Comments (6)
@pirarucu I can confirm the behaviour - I can replicate it on my side.
Is this preventing you from decrypting a session though? I am still able to decrypt with only "RSA Session-ID" available.
from extract-tls-secrets.
@neykov Thank you for confirming. It doesn't block the decryption. I just have a program to do some tracking with CLIENT_RANDOM keys. I worked around by this change.
pirarucu@693607c
from extract-tls-secrets.
Thanks @pirarucu. Let me look into the changes to understand them better. Thanks for sharing.
from extract-tls-secrets.
@pirarucu I've pushed a change to master that should address the problem. Do you mind checking it out?
I'll push out a new release if it works for you.
from extract-tls-secrets.
Thanks @neykov. I'd love to check it out! I will get back to you later.
from extract-tls-secrets.
@neykov, I've tried the fix and it worked as expected. Many thanks for the help.
And after this change, it'd get multiple CLIENT_RANDOM keys with the same Master-Key when renegotiation happens. FYI.
RSA Session-ID: xxx Master-Key: yyy
CLIENT_RANDOM aaa yyy
CLIENT_RANDOM bbb yyy
CLIENT_RANDOM ccc yyy
from extract-tls-secrets.
Related Issues (18)
- Doesn't Work with Tomcat 9 (Tested with Tomcat 9.0.12) HOT 3
- Attaching to IBM java HOT 1
- How to deattach? HOT 1
- Cannot attach to the process HOT 4
- can't see the TLS response of request HOT 3
- No secrets log being generated (but appears to be attaching) HOT 7
- Error: Could not find or load main class name.neykov.secrets.AgentAttach HOT 12
- EXPORTER_SECRET not work HOT 10
- No BCJSSE support? HOT 1
- Attaching to running process with missing tools.jar HOT 4
- Unable to log down information HOT 2
- Failed to attach to java process xxxx. Cause: Unable to open socket file: target process not responding or HotSpot VM not loaded HOT 4
- Cannot decrypt TLS 1.2 with TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 cipher suite selected HOT 6
- No output file HOT 1
- Provider WindowsAttachProvider could not be instantiated HOT 1
- Published 4.0.0 package is not installable on Linux
- attach problem HOT 3
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from extract-tls-secrets.