11 64 6a 34 39 3a d8 d9 23 fe 88 c7 3d b7 aa 1e 62 14 d2 6f fc a9 24 a3 36 55 59 df 95 08 90 a3 8d 06 eb ec 89 75 db 3d 7f 4b 80 57 15 27 b6 a6 47 cd 2c 47 e0 ae b9 af db b8 5a 7d 66 af 7e 88 73 d6 f5 b4 be d7 72 7e c4 77 84 aa 51 73 d0 df e2 c3 04 08 a9 0e bc 80 30 96 eb d3 c6 eb de 8b 44 65 cc 20 26 cf 19 86 01 5a ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 79 bytes, decr_len 127 decrypted_unstrip_pre_master[127]: 02 a0 6e 33 17 1a 78 6e 14 1d 2b ae f2 ef db 80 ba 08 21 4f 47 e6 30 82 86 f9 c2 2a 02 d9 16 bd 91 51 75 fc 79 91 52 9e ec 77 f2 7d a5 ab e4 b9 71 e3 c9 53 39 9a 03 4a 42 97 da 95 fb 8b 48 18 fe 0c 60 50 a7 7e 9f e2 0b 40 c8 07 fb 31 00 03 00 3d 36 9c a5 4b 3d 40 6d 54 05 08 c9 a2 f9 ee 54 51 a1 ca c8 cb 92 08 39 5c 45 d3 67 3a 99 68 33 21 f6 dd d8 65 40 5b de 8e e9 4b e0 a9 4d pre master secret[48]: 03 00 3d 36 9c a5 4b 3d 40 6d 54 05 08 c9 a2 f9 ee 54 51 a1 ca c8 cb 92 08 39 5c 45 d3 67 3a 99 68 33 21 f6 dd d8 65 40 5b de 8e e9 4b e0 a9 4d ssl_generate_keyring_material:PRF(pre_master_secret) ssl3_prf: sha1_hash(1) ssl3_prf: md5_hash(1) datalen 48 ssl3_prf: sha1_hash(2) ssl3_prf: md5_hash(2) datalen 48 ssl3_prf: sha1_hash(3) ssl3_prf: md5_hash(3) datalen 48 master secret[48]: 2a c0 af e4 dd e6 8e 48 0a a0 e0 6e 1c ab 58 1d 01 af 03 21 68 81 62 81 bf cb 4c ec 2a cd 46 86 be 71 d4 6a ab 79 53 e7 4d b9 bd 6a 31 14 60 78 ssl_generate_keyring_material sess key generation ssl3_prf: sha1_hash(1) ssl3_prf: md5_hash(1) datalen 48 ssl3_prf: sha1_hash(2) ssl3_prf: md5_hash(2) datalen 48 ssl3_prf: sha1_hash(3) ssl3_prf: md5_hash(3) datalen 48 ssl3_prf: sha1_hash(4) ssl3_prf: md5_hash(4) datalen 48 ssl3_prf: sha1_hash(5) ssl3_prf: md5_hash(5) datalen 48 ssl3_prf: sha1_hash(6) ssl3_prf: md5_hash(6) datalen 48 ssl3_prf: sha1_hash(7) ssl3_prf: md5_hash(7) datalen 48 ssl3_prf: sha1_hash(8) ssl3_prf: md5_hash(8) datalen 48 ssl3_prf: sha1_hash(9) ssl3_prf: md5_hash(9) datalen 48 key expansion[136]: a5 cc d8 2f 13 fb a8 d0 13 18 07 db 75 f0 2c 64 34 d1 3d 14 11 61 8c 28 68 72 96 40 02 1c 07 4c d3 de ab b5 a0 fd df 86 22 e5 56 07 5b 86 cf 6b ec a3 ae cd 66 a4 ba 5f 45 44 d0 78 af c9 07 8f f5 c4 12 52 19 68 1d 9d 0b 00 f1 9d cd 39 7f 46 59 40 eb b8 ac bc 56 a4 c2 78 ed ff bc bf d8 44 e7 55 91 98 d6 30 a5 2f 08 8d dc 56 81 8a 22 04 43 e2 3f 51 85 91 8c 38 5b a6 dd 27 3d 8d cb f5 71 50 99 31 f9 04 76 d9 Client MAC key[20]: a5 cc d8 2f 13 fb a8 d0 13 18 07 db 75 f0 2c 64 34 d1 3d 14 Server MAC key[20]: 11 61 8c 28 68 72 96 40 02 1c 07 4c d3 de ab b5 a0 fd df 86 Client Write key[32]: 22 e5 56 07 5b 86 cf 6b ec a3 ae cd 66 a4 ba 5f 45 44 d0 78 af c9 07 8f f5 c4 12 52 19 68 1d 9d Server Write key[32]: 0b 00 f1 9d cd 39 7f 46 59 40 eb b8 ac bc 56 a4 c2 78 ed ff bc bf d8 44 e7 55 91 98 d6 30 a5 2f Client Write IV[16]: 08 8d dc 56 81 8a 22 04 43 e2 3f 51 85 91 8c 38 Server Write IV[16]: 5b a6 dd 27 3d 8d cb f5 71 50 99 31 f9 04 76 d9 ssl_generate_keyring_material ssl_create_decoder(client) ssl_create_decoder CIPHER: AES256 decoder initialized (digest len 20) ssl_generate_keyring_material ssl_create_decoder(server) ssl_create_decoder CIPHER: AES256 decoder initialized (digest len 20) ssl_generate_keyring_material: client seq 0, server seq 0 ssl_save_session stored session id[32]: 9f 3a a0 35 13 d6 fe 97 50 6c 27 75 6a 70 31 ad e5 ad f9 1b 13 a6 47 73 a6 78 72 2d 00 ae bb fa ssl_save_session stored master secret[48]: 2a c0 af e4 dd e6 8e 48 0a a0 e0 6e 1c ab 58 1d 01 af 03 21 68 81 62 81 bf cb 4c ec 2a cd 46 86 be 71 d4 6a ab 79 53 e7 4d b9 bd 6a 31 14 60 78 dissect_ssl3_handshake session keys succesfully generated dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 64 ssl, state 0x1F association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder ssl_decrypt_record ciphertext len 64 Ciphertext[64]: 23 fc 65 c6 dc 7f af e8 25 d6 fb b9 14 25 bc ec 54 b3 66 33 b4 19 10 c0 8d c3 b6 e2 59 5f cc 71 94 d7 81 af f4 1b 5d a7 ae 25 ea e3 34 10 a0 9c 53 88 cc 24 7f 00 52 ce e6 e0 2e b6 d5 5c 7f f9 ssl_decrypt_record: allocating 96 bytes for decrypt data (old len 32) Plaintext[64]: 14 00 00 24 58 cd 4c df 48 e1 ea 61 6a 6d a2 3c 57 bc 81 9e 40 c8 db 6a 7e 8d 1b 20 e0 dc 6f fe f9 34 34 0c b9 6a 72 37 94 59 c6 ce 69 62 9d e4 08 7f 76 6a a2 e2 96 9d 04 46 ba d1 03 03 03 03 ssl_decrypt_record found padding 3 final len 60 checking mac (len 40, version 300, ct 22 seq 0) ssl_decrypt_record: mac ok dissect_ssl3_handshake iteration 1 type 20 offset 0 length 36 bytes, remaining 40 dissect_ssl enter frame #10 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE ssl_change_cipher SERVER dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 64 ssl, state 0x1F association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder ssl_decrypt_record ciphertext len 64 Ciphertext[64]: 17 fe ef 82 94 8f 97 31 30 64 7e 0d e8 36 35 2e 12 15 85 be 60 8b de 1c b4 50 4e d6 04 2f 3a 81 13 bf da 2c 68 7e 22 11 4c 1f ce a8 81 c4 6c d8 bb 26 df 73 5e ad 48 0d 1d 05 d2 f7 17 c3 3a 69 Plaintext[64]: 14 00 00 24 f8 28 d6 d5 8a 1e b0 5e e7 1f eb 73 40 10 c9 1d 00 30 ef fd db 34 01 31 00 c7 63 51 b6 41 49 52 1c a5 af 1c 71 2c 02 4e f7 f3 0d 99 65 ea 36 5e 9b 2c e7 bc 86 48 08 39 13 09 6c 03 ssl_decrypt_record found padding 3 final len 60 checking mac (len 40, version 300, ct 22 seq 0) ssl_decrypt_record: mac ok dissect_ssl3_handshake iteration 1 type 20 offset 0 length 36 bytes, remaining 40 dissect_ssl enter frame #12 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 464 ssl, state 0x1F association_find: TCP port 54289 found 0x0 packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder ssl_decrypt_record ciphertext len 464 Ciphertext[464]: 3b 52 e4 15 c5 9f 02 37 09 fb ab 5f 59 2d 5c 9b 5e fb 48 07 5d 0a 36 2b 31 f2 08 4f 19 3b 5d 71 ea e6 73 7b 20 35 91 cb 48 d8 7c db c3 22 e6 8a dc 32 57 e6 5b a2 59 63 f3 cb 7e 7c 91 c1 0e 5d 12 bd f0 cf fa 18 a2 c6 c1 32 5f 6f df 42 dd 35 bf 2d 6c f3 c0 aa 06 6c aa c7 3f d6 cf b1 59 4e 77 58 8f a4 ef 83 55 69 53 06 ed a5 74 93 1b b6 89 fd 9d 21 a0 79 b0 c0 83 81 06 22 2f ee 77 53 96 e8 fa cf 74 7a bb a0 c9 48 36 5c 75 3d 34 0f 76 e8 e9 b6 39 b7 29 d4 3c 17 bf 8c ec 3b c0 60 78 60 03 fc 1f 59 9a be 32 34 be 2d 4f ff 32 7e 80 cb 36 88 ce 8e 21 d6 cd 1a 53 56 00 80 81 e0 c5 08 07 1f 02 7f b1 af d3 d2 d3 ad c6 4f 65 35 4c 87 b8 a3 b5 7b 4d 41 b4 70 05 f8 71 c5 79 b2 13 0f f2 44 45 ca 07 fa 25 c8 b9 13 5b 5c 94 a3 7a e8 51 2a cd 60 67 90 2b 93 47 fe af f3 59 98 0a bb f0 f8 9a 24 15 21 8f 13 cc 5a 54 d6 1e a4 1d 57 49 32 9d 8c 2a 0d e7 78 9a d5 f3 a2 bb 2f 71 9d be c7 77 74 65 81 7a 9a df 51 d2 f8 ee c9 5b 92 1f 4b a4 28 ae 46 35 33 2d aa e2 b1 28 26 0f e5 b9 6f fe ef 06 1d b0 b8 14 82 46 73 ae c7 45 23 4e a0 60 51 68 79 31 9a 81 44 9f a3 4e e5 82 86 60 76 36 ff 29 5f 9b 26 ee 24 bd f6 aa c7 ec 98 60 96 b4 be 55 e9 3f c4 63 1f 3e 73 8d a0 c9 aa 6f 6f c8 fd 94 8f 69 08 a9 28 4e 81 8d e7 33 93 c5 60 f0 dd 66 f3 81 11 12 df 5c ce 7c f5 4f cc 3c 7c a1 02 38 6b aa 70 4f 05 23 6e 85 32 e4 23 d6 20 ba 84 db cf 26 f6 35 ee 71 aa c9 62 d2 ff 1d 13 fc b5 d6 3a c0 1d f4 d5 28 2f 25 c5 ssl_decrypt_record: allocating 496 bytes for decrypt data (old len 96) Plaintext[464]: 47 45 54 20 2f 20 48 54 54 50 2f 31 2e 31 0d 0a 48 6f 73 74 3a 20 31 30 2e 31 31 2e 30 2e 31 31 31 3a 34 34 33 33 0d 0a 55 73 65 72 2d 41 67 65 6e 74 3a 20 4d 6f 7a 69 6c 6c 61 2f 35 2e 30 20 28 4d 61 63 69 6e 74 6f 73 68 3b 20 55 3b 20 50 50 43 20 4d 61 63 20 4f 53 20 58 20 4d 61 63 68 2d 4f 3b 20 65 6e 2d 55 53 3b 20 72 76 3a 31 2e 38 2e 31 2e 31 31 29 20 47 65 63 6b 6f 2f 32 30 30 37 31 31 32 37 20 46 69 72 65 66 6f 78 2f 32 2e 30 2e 30 2e 31 31 0d 0a 41 63 63 65 70 74 3a 20 74 65 78 74 2f 78 6d 6c 2c 61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 6d 6c 2c 61 70 70 6c 69 63 61 74 69 6f 6e 2f 78 68 74 6d 6c 2b 78 6d 6c 2c 74 65 78 74 2f 68 74 6d 6c 3b 71 3d 30 2e 39 2c 74 65 78 74 2f 70 6c 61 69 6e 3b 71 3d 30 2e 38 2c 69 6d 61 67 65 2f 70 6e 67 2c 2a 2f 2a 3b 71 3d 30 2e 35 0d 0a 41 63 63 65 70 74 2d 4c 61 6e 67 75 61 67 65 3a 20 65 6e 2d 75 73 2c 65 6e 3b 71 3d 30 2e 35 0d 0a 41 63 63 65 70 74 2d 45 6e 63 6f 64 69 6e 67 3a 20 67 7a 69 70 2c 64 65 66 6c 61 74 65 0d 0a 41 63 63 65 70 74 2d 43 68 61 72 73 65 74 3a 20 49 53 4f 2d 38 38 35 39 2d 31 2c 75 74 66 2d 38 3b 71 3d 30 2e 37 2c 2a 3b 71 3d 30 2e 37 0d 0a 4b 65 65 70 2d 41 6c 69 76 65 3a 20 33 30 30 0d 0a 43 6f 6e 6e 65 63 74 69 6f 6e 3a 20 6b 65 65 70 2d 61 6c 69 76 65 0d 0a 43 61 63 68 65 2d 43 6f 6e 74 72 6f 6c 3a 20 6d 61 78 2d 61 67 65 3d 30 0d 0a 0d 0a 62 99 d8 69 9c 6b 81 57 3e f2 c2 2d 67 67 17 b5 ce 9a 44 60 00 ssl_decrypt_record found padding 0 final len 463 checking mac (len 443, version 300, ct 23 seq 1) ssl_decrypt_record: mac ok ssl_add_data_info: new data inserted data_len = 443, seq = 0, nxtseq = 443 association_find: TCP port 54289 found 0x0 association_find: TCP port 4433 found 0x2bf1e760 dissect_ssl3_record decrypted len 443 decrypted app data fragment: GET / HTTP/1.1 Host: 10.11.0.111:4433 User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Cache-Control: max-age=0 dissect_ssl3_record found association 0x2bf1e760 dissect_ssl enter frame #14 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 32 ssl, state 0x1F association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder ssl_decrypt_record ciphertext len 32 Ciphertext[32]: da 23 4a ec 01 30 4f 8f 05 73 82 d8 02 e2 3b 8e d0 c3 0c 68 81 f9 41 6b 29 19 35 dd a6 63 cd 01 Plaintext[32]: 89 3f a5 af 75 ca e3 58 cc a5 ff 45 f8 13 f9 44 72 68 f9 09 60 8b de 1c b4 50 4e d6 04 2f 3a 0b ssl_decrypt_record found padding 11 final len 20 checking mac (len 0, version 300, ct 23 seq 1) ssl_decrypt_record: mac ok ssl_add_data_info: new data inserted data_len = 0, seq = 0, nxtseq = 0 association_find: TCP port 4433 found 0x2bf1e760 dissect_ssl enter frame #15 (first time) conversation = 0x2c311870, ssl_session = 0x2c311a48 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1904 ssl, state 0x1F association_find: TCP port 4433 found 0x2bf1e760 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder ssl_decrypt_record ciphertext len 1904 Ciphertext[1904]: 2b 94 69 95 6a 0d 9b 08 0b a6 56 2a d3 c7 43 f3 fa fa 76 9a 2c 97 6c 91 dd bf fd 13 c6 64 01 a7 47 f9 b1 8c 4b e2 a3 22 ca 7e 56 70 1b b3 9d 35 51 c5 ea d5 4c 0e ee 72 ca e9 b6 4b 9f 73 91 f9 83 f7 b7 08 e6 5a 92 77 10 c9 7d 30 c9 e9 68 ab 2b 39 1d 7d 5e 51 72 7a 9b 41 5c 45 41 6d bd 17 97 70 cd 4a ff 22 69 44 1e 74 b9 05 0b bf c8 79 6f 89 dd b8 3e 65 ed 89 ea eb 2d 7d 0a 0b 86 0b 93 75 67 b8 af da ef 7b ac 83 d6 c9 21 32 03 de 83 3c 9f bf 85 ce 65 0f 71 c2 b8 7a 82 c3 84 2f cf ce 37 c1 85 7c d7 51 bd ff 80 5a 1e c5 6b ae 0a aa f7 b8 b5 20 3e 5f da f2 2a ca e1 f0 a2 cd 81 05 54 fa 43 0f 09 56 94 6c b6 50 07 48 5b 98 83 cf cd fb 79 a2 d9 b8 5b e6 69 c6 74 f7 de 52 fc 83 fa d8 60 40 74 0d c3 c2 cd f5 ec f4 1f c9 14 1e b6 69 d0 28 18 96 37 af d3 a6 26 76 75 7b fd 82 ea 34 de c0 4b 8d 2a 89 d5 2e 92 04 cf 85 fa 95 e7 a5 6b aa f7 03 bc 54 9c 36 c5 2e a5 6c 9f c8 36 58 87 06 cc af 0a d1 b0 06 4b 6f ef 78 ca a8 72 14 54 fd 7e d0 58 e6 64 95 60 0d 14 ec 69 d9 6a b7 8e b0 bc 57 c0 50 00 b1 0d be 04 3e 85 a7 25 e7 8d a5 1b e0 29 ce 07 d0 74 b6 c7 17 72 f2 99 93 dd 5a 9e ce ec 39 9b a6 99 4b 22 10 e3 1a 11 8d 7a e3 31 8e 53 1c ea 2a e9 72 22 da 6b dc 49 06 b2 28 20 c2 a5 68 82 b3 c4 cc ff a2 84 3e c9 76 67 64 e0 a0 60 5c 99 81 35 bf 29 58 c2 73 89 4a 5d 7d 15 50 de df d3 a7 e8 5b eb 51 cc 57 b2 4d dd b6 37 f8 a4 c4 e9 41 e2 01 a4 31 bc 44 a3 88 ac e6 94 e3 3a 09 c6 97 fc 0f 94 15 c3 39 ee 53 70 95 fd 50 3c d8 b2 73 17 cf 36 69 94 77 02 7c d2 76 db f2 2b af 93 ab 7f 99 a9 f5 8c 37 ea 9f 09 b4 5c 24 98 54 1a 78 16 e5 8d 2a 97 14 85 95 03 5b 68 9f 90 c7 1c f9 36 ed d6 a0 7e 85 18 25 ec 62 92 18 16 0a 4c b9 41 3a f6 60 0f 22 6d 74 00 38 9e d7 7b 8a 41 f4 38 7f a5 93 83 25 7a 08 a8 f6 02 46 ce 97 8d 2f 8d 00 6b 3e 2f d1 27 ce 7b 4b 05 a1 88 3f 16 19 b4 80 95 df 00 d9 d7 73 e8 7c 25 9d c7 71 df 99 9a 1b db 96 f4 ad 90 c3 51 0e ae a0 b7 19 0d 87 51 fe 3f 7e 23 8d 8b 84 e0 61 11 12 5e 1c 3d 8a c3 d1 95 fa 52 e5 b9 b4 00 ea fb 15 f8 9a a5 60 7d a1 bf 2c 81 25 5b 59 d1 97 09 de 5e 44 98 fb bc 27 7f 53 40 9e 9f a1 f1 0a f9 f0 74 ed b4 6c bf 97 1b aa 2b 16 9d 9f df 49 bd a7 d0 f0 41 f0 04 1a 97 e8 2f 96 f2 ee 1f 11 dc 4b c3 da 6d 90 cd 44 b0 69 37 7d a8 03 ff 2d 41 41 1e 4d 2a b1 36 99 f6 b8 a1 80 0a b4 37 2a 03 0b 36 14 b6 7d 57 b9 24 db 13 a9 6f f2 85 c5 1a ee a9 27 72 09 bd ac 6e 78 69 e2 6f f8 42 f6 87 5f 17 8a f2 77 0a f0 51 66 3e 9d 30 58 14 04 11 0e 6e d6 b8 3d 90 96 91 21 73 e8 ac 56 74 91 72 2e 5b 33 1b 41 bb bd 42 c7 88 b0 12 37 f5 bb 43 f9 74 b2 33 33 52 a3 13 68 bb 9a 37 6b eb 1e 72 72 46 f6 7f 03 da 88 d4 27 c1 aa 31 55 80 b5 a8 e3 dc c2 50 db 6f d1 33 37 21 52 ef b5 ae 42 ba a6 a2 95 27 55 b4 e3 e5 d4 ae 63 f6 ed 81 29 43 b8 6a df 55 77 5d 7f 75 37 d1 f6 4c 61 d4 e8 8c e2 99 8c 21 f8 3d 98 47 f9 95 13 71 8f 80 a6 89 63 86 0d a0 17 79 9d 27 1b 5b e9 77 ae 06 ef 3d 19 8d 6d c8 af 03 d5 d4 a7 fb b8 15 b4 92 46 26 b9 8b 3b 1f ae b0 1f cd 6a 44 12 5b e5 fe fa 36 7d 51 27 6e 30 d1 78 ea cb 0c 86 52 16 d7 cf e6 50 78 c5 16 80 df a4 41 a5 ca dc 32 43 0f 67 d4 f6 2d 30 dd 7a 8e bd 52 b8 58 fd bc 10 03 0b 1e f4 18 42 6b 73 d5 48 0a 1f 05 3a 2f 32 24 af 25 ce b8 f9 fd 05 0f f7 e1 c1 75 7a d8 70 b2 74 77 40 1b b6 17 f7 8f 71 a1 dc ca 23 00 c4 78 ac 6e c3 60 2c 45 9c 92 22 e2 f6 ee 9a fe a5 94 f7 93 d2 ef cd 83 ce 54 13 ef a4 52 6d 26 f5 ec 7c c3 41 74 12 f0 a1 ed 8f 5f 5d 64 f1 c9 ae d9 68 90 a3 f9 c9 4d c3 7d 52 46 d3 99 ce b0 fc c2 27 17 e7 4e a1 fa 47 c2 8b 01 8c 3c 6d 11 d7 1e 18 e5 69 39 20 1f 4a b1 d9 7b 6e 4d f8 fb 4d 2c b5 b5 5c f3 ac 69 7d d5 13 90 72 a1 5a bf 2c 42 11 f5 5b e1 eb d7 86 3f f3 c8 fb 32 47 ff b6 32 f9 b1 18 b1 6a b1 8a 25 eb 13 ba c6 18 fc e8 f0 98 b1 5f 04 15 65 8f 9e 1a 59 3f f3 72 bd 18 39 5f b7 2e 90 5c e4 ad 21 21 2f 77 4c 44 34 e1 8c b1 71 4b c3 32 02 a9 7f 39 da 50 a4 58 9e c4 92 26 4b d3 43 2f 19 aa 29 78 1b f1 96 79 8d 81 e8 2a 72 86 96 18 01 a4 8c 42 1c ca 9b a9 28 2a d6 bf df 00 e9 0e 2e 10 bb da cd 00 4b a7 45 55 11 d3 96 d7 ed de 99 97 59 b9 0a b0 c7 6b b1 81 fd dc 82 44 33 65 88 b2 4b a1 13 59 a6 b7 17 93 c0 e2 58 13 d9 51 e2 66 c3 34 6c 18 c8 49 3e 77 b9 3d 31 94 2c ec 85 36 03 16 c3 42 eb 4f d5 79 8a af a5 14 1f fc 92 33 d3 67 9e 3e 6f 84 4f 30 17 26 08 74 56 fb ac 8b 6d 93 a5 1e da 7a a0 14 81 4b c7 8e 8d 6c f9 56 72 c2 9c d9 68 e7 47 76 ab e7 04 f6 2b ec 8d 35 a5 f7 9a 47 7f 7f ba dc 62 2d a8 13 40 b0 01 18 4e 5f a0 a8 b8 6f da 7a 3c 3a 8b 30 ae 07 8c e9 6c 9c 32 c5 40 dd 72 a3 d6 33 3f 4e 53 9f c2 55 90 13 48 be d1 51 13 4f 64 d1 af 71 4d 47 60 6a 9e 8a b0 6e c9 91 b5 ea f9 37 09 75 b8 ec 44 08 b3 2d 0f 53 51 90 1c d4 b1 c5 49 f8 9c 9a 84 12 e7 03 b2 74 3d e9 2a 33 9a 31 e3 c7 f2 92 96 69 70 06 85 8e 6f ad e9 e8 71 0d cb e3 53 18 8c f5 f6 02 ba 56 f5 14 89 ee f7 c6 ce 3c 7b 2e 43 de 38 1c fb e2 d2 a0 8d 54 d5 93 39 0b 36 dd e3 1b 17 c8 63 be 47 27 f5 ca 1f 40 3c 30 03 f9 a4 2b 7b 31 e2 2e f9 76 ab a4 f3 dc a6 3d cc 4a 1c 84 ee 92 de 55 13 e7 c3 73 0d a0 e2 dc 4c fb fa 04 ae 18 46 20 c4 c2 b2 e8 6e 0d b4 97 8f 6f 84 ea 80 35 0e 1b 00 4e c9 28 2e 89 1c 99 83 86 32 a5 9a 85 fa 27 fa e9 52 1a 72 96 43 38 bd e6 a1 5d a3 58 b1 62 73 e6 a8 b8 8e c3 c5 27 51 90 70 f0 47 80 14 a0 db 8b 02 ea a1 cf 7b f0 24 ff af d2 74 76 1e 7c bc e4 56 c0 7d 5c f4 a9 3d 35 3e 41 e0 c3 45 44 2f 0a ca 32 f0 b8 0a 38 26 3e c8 24 79 42 3a d1 da 9f 5d 37 37 f3 ca 6f 46 eb f8 ab 6e df 22 cb 8b 34 52 8d ad 24 63 5f 20 fe 19 03 fe 20 b9 dc 4e 9f de 9d 22 af 86 2b 45 b5 f9 5c df a1 78 f0 fe a0 a2 9b c2 04 f3 b4 e1 96 cd bb b7 fc 74 d4 82 51 b5 68 f6 13 66 d5 18 ca d3 a5 0a 6f 3a 33 04 fd 44 80 a8 96 be 47 b9 4a e2 6e 58 e5 5f f7 07 1d ba b6 24 a8 db fd 35 41 72 28 51 03 14 45 e8 d5 6e 5a 70 0e cf ea e0 79 93 11 30 2a 45 9b c2 70 68 4a 0f 38 f6 66 fd 64 f8 8b c3 a7 4c 96 55 69 bb 3a f2 5a 2c e8 07 5c 3c 20 a1 6d e6 bf ssl_decrypt_record: allocating 1936 bytes for decrypt data (old len 496) Plaintext[1904]: 48 54 54 50 2f 31 2e 30 20 32 30 30 20 6f 6b 0d 0a 43 6f 6e 74 65 6e 74 2d 74 79 70 65 3a 20 74 65 78 74 2f 68 74 6d 6c 0d 0a 0d 0a 3c 48 54 4d 4c 3e 3c 42 4f 44 59 20 42 47 43 4f 4c 4f 52 3d 22 23 66 66 66 66 66 66 22 3e 0a 3c 70 72 65 3e 0a 0a 73 5f 73 65 72 76 65 72 20 2d 77 77 77 20 2d 73 73 6c 33 20 2d 63 69 70 68 65 72 20 41 45 53 32 35 36 2d 53 48 41 20 2d 6b 65 79 20 2e 2f 70 72 69 76 6b 65 79 2e 70 65 6d 20 0a 43 69 70 68 65 72 73 20 73 75 70 70 6f 72 74 65 64 20 69 6e 20 73 5f 73 65 72 76 65 72 20 62 69 6e 61 72 79 0a 54 4c 53 76 31 2f 53 53 4c 76 33 3a 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 2d 2d 2d 0a 43 69 70 68 65 72 73 20 63 6f 6d 6d 6f 6e 20 62 65 74 77 65 65 6e 20 62 6f 74 68 20 53 53 4c 20 65 6e 64 20 70 6f 69 6e 74 73 3a 0a 45 43 44 48 45 2d 45 43 44 53 41 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 45 43 44 48 45 2d 52 53 41 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 44 48 45 2d 52 53 41 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 20 0a 44 48 45 2d 44 53 53 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 20 20 45 43 44 48 2d 52 53 41 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 20 45 43 44 48 2d 45 43 44 53 41 2d 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 0a 41 45 53 32 35 36 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 45 43 44 48 45 2d 45 43 44 53 41 2d 52 43 34 2d 53 48 41 20 20 20 20 20 20 20 20 45 43 44 48 45 2d 45 43 44 53 41 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 0a 45 43 44 48 45 2d 52 53 41 2d 52 43 34 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 45 43 44 48 45 2d 52 53 41 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 20 44 48 45 2d 52 53 41 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 20 20 0a 44 48 45 2d 44 53 53 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 20 20 20 45 43 44 48 2d 52 53 41 2d 52 43 34 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 20 45 43 44 48 2d 52 53 41 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 20 0a 45 43 44 48 2d 45 43 44 53 41 2d 52 43 34 2d 53 48 41 20 20 20 20 20 20 20 20 20 45 43 44 48 2d 45 43 44 53 41 2d 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 52 43 34 2d 4d 44 35 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 0a 52 43 34 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 41 45 53 31 32 38 2d 53 48 41 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 45 43 44 48 45 2d 45 43 44 53 41 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 0a 45 43 44 48 45 2d 52 53 41 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 20 20 20 45 44 48 2d 52 53 41 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 20 20 20 20 20 45 44 48 2d 44 53 53 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 20 20 20 20 0a 45 43 44 48 2d 52 53 41 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 20 20 20 20 45 43 44 48 2d 45 43 44 53 41 2d 44 45 53 2d 43 42 43 33 2d 53 48 41 20 20 20 20 44 45 53 2d 43 42 43 33 2d 53 48 41 0a 2d 2d 2d 0a 4e 65 77 2c 20 54 4c 53 76 31 2f 53 53 4c 76 33 2c 20 43 69 70 68 65 72 20 69 73 20 41 45 53 32 35 36 2d 53 48 41 0a 53 53 4c 2d 53 65 73 73 69 6f 6e 3a 0a 20 20 20 20 50 72 6f 74 6f 63 6f 6c 20 20 3a 20 53 53 4c 76 33 0a 20 20 20 20 43 69 70 68 65 72 20 20 20 20 3a 20 41 45 53 32 35 36 2d 53 48 41 0a 20 20 20 20 53 65 73 73 69 6f 6e 2d 49 44 3a 20 39 46 33 41 41 30 33 35 31 33 44 36 46 45 39 37 35 30 36 43 32 37 37 35 36 41 37 30 33 31 41 44 45 35 41 44 46 39 31 42 31 33 41 36 34 37 37 33 41 36 37 38 37 32 32 44 30 30 41 45 42 42 46 41 0a 20 20 20 20 53 65 73 73 69 6f 6e 2d 49 44 2d 63 74 78 3a 20 30 31 30 30 30 30 30 30 0a 20 20 20 20 4d 61 73 74 65 72 2d 4b 65 79 3a 20 32 41 43 30 41 46 45 34 44 44 45 36 38 45 34 38 30 41 41 30 45 30 36 45 31 43 41 42 35 38 31 44 30 31 41 46 30 33 32 31 36 38 38 31 36 32 38 31 42 46 43 42 34 43 45 43 32 41 43 44 34 36 38 36 42 45 37 31 44 34 36 41 41 42 37 39 35 33 45 37 34 44 42 39 42 44 36 41 33 31 31 34 36 30 37 38 0a 20 20 20 20 4b 65 79 2d 41 72 67 20 20 20 3a 20 4e 6f 6e 65 0a 20 20 20 20 53 74 61 72 74 20 54 69 6d 65 3a 20 31 32 30 38 33 37 32 34 36 32 0a 20 20 20 20 54 69 6d 65 6f 75 74 20 20 20 3a 20 37 32 30 30 20 28 73 65 63 29 0a 20 20 20 20 56 65 72 69 66 79 20 72 65 74 75 72 6e 20 63 6f 64 65 3a 20 30 20 28 6f 6b 29 0a 2d 2d 2d 0a 20 20 20 31 20 69 74 65 6d 73 20 69 6e 20 74 68 65 20 73 65 73 73 69 6f 6e 20 63 61 63 68 65 0a 20 20 20 30 20 63 6c 69 65 6e 74 20 63 6f 6e 6e 65 63 74 73 20 28 53 53 4c 5f 63 6f 6e 6e 65 63 74 28 29 29 0a 20 20 20 30 20 63 6c 69 65 6e 74 20 72 65 6e 65 67 6f 74 69 61 74 65 73 20 28 53 53 4c 5f 63 6f 6e 6e 65 63 74 28 29 29 0a 20 20 20 30 20 63 6c 69 65 6e 74 20 63 6f 6e 6e 65 63 74 73 20 74 68 61 74 20 66 69 6e 69 73 68 65 64 0a 20 20 20 31 20 73 65 72 76 65 72 20 61 63 63 65 70 74 73 20 28 53 53 4c 5f 61 63 63 65 70 74 28 29 29 0a 20 20 20 30 20 73 65 72 76 65 72 20 72 65 6e 65 67 6f 74 69 61 74 65 73 20 28 53 53 4c 5f 61 63 63 65 70 74 28 29 29 0a 20 20 20 31 20 73 65 72 76 65 72 20 61 63 63 65 70 74 73 20 74 68 61 74 20 66 69 6e 69 73 68 65 64 0a 20 20 20 30 20 73 65 73 73 69 6f 6e 20 63 61 63 68 65 20 68 69 74 73 0a 20 20 20 31 20 73 65 73 73 69 6f 6e 20 63 61 63 68 65 20 6d 69 73 73 65 73 0a 20 20 20 30 20 73 65 73 73 69 6f 6e 20 63 61 63 68 65 20 74 69 6d 65 6f 75 74 73 0a 20 20 20 30 20 63 61 6c 6c 62 61 63 6b 20 63 61 63 68 65 20 68 69 74 73 0a 20 20 20 30 20 63 61 63 68 65 20 66 75 6c 6c 20 6f 76 65 72 66 6c 6f 77 73 20 28 31 32 38 20 61 6c 6c 6f 77 65 64 29 0a 2d 2d 2d 0a 6e 6f 20 63 6c 69 65 6e 74 20 63 65 72 74 69 66 69 63 61 74 65 20 61 76 61 69 6c 61 62 6c 65 0a 3c 2f 42 4f 44 59 3e 3c 2f 48 54 4d 4c 3e 0d 0a 0d 0a 6d 68 ca 76 d2 8c ad b0 b5 37 4b ef b4 69 99 fc 87 4e 8e d4 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0f ssl_decrypt_record found padding 15 final len 1888 checking mac (len 1868, version 300, ct 23 seq 2) ssl_decrypt_record: mac ok ssl_add_data_info: new data inserted data_len = 1868, seq = 0, nxtseq = 1868 association_find: TCP port 4433 found 0x2bf1e760 dissect_ssl3_record decrypted len 1868 decrypted app data fragment: HTTP/1.0 200 ok Content-type: text/html

s_server -www -ssl3 -cipher AES256-SHA -key ./privkey.pem 
Ciphers supported in s_server binary
TLSv1/SSLv3:AES256-SHA               
---
Ciphers common between both SSL end points:
ECDHE-ECDSA-AES256-SHA     ECDHE-RSA-AES256-SHA       DHE-RSA-AES256-SHA        
DHE-DSS-AES256-SHA         ECDH-RSA-AES256-SHA        ECDH-ECDSA-AES256-SHA     
AES256-SHA                 ECDHE-ECDSA-RC4-SHA        ECDHE-ECDSA-AES128-SHA    
ECDHE-RSA-RC4-SHA          ECDHE-RSA-AES128-SHA       DHE-RSA-AES128-SHA        
DHE-DSS-AES128-SHA         ECDH-RSA-RC4-SHA           ECDH-RSA-AES128-SHA       
ECDH-ECDSA-RC4-SHA         ECDH-ECDSA-AES128-SHA      RC4-MD5                   
RC4-SHA                    AES128-SHA                 ECDHE-ECDSA-DES-CBC3-SHA  
ECDHE-RSA-DES-CBC3-SHA     EDH-RSA-DES-CBC3-SHA       EDH-DSS-DES-CBC3-SHA      
ECDH-RSA-DES-CBC3-SHA      ECDH-ECDSA-DES-CBC3-SHA    DES-CBC3-SHA
---
New, TLSv1/SSLv3, Cipher is AES256-SHA
SSL-Session:
    Protocol  : SSLv3
    Cipher    : AES256-SHA
    Session-ID: 9F3AA03513D6FE97506C27756A7031ADE5ADF91B13A64773A678722D00AEBBFA
    Session-ID-ctx: 01000000
    Master-Key: 2AC0AFE4DDE68E480AA0E06E1CAB581D01AF032168816281BFCB4CEC2ACD4686BE71D46AAB7953E74DB9BD6A31146078
    Key-Arg   : None
    Start Time: 1208372462
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
---
   1 items in the session cache
   0 client connects (SSL_connect())
   0 client renegotiates (SSL_connect())
   0 client connects that finished
   1 server accepts (SSL_accept())
   0 server renegotiates (SSL_accept())
   1 server accepts that finished
   0 session cache hits
   1 session cache misses
   0 session cache timeouts
   0 callback cache hits
   0 cache full overflows (128 allowed)
---
no client certificate available



dissect_ssl3_record found association 0x2bf1e760

dissect_ssl enter frame #19 (first time)
  conversation = 0x2c311870, ssl_session = 0x2c311a48
dissect_ssl3_record: content_type 21
decrypt_ssl3_record: app_data len 32 ssl, state 0x1F
association_find: TCP port 54289 found 0x0
packet_from_server: is from server - FALSE
decrypt_ssl3_record: using client decoder
ssl_decrypt_record ciphertext len 32
Ciphertext[32]:
22 46 ed e0 70 32 aa 82 a5 ad 06 ef e5 f2 57 50 
ad d3 c3 89 9b 3b 2e b7 7c 52 f4 f1 1d e8 5c 05 
Plaintext[32]:
01 00 ad bb cf 9d 49 3a 9f 3c dc c2 cd 5e ea 8e 
1b b8 74 a1 a7 4c 09 09 09 09 09 09 09 09 09 09 
ssl_decrypt_record found padding 9 final len 22
checking mac (len 2, version 300, ct 21 seq 2)
ssl_decrypt_record: mac ok