Wireshark-users: [Wireshark-users] SSL decode "can't decrypt pre master secret"
From: Clinton James <cjames@xxxxxxxxxxx>
Date: Tue, 17 Nov 2009 07:50:11 -0600
I can't seem to decrypt an exchange. Google doesn't seem to give me much either. I hoping someone can point me in the right direction. My client app is contacting the server WWW.XXX.YYY.ZZZ via https. ------ # wireshark -v wireshark 1.2.3 Copyright 1998-2009 Gerald Combs <gerald@xxxxxxxxxxxxx> and contributors. This is free software; see the source for copying conditions. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. Compiled with GTK+ 2.16.6, with GLib 2.20.5, with libpcap 1.0.0, with libz 1.2.3, with POSIX capabilities (Linux), with libpcre 7.9, without SMI, without c-ares, without ADNS, without Lua, with GnuTLS 2.8.3, with Gcrypt 1.4.4, without Kerberos, without GeoIP, without PortAudio, without AirPcap. Running on Linux 2.6.30-gentoo-r4, with libpcap version 1.0.0, GnuTLS 2.8.3, Gcrypt 1.4.4. Built using gcc 4.1.2 (Gentoo 4.1.2 p1.1). ------- ssl_init keys string: WWW.XXX.YYY.ZZZ,443,http,/tmp/test.key ssl_init found host entry WWW.XXX.YYY.ZZZ,443,http,/tmp/test.key ssl_init addr 'WWW.XXX.YYY.ZZZ' port '443' filename '/tmp/test.key' password(only for p12 file) '(null)' Private key imported: KeyID 9D:B5:CF:EB:C8:8D:AD:12:CE:92:C2:EB:10:F3:B4:69:... ssl_init private key file /tmp/test.key successfully loaded association_add TCP port 443 protocol http handle 0xccc570 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x7f602b872c00 size 648 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE dissect_ssl server WWW.XXX.YYY.ZZZ:443 conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 100 client random len: 32 padded to 32 dissect_ssl enter frame #5 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #7 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #9 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record found version 0x0301 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 3077 ssl, state 0x11 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0004 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 2317 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 pre master encrypted[128]: c7 e8 f9 92 6e 01 f5 b4 8e 88 06 a3 b4 53 2b 0f 24 29 81 eb 3c 11 3f cb 3d 9d 78 82 75 6c a9 f4 bd 1b bb da e9 e2 e8 2f 65 ac 93 fc f4 b9 36 bf aa a8 89 5c fa ac da b7 40 04 81 b0 95 45 3a a4 ec e4 87 17 79 d2 95 d7 06 25 ec c3 d5 6e bc 4d 80 6d b6 4e 8e c3 38 68 b5 f2 f3 a4 f1 da 2a 59 54 16 53 ae 49 54 4a 5a 15 fe af 60 a7 e1 c1 dd 7b 36 c5 56 1a 3a f7 93 c8 09 dd 66 f8 92 d2 4b ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 0 bytes, decr_len 128 decrypted_unstrip_pre_master[128]: b0 a3 9f d7 b0 fc 7e db fd b4 88 22 65 3f f9 b1 01 ab ed 42 16 74 b9 73 5f 41 84 cd 6a e6 28 ec c3 9c f7 3e 54 45 df 8c 8c 5a a8 9a c2 6a aa c3 9e 15 9d 32 a1 cf 5f af cf 0b 73 d1 4b bf 7c de 35 05 a8 d5 f5 71 1d e9 83 99 85 b7 4b 1a 7d 57 7f ce 54 e0 ae 93 69 36 5b a3 a3 c5 9e 82 f9 cb a9 40 38 a2 0e 99 50 4b 1a 25 86 30 37 58 5f 4e ce 7a 51 81 ff b6 d7 79 eb 8c 2c d5 5e 38 63 f8 ssl_decrypt_pre_master_secret wrong pre_master_secret length (128, expected 48) dissect_ssl3_handshake can't decrypt pre master secret dissect_ssl enter frame #13 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 134 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl enter frame #16 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 260 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1814 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 97 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #27 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #29 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 4344 need_desegmentation: offset = 0, reported_length_remaining = 4344 dissect_ssl enter frame #31 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5792 need_desegmentation: offset = 0, reported_length_remaining = 5792 dissect_ssl enter frame #33 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 7240 need_desegmentation: offset = 0, reported_length_remaining = 7240 dissect_ssl enter frame #35 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8688 need_desegmentation: offset = 0, reported_length_remaining = 8688 dissect_ssl enter frame #37 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 10034 need_desegmentation: offset = 0, reported_length_remaining = 10034 dissect_ssl enter frame #39 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11482 need_desegmentation: offset = 0, reported_length_remaining = 11482 dissect_ssl enter frame #41 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11584 need_desegmentation: offset = 0, reported_length_remaining = 11584 dissect_ssl enter frame #43 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13032 need_desegmentation: offset = 0, reported_length_remaining = 13032 dissect_ssl enter frame #45 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 14480 need_desegmentation: offset = 0, reported_length_remaining = 14480 dissect_ssl enter frame #47 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 15928 need_desegmentation: offset = 0, reported_length_remaining = 15928 dissect_ssl enter frame #49 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 16144 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 272 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #51 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2398 need_desegmentation: offset = 0, reported_length_remaining = 2398 dissect_ssl enter frame #53 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3846 need_desegmentation: offset = 0, reported_length_remaining = 3846 dissect_ssl enter frame #55 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5294 need_desegmentation: offset = 0, reported_length_remaining = 5294 dissect_ssl enter frame #57 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6742 need_desegmentation: offset = 0, reported_length_remaining = 6742 dissect_ssl enter frame #58 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8190 need_desegmentation: offset = 0, reported_length_remaining = 8190 dissect_ssl enter frame #61 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 9638 need_desegmentation: offset = 0, reported_length_remaining = 9638 dissect_ssl enter frame #63 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11086 need_desegmentation: offset = 0, reported_length_remaining = 11086 dissect_ssl enter frame #65 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 12534 need_desegmentation: offset = 0, reported_length_remaining = 12534 dissect_ssl enter frame #67 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 13263 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #19 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 100 dissect_ssl enter frame #5 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #9 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 dissect_ssl enter frame #13 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec dissect_ssl enter frame #16 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #49 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #67 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #19 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x7f602b872c00 size 648 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE dissect_ssl server WWW.XXX.YYY.ZZZ:443 conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 100 client random len: 32 padded to 32 dissect_ssl enter frame #5 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #7 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #9 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record found version 0x0301 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 3077 ssl, state 0x11 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0004 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 2317 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 pre master encrypted[128]: c7 e8 f9 92 6e 01 f5 b4 8e 88 06 a3 b4 53 2b 0f 24 29 81 eb 3c 11 3f cb 3d 9d 78 82 75 6c a9 f4 bd 1b bb da e9 e2 e8 2f 65 ac 93 fc f4 b9 36 bf aa a8 89 5c fa ac da b7 40 04 81 b0 95 45 3a a4 ec e4 87 17 79 d2 95 d7 06 25 ec c3 d5 6e bc 4d 80 6d b6 4e 8e c3 38 68 b5 f2 f3 a4 f1 da 2a 59 54 16 53 ae 49 54 4a 5a 15 fe af 60 a7 e1 c1 dd 7b 36 c5 56 1a 3a f7 93 c8 09 dd 66 f8 92 d2 4b ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 0 bytes, decr_len 128 decrypted_unstrip_pre_master[128]: b0 a3 9f d7 b0 fc 7e db fd b4 88 22 65 3f f9 b1 01 ab ed 42 16 74 b9 73 5f 41 84 cd 6a e6 28 ec c3 9c f7 3e 54 45 df 8c 8c 5a a8 9a c2 6a aa c3 9e 15 9d 32 a1 cf 5f af cf 0b 73 d1 4b bf 7c de 35 05 a8 d5 f5 71 1d e9 83 99 85 b7 4b 1a 7d 57 7f ce 54 e0 ae 93 69 36 5b a3 a3 c5 9e 82 f9 cb a9 40 38 a2 0e 99 50 4b 1a 25 86 30 37 58 5f 4e ce 7a 51 81 ff b6 d7 79 eb 8c 2c d5 5e 38 63 f8 ssl_decrypt_pre_master_secret wrong pre_master_secret length (128, expected 48) dissect_ssl3_handshake can't decrypt pre master secret dissect_ssl enter frame #13 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 134 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl enter frame #16 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 260 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1814 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 97 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #27 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #29 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 4344 need_desegmentation: offset = 0, reported_length_remaining = 4344 dissect_ssl enter frame #31 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5792 need_desegmentation: offset = 0, reported_length_remaining = 5792 dissect_ssl enter frame #33 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 7240 need_desegmentation: offset = 0, reported_length_remaining = 7240 dissect_ssl enter frame #35 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8688 need_desegmentation: offset = 0, reported_length_remaining = 8688 dissect_ssl enter frame #37 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 10034 need_desegmentation: offset = 0, reported_length_remaining = 10034 dissect_ssl enter frame #39 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11482 need_desegmentation: offset = 0, reported_length_remaining = 11482 dissect_ssl enter frame #41 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11584 need_desegmentation: offset = 0, reported_length_remaining = 11584 dissect_ssl enter frame #43 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13032 need_desegmentation: offset = 0, reported_length_remaining = 13032 dissect_ssl enter frame #45 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 14480 need_desegmentation: offset = 0, reported_length_remaining = 14480 dissect_ssl enter frame #47 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 15928 need_desegmentation: offset = 0, reported_length_remaining = 15928 dissect_ssl enter frame #49 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 16144 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 272 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #51 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2398 need_desegmentation: offset = 0, reported_length_remaining = 2398 dissect_ssl enter frame #53 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3846 need_desegmentation: offset = 0, reported_length_remaining = 3846 dissect_ssl enter frame #55 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5294 need_desegmentation: offset = 0, reported_length_remaining = 5294 dissect_ssl enter frame #57 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6742 need_desegmentation: offset = 0, reported_length_remaining = 6742 dissect_ssl enter frame #58 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8190 need_desegmentation: offset = 0, reported_length_remaining = 8190 dissect_ssl enter frame #61 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 9638 need_desegmentation: offset = 0, reported_length_remaining = 9638 dissect_ssl enter frame #63 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11086 need_desegmentation: offset = 0, reported_length_remaining = 11086 dissect_ssl enter frame #65 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 12534 need_desegmentation: offset = 0, reported_length_remaining = 12534 dissect_ssl enter frame #67 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 13263 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x7f602b872c00 size 648 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE dissect_ssl server WWW.XXX.YYY.ZZZ:443 conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 100 client random len: 32 padded to 32 dissect_ssl enter frame #5 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #7 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #9 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record found version 0x0301 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 3077 ssl, state 0x11 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0004 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 2317 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 pre master encrypted[128]: c7 e8 f9 92 6e 01 f5 b4 8e 88 06 a3 b4 53 2b 0f 24 29 81 eb 3c 11 3f cb 3d 9d 78 82 75 6c a9 f4 bd 1b bb da e9 e2 e8 2f 65 ac 93 fc f4 b9 36 bf aa a8 89 5c fa ac da b7 40 04 81 b0 95 45 3a a4 ec e4 87 17 79 d2 95 d7 06 25 ec c3 d5 6e bc 4d 80 6d b6 4e 8e c3 38 68 b5 f2 f3 a4 f1 da 2a 59 54 16 53 ae 49 54 4a 5a 15 fe af 60 a7 e1 c1 dd 7b 36 c5 56 1a 3a f7 93 c8 09 dd 66 f8 92 d2 4b ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 0 bytes, decr_len 128 decrypted_unstrip_pre_master[128]: b0 a3 9f d7 b0 fc 7e db fd b4 88 22 65 3f f9 b1 01 ab ed 42 16 74 b9 73 5f 41 84 cd 6a e6 28 ec c3 9c f7 3e 54 45 df 8c 8c 5a a8 9a c2 6a aa c3 9e 15 9d 32 a1 cf 5f af cf 0b 73 d1 4b bf 7c de 35 05 a8 d5 f5 71 1d e9 83 99 85 b7 4b 1a 7d 57 7f ce 54 e0 ae 93 69 36 5b a3 a3 c5 9e 82 f9 cb a9 40 38 a2 0e 99 50 4b 1a 25 86 30 37 58 5f 4e ce 7a 51 81 ff b6 d7 79 eb 8c 2c d5 5e 38 63 f8 ssl_decrypt_pre_master_secret wrong pre_master_secret length (128, expected 48) dissect_ssl3_handshake can't decrypt pre master secret dissect_ssl enter frame #13 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 134 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl enter frame #16 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 260 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1814 ssl, state 0x17 association_find: TCP port 38635 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 97 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #27 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #29 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 4344 need_desegmentation: offset = 0, reported_length_remaining = 4344 dissect_ssl enter frame #31 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5792 need_desegmentation: offset = 0, reported_length_remaining = 5792 dissect_ssl enter frame #33 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 7240 need_desegmentation: offset = 0, reported_length_remaining = 7240 dissect_ssl enter frame #35 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8688 need_desegmentation: offset = 0, reported_length_remaining = 8688 dissect_ssl enter frame #37 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 10034 need_desegmentation: offset = 0, reported_length_remaining = 10034 dissect_ssl enter frame #39 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11482 need_desegmentation: offset = 0, reported_length_remaining = 11482 dissect_ssl enter frame #41 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11584 need_desegmentation: offset = 0, reported_length_remaining = 11584 dissect_ssl enter frame #43 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13032 need_desegmentation: offset = 0, reported_length_remaining = 13032 dissect_ssl enter frame #45 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 14480 need_desegmentation: offset = 0, reported_length_remaining = 14480 dissect_ssl enter frame #47 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 15928 need_desegmentation: offset = 0, reported_length_remaining = 15928 dissect_ssl enter frame #49 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 16144 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 272 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #51 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2398 need_desegmentation: offset = 0, reported_length_remaining = 2398 dissect_ssl enter frame #53 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3846 need_desegmentation: offset = 0, reported_length_remaining = 3846 dissect_ssl enter frame #55 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5294 need_desegmentation: offset = 0, reported_length_remaining = 5294 dissect_ssl enter frame #57 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6742 need_desegmentation: offset = 0, reported_length_remaining = 6742 dissect_ssl enter frame #58 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8190 need_desegmentation: offset = 0, reported_length_remaining = 8190 dissect_ssl enter frame #61 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 9638 need_desegmentation: offset = 0, reported_length_remaining = 9638 dissect_ssl enter frame #63 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11086 need_desegmentation: offset = 0, reported_length_remaining = 11086 dissect_ssl enter frame #65 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 12534 need_desegmentation: offset = 0, reported_length_remaining = 12534 dissect_ssl enter frame #67 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 13263 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 100 dissect_ssl enter frame #5 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #9 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 dissect_ssl enter frame #13 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec dissect_ssl enter frame #16 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #49 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #67 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 100 dissect_ssl enter frame #5 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #9 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 dissect_ssl enter frame #13 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec dissect_ssl enter frame #16 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 23 offset 5 length 439121 bytes, remaining 37 dissect_ssl enter frame #17 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 dissect_ssl3_handshake iteration 1 type 54 offset 11 length 3877662 bytes, remaining 43 dissect_ssl enter frame #19 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #20 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #23 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #25 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #49 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 17376 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 1227 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 record: offset = 16426, reported_length_remaining = 950 need_desegmentation: offset = 16426, reported_length_remaining = 950 dissect_ssl enter frame #67 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 13268 dissect_ssl3_record: content_type 23 association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 1819 dissect_ssl3_record: content_type 23 association_find: TCP port 38635 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #14 (already visited) conversation = 0x7f602b872880, ssl_session = (nil) record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x7f602b872c00 size 648 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE dissect_ssl server WWW.XXX.YYY.ZZZ:443 conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 100 client random len: 32 padded to 32 dissect_ssl enter frame #5 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #7 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #9 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record found version 0x0301 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 3077 ssl, state 0x11 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0004 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 2317 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 pre master encrypted[128]: 19 ce f3 9b a0 8e 28 f3 cb b4 f5 5a 90 83 58 0d 58 00 52 3f dd 84 07 26 93 8c 24 df 05 d0 1c c0 3b 5d 52 be d9 c0 ab d6 75 9a 57 e7 41 cf 9b df e1 c0 04 a2 ba 87 15 c8 77 3b 18 49 d5 38 09 a2 cf 85 47 19 7d e7 63 18 1a 4b 1a 87 75 5c 7e b1 b1 39 40 ab 56 04 9b e5 d3 34 4e 89 9c 5c 9d f5 15 75 40 00 d4 2c d2 c2 88 7f 56 78 81 14 4b 2e aa 7a 9c 5d 7f c0 72 f3 81 e2 17 c3 72 92 e9 fc ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 0 bytes, decr_len 128 decrypted_unstrip_pre_master[128]: 71 f4 2f 2b 09 7e f2 85 26 d1 ad 1c 2a 12 a5 15 0b 1c 50 a5 fe a2 73 89 a7 67 24 66 f3 e1 6b 07 54 92 7d af 79 b7 56 07 fe 15 1a b1 c5 ee d4 ba 9e f7 80 fb c8 1e 17 c8 df 47 fa a7 20 03 40 99 d5 92 2b ca 5c f3 17 96 e9 a3 6b 02 db a9 d1 d8 59 60 fd 64 26 26 1b 52 28 cb c6 c1 60 f6 d7 80 6d 88 55 d4 0a 18 07 43 4a 50 83 89 02 ee 4e 7b 40 b0 9f 2e a7 9a 1f 09 75 a5 48 94 f7 47 1e 11 ssl_decrypt_pre_master_secret wrong pre_master_secret length (128, expected 48) dissect_ssl3_handshake can't decrypt pre master secret dissect_ssl enter frame #13 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 134 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl enter frame #15 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #17 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 20 offset 5 length 6249515 bytes, remaining 37 dissect_ssl enter frame #18 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 219 offset 11 length 14869954 bytes, remaining 43 dissect_ssl enter frame #20 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 260 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 46252 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #22 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1820 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1815 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 46252 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #24 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 97 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #26 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #28 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #30 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 4344 need_desegmentation: offset = 0, reported_length_remaining = 4344 dissect_ssl enter frame #32 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5792 need_desegmentation: offset = 0, reported_length_remaining = 5792 dissect_ssl enter frame #34 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 7240 need_desegmentation: offset = 0, reported_length_remaining = 7240 dissect_ssl enter frame #36 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8688 need_desegmentation: offset = 0, reported_length_remaining = 8688 dissect_ssl enter frame #38 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 10034 need_desegmentation: offset = 0, reported_length_remaining = 10034 dissect_ssl enter frame #40 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11482 need_desegmentation: offset = 0, reported_length_remaining = 11482 dissect_ssl enter frame #42 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11584 need_desegmentation: offset = 0, reported_length_remaining = 11584 dissect_ssl enter frame #44 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13032 need_desegmentation: offset = 0, reported_length_remaining = 13032 dissect_ssl enter frame #46 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 14480 need_desegmentation: offset = 0, reported_length_remaining = 14480 dissect_ssl enter frame #48 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 15928 need_desegmentation: offset = 0, reported_length_remaining = 15928 dissect_ssl enter frame #50 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 16426 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 16144 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 277 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 272 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #52 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 950 need_desegmentation: offset = 0, reported_length_remaining = 950 dissect_ssl enter frame #54 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2398 need_desegmentation: offset = 0, reported_length_remaining = 2398 dissect_ssl enter frame #56 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3846 need_desegmentation: offset = 0, reported_length_remaining = 3846 dissect_ssl enter frame #58 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5294 need_desegmentation: offset = 0, reported_length_remaining = 5294 dissect_ssl enter frame #59 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6742 need_desegmentation: offset = 0, reported_length_remaining = 6742 dissect_ssl enter frame #62 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8190 need_desegmentation: offset = 0, reported_length_remaining = 8190 dissect_ssl enter frame #64 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 9638 need_desegmentation: offset = 0, reported_length_remaining = 9638 dissect_ssl enter frame #66 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11086 need_desegmentation: offset = 0, reported_length_remaining = 11086 dissect_ssl enter frame #68 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 12534 need_desegmentation: offset = 0, reported_length_remaining = 12534 dissect_ssl enter frame #69 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13269 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 13264 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #4 (first time) ssl_session_init: initializing ptr 0x7f602b872c00 size 648 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE dissect_ssl server WWW.XXX.YYY.ZZZ:443 conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 100 client random len: 32 padded to 32 dissect_ssl enter frame #5 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #7 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #9 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3082 dissect_ssl3_record found version 0x0301 -> state 0x11 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 3077 ssl, state 0x11 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 2 offset 5 length 70 bytes, remaining 3082 dissect_ssl3_hnd_hello_common found SERVER RANDOM -> state 0x13 dissect_ssl3_hnd_srv_hello found CIPHER 0x0004 -> state 0x17 dissect_ssl3_hnd_srv_hello trying to generate keys ssl_generate_keyring_material not enough data to generate key (0x17 required 0x37 or 0x57) dissect_ssl3_hnd_srv_hello can't generate keyring material dissect_ssl3_handshake iteration 0 type 11 offset 79 length 2901 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 13 offset 2984 length 90 bytes, remaining 3082 dissect_ssl3_handshake iteration 0 type 14 offset 3078 length 0 bytes, remaining 3082 dissect_ssl enter frame #11 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #12 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2322 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 2317 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 11 offset 5 length 2179 bytes, remaining 2322 dissect_ssl3_handshake iteration 0 type 16 offset 2188 length 130 bytes, remaining 2322 pre master encrypted[128]: 19 ce f3 9b a0 8e 28 f3 cb b4 f5 5a 90 83 58 0d 58 00 52 3f dd 84 07 26 93 8c 24 df 05 d0 1c c0 3b 5d 52 be d9 c0 ab d6 75 9a 57 e7 41 cf 9b df e1 c0 04 a2 ba 87 15 c8 77 3b 18 49 d5 38 09 a2 cf 85 47 19 7d e7 63 18 1a 4b 1a 87 75 5c 7e b1 b1 39 40 ab 56 04 9b e5 d3 34 4e 89 9c 5c 9d f5 15 75 40 00 d4 2c d2 c2 88 7f 56 78 81 14 4b 2e aa 7a 9c 5d 7f c0 72 f3 81 e2 17 c3 72 92 e9 fc ssl_decrypt_pre_master_secret:RSA_private_decrypt pcry_private_decrypt: stripping 0 bytes, decr_len 128 decrypted_unstrip_pre_master[128]: 71 f4 2f 2b 09 7e f2 85 26 d1 ad 1c 2a 12 a5 15 0b 1c 50 a5 fe a2 73 89 a7 67 24 66 f3 e1 6b 07 54 92 7d af 79 b7 56 07 fe 15 1a b1 c5 ee d4 ba 9e f7 80 fb c8 1e 17 c8 df 47 fa a7 20 03 40 99 d5 92 2b ca 5c f3 17 96 e9 a3 6b 02 db a9 d1 d8 59 60 fd 64 26 26 1b 52 28 cb c6 c1 60 f6 d7 80 6d 88 55 d4 0a 18 07 43 4a 50 83 89 02 ee 4e 7b 40 b0 9f 2e a7 9a 1f 09 75 a5 48 94 f7 47 1e 11 ssl_decrypt_pre_master_secret wrong pre_master_secret length (128, expected 48) dissect_ssl3_handshake can't decrypt pre master secret dissect_ssl enter frame #13 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 139 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 134 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 15 offset 5 length 130 bytes, remaining 139 dissect_ssl enter frame #14 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE ssl_change_cipher CLIENT dissect_ssl enter frame #15 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #17 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 20 offset 5 length 6249515 bytes, remaining 37 dissect_ssl enter frame #18 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 43 dissect_ssl3_record: content_type 20 dissect_ssl3_change_cipher_spec association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE ssl_change_cipher SERVER record: offset = 6, reported_length_remaining = 37 dissect_ssl3_record: content_type 22 decrypt_ssl3_record: app_data len 32 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available dissect_ssl3_handshake iteration 1 type 219 offset 11 length 14869954 bytes, remaining 43 dissect_ssl enter frame #20 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 265 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 260 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 46252 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #21 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #22 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1820 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 1815 ssl, state 0x17 association_find: TCP port 46252 found (nil) packet_from_server: is from server - FALSE decrypt_ssl3_record: using client decoder decrypt_ssl3_record: no decoder available association_find: TCP port 46252 found (nil) association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #24 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 102 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 97 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #26 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 1448 need_desegmentation: offset = 0, reported_length_remaining = 1448 dissect_ssl enter frame #28 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2896 need_desegmentation: offset = 0, reported_length_remaining = 2896 dissect_ssl enter frame #30 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 4344 need_desegmentation: offset = 0, reported_length_remaining = 4344 dissect_ssl enter frame #32 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5792 need_desegmentation: offset = 0, reported_length_remaining = 5792 dissect_ssl enter frame #34 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 7240 need_desegmentation: offset = 0, reported_length_remaining = 7240 dissect_ssl enter frame #36 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8688 need_desegmentation: offset = 0, reported_length_remaining = 8688 dissect_ssl enter frame #38 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 10034 need_desegmentation: offset = 0, reported_length_remaining = 10034 dissect_ssl enter frame #40 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11482 need_desegmentation: offset = 0, reported_length_remaining = 11482 dissect_ssl enter frame #42 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11584 need_desegmentation: offset = 0, reported_length_remaining = 11584 dissect_ssl enter frame #44 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13032 need_desegmentation: offset = 0, reported_length_remaining = 13032 dissect_ssl enter frame #46 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 14480 need_desegmentation: offset = 0, reported_length_remaining = 14480 dissect_ssl enter frame #48 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 15928 need_desegmentation: offset = 0, reported_length_remaining = 15928 dissect_ssl enter frame #50 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 16426 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 16144 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 record: offset = 16149, reported_length_remaining = 277 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 272 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0 dissect_ssl enter frame #52 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 950 need_desegmentation: offset = 0, reported_length_remaining = 950 dissect_ssl enter frame #54 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 2398 need_desegmentation: offset = 0, reported_length_remaining = 2398 dissect_ssl enter frame #56 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 3846 need_desegmentation: offset = 0, reported_length_remaining = 3846 dissect_ssl enter frame #58 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 5294 need_desegmentation: offset = 0, reported_length_remaining = 5294 dissect_ssl enter frame #59 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 6742 need_desegmentation: offset = 0, reported_length_remaining = 6742 dissect_ssl enter frame #62 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 8190 need_desegmentation: offset = 0, reported_length_remaining = 8190 dissect_ssl enter frame #64 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 9638 need_desegmentation: offset = 0, reported_length_remaining = 9638 dissect_ssl enter frame #66 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 11086 need_desegmentation: offset = 0, reported_length_remaining = 11086 dissect_ssl enter frame #68 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 12534 need_desegmentation: offset = 0, reported_length_remaining = 12534 dissect_ssl enter frame #69 (first time) conversation = 0x7f602b872880, ssl_session = 0x7f602b872c00 record: offset = 0, reported_length_remaining = 13269 dissect_ssl3_record: content_type 23 decrypt_ssl3_record: app_data len 13264 ssl, state 0x17 association_find: TCP port 443 found 0x9737b0 packet_from_server: is from server - TRUE decrypt_ssl3_record: using server decoder decrypt_ssl3_record: no decoder available association_find: TCP port 443 found 0x9737b0
- Follow-Ups:
- Prev by Date: Re: [Wireshark-users] compile static built tshark
- Next by Date: [Wireshark-users] IP BW computation in RTP stream analysis
- Previous by thread: Re: [Wireshark-users] [Wireshark-announce] Wireshark 1.2.4 is now available
- Next by thread: Re: [Wireshark-users] SSL decode "can't decrypt pre master secret"
- Index(es):