1
1
mirror of https://github.com/wader/fq.git synced 2024-09-19 07:47:14 +03:00
fq/format/tls/testdata/dump-broken.pcapng.keylog
Mattias Wadman 9852f56b74 tls: Add TLS 1.0, 1.1, 1.2 decode and decryption
What it can do:
- Decodes records and most standard messages and extensions.
- Decryptes records and reassemples application data stream if a keylog is provided
  and the cipher suite is supported.
- Supports most recommended and used ciphers and a bunch of older ones.

What it can't do:
- SSL v3 maybe supported, is similar to TLS 1.0, not tested.
- Decryption and renegotiation/cipher change.
- Record defragmentation not supported, seems rare over TCP.
- TLS 1.3
- SSL v2 but v2 compat header is supported.
- Some key exchange messages not decoded yet

Decryption code is heavly based on golang crypto/tls and zmap/zcrypto.

Will be base for decoding http2 and other TLS based on protocols.

Fixes #587
2023-03-05 13:52:12 +01:00

5 lines
704 B
Plaintext

CLIENT_RANDOM 5234987e84c01d8dbce8287cb4603a0e574454d7db99c81def5252554963ca78 84DD091976941973D14DA46494C8D29E72D62DFB37A1B45DBFEF1DFC860617E3E5BFB9B3C487B1E503F40A3EDA50B61D
CLIENT_RANDOM 5234987e7dc507ff052512313dc27ad815805bab380aabb14b433126f5af1e17 84DD091976941973D14DA46494C8D29E72D62DFB37A1B45DBFEF1DFC860617E3E5BFB9B3C487B1E503F40A3EDA50B61D
CLIENT_RANDOM 5234987e665b9d04734ad8186aa44e3d7f020c59d2f51f0b631e568886a405f7 50868CC4AA15F98824298AB6F3DDEA9686FB9A1630133E2C2473C0D093B603D0A43DFE7CBE483106DEC01E2DE1C83EAB
CLIENT_RANDOM 5234987ec57e1828a2975347e799ba2ae60085ff08ef7c86fcf257482217b584 50868CC4AA15F98824298AB6F3DDEA9686FB9A1630133E2C2473C0D093B603D0A43DFE7CBE483106DEC01E2DE1C83EAB