<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=SSLDUMP_-_Examples</id>
	<title>SSLDUMP - Examples - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=SSLDUMP_-_Examples"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=SSLDUMP_-_Examples&amp;action=history"/>
	<updated>2026-05-02T18:33:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=SSLDUMP_-_Examples&amp;diff=1071&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=SSLDUMP_-_Examples&amp;diff=1071&amp;oldid=prev"/>
		<updated>2026-01-17T09:06:39Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 09:06, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Basic Usage ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== Basic Usage ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=SSLDUMP_-_Examples&amp;diff=491&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == Basic Usage ==  The basic syntax of the `ssldump` command is as follows:   &lt;nowiki&gt; ssldump [options] [host] [port]&lt;/nowiki&gt;  Here: * `host` specifies the target host. * `port` specifies the target port (default is 443 for HTTPS).  == Commonly Used Options ==  * `-i &lt;interface&gt;`: Specifies the network interface to capture packets from (e.g., `eth0`, `wlan0`). * `-A`: Print all available SSL/TLS protocol messages. * `-d`: Enable the display of decode...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=SSLDUMP_-_Examples&amp;diff=491&amp;oldid=prev"/>
		<updated>2025-12-14T07:34:10Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == Basic Usage ==  The basic syntax of the `ssldump` command is as follows:   &amp;lt;nowiki&amp;gt; ssldump [options] [host] [port]&amp;lt;/nowiki&amp;gt;  Here: * `host` specifies the target host. * `port` specifies the target port (default is 443 for HTTPS).  == Commonly Used Options ==  * `-i &amp;lt;interface&amp;gt;`: Specifies the network interface to capture packets from (e.g., `eth0`, `wlan0`). * `-A`: Print all available SSL/TLS protocol messages. * `-d`: Enable the display of decode...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== Basic Usage ==&lt;br /&gt;
&lt;br /&gt;
The basic syntax of the `ssldump` command is as follows:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump [options] [host] [port]&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Here:&lt;br /&gt;
* `host` specifies the target host.&lt;br /&gt;
* `port` specifies the target port (default is 443 for HTTPS).&lt;br /&gt;
&lt;br /&gt;
== Commonly Used Options ==&lt;br /&gt;
&lt;br /&gt;
* `-i &amp;lt;interface&amp;gt;`: Specifies the network interface to capture packets from (e.g., `eth0`, `wlan0`).&lt;br /&gt;
* `-A`: Print all available SSL/TLS protocol messages.&lt;br /&gt;
* `-d`: Enable the display of decoded packets.&lt;br /&gt;
* `-r &amp;lt;file&amp;gt;`: Read traffic from a file instead of live capture.&lt;br /&gt;
* `-v`: Increase verbosity, providing more details about the handshake and packet exchanges.&lt;br /&gt;
&lt;br /&gt;
== Example: Capture and Decode SSL Traffic ==&lt;br /&gt;
&lt;br /&gt;
To capture and decode SSL traffic on the default HTTPS port (443) for a specific host, you can use the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A host example.com&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command captures packets on the `eth0` interface, decodes SSL traffic, and displays all available protocol messages exchanged between the client and server for the host `example.com`.&lt;br /&gt;
&lt;br /&gt;
== Example: Reading from a Packet Capture File ==&lt;br /&gt;
&lt;br /&gt;
You can also read SSL/TLS traffic from a previously captured pcap file (e.g., using `tcpdump` or Wireshark) and analyze it using `ssldump`. The following command reads from the file `capture.pcap`:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -r capture.pcap -A&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command processes the capture file `capture.pcap` and displays the SSL/TLS protocol messages.&lt;br /&gt;
&lt;br /&gt;
== Example: Filter SSL Traffic by Host and Port ==&lt;br /&gt;
&lt;br /&gt;
To filter the SSL/TLS traffic by a specific host and port, you can use the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A host example.com and port 443&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command captures SSL/TLS traffic between the host `example.com` and port `443`.&lt;br /&gt;
&lt;br /&gt;
== Example: Displaying Detailed SSL Handshake ==&lt;br /&gt;
&lt;br /&gt;
For detailed analysis of the SSL/TLS handshake, including the cipher suites used, certificates exchanged, and session establishment, you can use the `-d` option:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -d host example.com&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This will display decoded SSL/TLS handshake messages and provide details such as certificate information, session keys, and cipher suites negotiated during the handshake.&lt;br /&gt;
&lt;br /&gt;
== Example: Increase Verbosity ==&lt;br /&gt;
&lt;br /&gt;
To increase the verbosity and show more detailed protocol information, use the `-v` option:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -v host example.com&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command provides a more verbose output of SSL/TLS packets, including details on handshakes, alerts, and encrypted payloads.&lt;br /&gt;
&lt;br /&gt;
== Example: Monitoring SSL/TLS Session with Specific Server Certificate ==&lt;br /&gt;
&lt;br /&gt;
To filter SSL/TLS sessions by a specific server certificate, you can use the `-c` option, which filters traffic by the certificate&amp;#039;s Common Name (CN):&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A -c &amp;quot;example.com&amp;quot;&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command captures and decrypts SSL/TLS traffic involving a server whose certificate has the CN `example.com`.&lt;br /&gt;
&lt;br /&gt;
== Example: Saving Output to a File ==&lt;br /&gt;
&lt;br /&gt;
To save the output of the `ssldump` command to a file, you can redirect the output using `&amp;gt;`:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A host example.com &amp;gt; output.txt&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command will capture SSL/TLS traffic for `example.com` and save the decoded messages to the file `output.txt`.&lt;br /&gt;
&lt;br /&gt;
== Example: SSL Debugging for Specific Protocol Versions ==&lt;br /&gt;
&lt;br /&gt;
You can also filter SSL/TLS sessions by specifying the SSL/TLS version you are interested in. To focus on a specific version (e.g., TLSv1.2), use the `-v` flag along with the desired version:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A -v TLSv1.2 host example.com&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command will capture SSL/TLS traffic only for sessions using TLSv1.2.&lt;br /&gt;
&lt;br /&gt;
== Example: Detailed SSL/TLS Alert Messages ==&lt;br /&gt;
&lt;br /&gt;
To specifically display SSL/TLS alert messages, use the `-a` option to focus on alerts:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
ssldump -i eth0 -A -a host example.com&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command filters out everything except SSL/TLS alert messages, providing detailed insights into any alerts or errors during the SSL/TLS session.&lt;br /&gt;
&lt;br /&gt;
== Additional Notes ==&lt;br /&gt;
&lt;br /&gt;
* SSldump relies on raw packet capture to decrypt and interpret SSL/TLS traffic. This means that you need to capture traffic at a point where the SSL/TLS handshake occurs.&lt;br /&gt;
* `ssldump` requires root or superuser privileges to capture packets on network interfaces (e.g., using `sudo`).&lt;br /&gt;
* While `ssldump` can decrypt SSL/TLS sessions, it cannot decrypt traffic that uses perfect forward secrecy (PFS) unless you have access to the private key or session keys.&lt;br /&gt;
* The tool supports several SSL/TLS versions, including SSLv2, SSLv3, and TLSv1.x, but its ability to decode these protocols depends on the version of `ssldump` and its compatibility with the protocols being used.&lt;br /&gt;
&lt;br /&gt;
== Troubleshooting ==&lt;br /&gt;
&lt;br /&gt;
* If `ssldump` fails to capture or decode traffic, ensure that the correct network interface is specified using the `-i` option.&lt;br /&gt;
* Ensure that SSL/TLS handshakes are visible in the captured traffic; if the traffic is encrypted with Perfect Forward Secrecy (PFS), SSL/TLS session keys or certificates may be required for decryption.&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>