Skip to content

jabber: realistic XMPP stream negotiation and direct TLS - #200

Merged
glaslos merged 1 commit into
mainfrom
worktree-jabber-xmpp
Oct 6, 2026
Merged

glaslos merged 1 commit into
mainfrom
worktree-jabber-xmpp

Conversation

@glaslos

@glaslos glaslos commented Oct 5, 2026

Copy link
Copy Markdown
Member

Replace the fixed Test_VPN banner, which identified sensors on Shodan, with client-speaks-first XMPP behaviour:

  • canonical handler shape: jabberServer with read()/write() frames, one deferred ProduceTCP, per-iteration timeouts, 32-frame / 4 KiB caps with truncated
  • stanza framing via xml.Decoder (stream headers without newlines), server stream header + features (STARTTLS, SASL PLAIN, iq-auth)
  • SASL PLAIN and jabber:iq:auth credentials recorded, auth always fails
  • direct TLS when the first byte is 0x16 (tcp/5223) and STARTTLS, with ClientHello bytes and SNI recorded
  • parsing/responses in protocols/tcp/jabber; self-signed cert helper shared with RDP in protocols/helpers
  • tests and docs/logging.md

Replace the fixed <servers>Test_VPN</servers> banner, which identified
sensors on Shodan, with client-speaks-first XMPP behaviour:

- canonical handler shape: jabberServer with read()/write() frames, one
  deferred ProduceTCP, per-iteration timeouts, 32-frame / 4 KiB caps
  with truncated
- stanza framing via xml.Decoder (stream headers without newlines),
  server stream header + features (STARTTLS, SASL PLAIN, iq-auth)
- SASL PLAIN and jabber:iq:auth credentials recorded, auth always fails
- direct TLS when the first byte is 0x16 (tcp/5223) and STARTTLS, with
  ClientHello bytes and SNI recorded
- parsing/responses in protocols/tcp/jabber; self-signed cert helper
  shared with RDP in protocols/helpers
- tests and docs/logging.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@glaslos
glaslos merged commit d7bc75b into main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant