Quickpost: Trying Out JA3

I tried out JA3 (a Python program to fingerprint TLS clients) with a 1GB pcap file from my server. It was fast (less than 1 minute), but I had to add some error handling to skip packets it would crash on.

I did not identify a lot of client HELLO packets with the JSON fingerprint database: around 5%.

 

Quickpost info


Article Link: https://blog.didierstevens.com/2017/07/30/quickpost-trying-out-ja3/