1 DNS: a question and an answer
Before a client connects to www.example.org it asks a resolver for the address, usually over UDP port
53. Query and answer share a 2-byte transaction ID. Names are stored as labels: a length byte, then
that many characters, ending with a zero byte. www.example.org becomes
03 77 77 77 07 65 78 61 6D 70 6C 65 03 6F 72 67 00.
The answer repeats the question and adds a resource record. Its name is just C0 0C: a
compression pointer (top two bits set) to offset 12 of the DNS message, where the question's name starts.
The record also carries a TTL: how long caches may keep it.
2 HTTP: plain text on the wire
Unencrypted HTTP is readable line by line: a request line (method, path, version), headers, an empty line, an
optional body. The Host header names the site; User-Agent names the client software, which
helps to tell a browser from a script or an update service.
Plain HTTP is rare for websites today, but common for update checks, telemetry, internal devices, printers and old applications. Whatever travels in plain HTTP (query strings, cookies, form fields) is visible to every capture point and in every proxy log.
3 Through a proxy
In companies, browsers often talk to an explicit proxy instead of the server. The request line then changes:
For HTTPS the proxy sees only the host and port in the CONNECT line, then relays encrypted bytes.
Unless it does TLS inspection (decrypting with a company certificate), its log has no path, no file name, no
content, only the volume in each direction and the duration. Many companies exclude categories such as banking, health
or personal webmail from inspection for privacy reasons; the proxy configuration tells you which.
Proxy logs usually write one line per request when it ends. A tunnel that stayed open for 20 minutes appears at its end time, with the duration in a separate field. Subtract it to get the start.
4 TLS: what encryption leaves visible
A TLS connection starts with a ClientHello in clear text. It contains the SNI (server name
indication: the host name the client wants), the protocols it can speak inside (ALPN: h2,
http/1.1), and long lists of cipher suites and extensions that differ between browsers, libraries and
tools.
The JA3 fingerprint is an MD5 hash over the ClientHello's version, cipher suites, extensions, groups and point formats. The same software produces the same JA3, so it can link connections made by the same client program, or show that "the browser" was in fact a script. It does not identify a person. (JA4 is a newer, more robust variant.)
| Visible without decryption | Hidden |
|---|---|
| Client and server addresses and ports; start, end, duration | URL path and query, headers, cookies |
| SNI host name (unless Encrypted Client Hello is used) | Request and response bodies, file names |
| ClientHello fingerprint (JA3/JA4), ALPN | In TLS 1.3: the server certificate |
| Record sizes and timing: uploads vs downloads, bursts | Which of several sites on the same server was used, if SNI is absent |
Direction and volume tell a lot: a session where the client sends hundreds of megabytes and receives a few kilobytes is an upload, whatever the content. Watch out for DNS over HTTPS (lookups hidden inside HTTPS), QUIC (HTTP/3 over UDP 443) and Encrypted Client Hello, which remove some of these traces.
5 Try it yourself
Answer from the hex views above.
Which two bytes link the DNS answer to its query (the transaction ID)? Type them in file order.
The DNS message starts right after the 8-byte UDP header; the ID is its first field.
1A 2B in both packets. A resolver that gets an answer with an unknown ID throws
it away; that is part of the protection against forged answers.
For how many seconds may a cache keep the answer for www.example.org?
The TTL is the 4-byte field after type and class in the answer record.
00 00 0E 10 = 3,600 seconds, one hour. During that hour, repeat lookups by clients
of the same resolver do not reach the upstream servers, so upstream DNS logs undercount visits.
Which host name does the TLS client ask for (SNI)?
Look for the extension of type 00 00 in the ClientHello.
shop.example.net. The extension holds a list with one entry: type 0 (host name), length, and the name in ASCII. A proxy or firewall that cannot decrypt can still log this name.
A user downloads https://shop.example.net/orders/2026.pdf through an explicit proxy without TLS
inspection. What can the proxy log?
Compare the two request lines in section 3.
The browser sends CONNECT shop.example.net:443; the path travels only inside TLS. The proxy
logs host, port, user, bytes and duration. With TLS inspection enabled it could log the full URL.
These are the query name and the type/class of the DNS query. Edit them and watch the decoded query:
- Change the first length byte
03to02. Where does the decoder now split the name, and why does everything after it shift? - Reset, then change the type (
00 01) to00 1C. What is the client asking for now?