From 0522e562e82c07ed282d836727211817cf703bb1 Mon Sep 17 00:00:00 2001 From: Luca Deri Date: Sat, 7 Aug 2021 19:42:53 +0200 Subject: Added testing pcap for TLS fatal alert --- tests/pcap/tls_alert.pcap | Bin 0 -> 1152 bytes tests/result/tls_alert.pcap.out | 12 ++++++++++++ 2 files changed, 12 insertions(+) create mode 100644 tests/pcap/tls_alert.pcap create mode 100644 tests/result/tls_alert.pcap.out (limited to 'tests') diff --git a/tests/pcap/tls_alert.pcap b/tests/pcap/tls_alert.pcap new file mode 100644 index 000000000..f11d04d67 Binary files /dev/null and b/tests/pcap/tls_alert.pcap differ diff --git a/tests/result/tls_alert.pcap.out b/tests/result/tls_alert.pcap.out new file mode 100644 index 000000000..967e360f7 --- /dev/null +++ b/tests/result/tls_alert.pcap.out @@ -0,0 +1,12 @@ +Guessed flow protos: 1 + +DPI Packets (TCP): 11 (11.00 pkts/flow) + +Google 11 952 1 + +JA3 Host Stats: + IP Address # JA3C + 1 192.168.1.192 1 + + + 1 TCP 192.168.1.192:63158 <-> 192.168.1.20:443 [proto: 91.126/TLS.Google][Encrypted][cat: Web/5][6 pkts/607 bytes <-> 5 pkts/345 bytes][Goodput ratio: 33/2][0.00 sec][ALPN: h2;h2-16;h2-15;h2-14;spdy/3.1;spdy/3;http/1.1][bytes ratio: 0.275 (Upload)][IAT c2s/s2c min/avg/max/stddev: 0/0 0/0 0/0 0/0][Pkt Len c2s/s2c min/avg/max/stddev: 66/66 101/69 265/74 73/4][Risk: ** Obsolete TLS version (< 1.1) **** TLS fatal alert **][Risk Score: 60][TLSv1][Client: www.google-analytics.com][JA3C: d78489b860c8bf7838a6ff0b4d131541][Plen Bins: 50,0,0,0,0,0,50,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0] -- cgit v1.2.3