Here's some examples I've put together to show you various differences that's commonly encountered.
Microsoft IDs 65281, 35, & 5
Cisco IDs 65281 and 35
Here's heartbeat support id15 which did not translated in the debug output via openssl
A local email-appliance IDs 65281 and 15
Since the tls server extension happens before the SSL session is negotiated, these messages can easily be displayed via tshark/wireshark and by monitoring the client/server hellos.
Be advise that that various forward-proxies can change or remove various extension during the negotiation.
example in my office behind a proxy the same microsoft site now shows;
Now just the single IDs 65281 shows up.
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUOFc6uMyn5pmmQVMpz6HbbQ4s73-Qn69IwxLM3EzZZPh_ezBCbi1_l7144ZvwuT7YVDMOOR4tlvRuOP_GrxN1FMKa-Q-jm_k_Wr9SNftPiB46Qu-OlP8t5ck2-9725IXwauyVgIM8gfU/s640/Screen+Shot+2017-06-02+at+11.08.16+AM.png)
Ken Felix
NSE ( network security expert) and Route/Switching Engineer
kfelix -----a----t---- socpuppets ---dot---com
^ ^
=( @ @ )=
o
/ \
No comments:
Post a Comment