Example 141 Using Telnet to Access a Server on TCP Port 443 HTTPS

4 $ telnet 10.16.17.223 443

Trying 10.16.17.223...

Connected to 10.16.17.223.

Escape character is '*■]'.

GET / HTTP/1.0

<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN">

<html><head>

<title>400 Bad Request</title>

</head><body>

<h1>Bad Request</h1>

<p>Your browser sent a request that this server could not understand.<br />

Reason: You're speaking plain HTTP to an SSL-enabled server port.

<br / >

Instead use the HTTPS scheme to access this URL, please.<br />

<blockquote>Hint: <a href="https://www.innocentvictimcompany.com/

"><b>https://

www.innocentvictimcompany.com/</b></a></blockquote></p>

<hr>

<address>Apache/2.0.52 (Unix) mod ssl/2.0.52 OpenSSL/0.9.7d DAV/2

PHP/4.3.9

Server at

www.innocentvictimcompany.com Port 443</address>

</body></html>

Connection to 10.16.17.223 closed by foreign host.

A simple connection is clearly not understood by the server. To get around this, the attacker uses OpenSSL, as shown in Example 14-2.

Continue reading here: Overview of IDS

Was this article helpful?

0 0