You are not logged in.
hi,
I used to upload commands output, as recommended here, to 0x0.st, and paste the url it returns in topic
I don't do it very often
but today, the url doesn't appear
and `curl` refuses to use https://0x0.st
is it something with 0x0, or with curl, or with me ?! ![]()
Last edited by sukolyn (2026-06-29 20:55:35)
Offline
curl -s -H "Accept: application/json, */*" --upload-file - 'https://paste.c-net.org/'0x0.st succumbed to AI abuse - for now ![]()
Offline
thank you.
Offline
it's the same with https://paste.c-net.org ![]()
no url, and curl complains about no alternative
curl: (60) SSL: no alternative certificate subject name matches target hostname 'paste.c-net.org'
Offline
Oh, that's a completely different problem and not related to any pastebin service, does "curl -4 …" work?
openssl s_client paste.c-net.org:443Offline
no -4 doesn't help.
$ openssl s_client paste.c-net.org:443
Connecting to 2a02:8400::5757:444e:0
CONNECTED(00000004)
depth=0 CN=localhost
verify error:num=18:self-signed certificate
verify return:1
depth=0 CN=localhost
verify return:1
---
Certificate chain
0 s:CN=localhost
i:CN=localhost
a:PKEY: RSA, 2048 (bit); sigalg: sha256WithRSAEncryption
v:NotBefore: Mar 17 13:23:26 2026 GMT; NotAfter: Mar 14 13:23:26 2036 GMT
---
Server certificate
-----BEGIN CERTIFICATE-----
MIIDODCCAiCgAwIBAgIUFIxEKchFOjM75QOHJajsBTNd2r0wDQYJKoZIhvcNAQEL
BQAwFDESMBAGA1UEAwwJbG9jYWxob3N0MB4XDTI2MDMxNzEzMjMyNloXDTM2MDMx
NDEzMjMyNlowFDESMBAGA1UEAwwJbG9jYWxob3N0MIIBIjANBgkqhkiG9w0BAQEF
AAOCAQ8AMIIBCgKCAQEAynP83VeUwPTAhqSrB5xNCSapT2vxgyM9bc2B0uBvevcL
1ztKQP9Hb8EGWEJtJDEEpsFJZPVzJqyQWFw11vENDWcSUaHLRXJGR8bfkBjMTEPE
x09sklqDCDkKDmJ9Tz9Q4iH+bb2xQoZ6+xf7ugeNlaM/xYFeB4fs7AM5Oswc/gEK
LXRFG6xXnIxDFSiK5GdWhanCuWlMt+ujW5cqpVfvBk0RU91w0hGasNi4PkIAqZxB
dytawXEclamxaKnz1drT851aqLvOWGR5lybkei8j8D0hU4aWdyllQM8EQcU+GMjN
KuAPCSN6XcGCW0GowH+Mi4CpeOuE6oKHfuFzJupLeQIDAQABo4GBMH8wHQYDVR0O
BBYEFPIRcAhk8jYPEkY82sgUUTXiMKuOMB8GA1UdIwQYMBaAFPIRcAhk8jYPEkY8
2sgUUTXiMKuOMA8GA1UdEwEB/wQFMAMBAf8wLAYDVR0RBCUwI4IJbG9jYWxob3N0
hwR/AAABhxAAAAAAAAAAAAAAAAAAAAABMA0GCSqGSIb3DQEBCwUAA4IBAQCl6o14
uR9hU6CCuQVzX7GAltVJjobs+FzSlp6um0IMVHViBuVzDeoQIuK/e3He1oEoyKRP
6FIt2RyMIV5D45temyt8TGtQf95D/Ligk+AP673b0JFcAfywRGhhsNCjthX8O22K
lPpbJajkC+sWUfPjoniayss1BCc5eUsKvsvVSKFfUbqTnsR+d5JBhv/Yi/lCzVn4
bcxRxnhTYORFE93Eg5Vc05IdGCc2/PofYPfy9ul+1oNuF24CeUGDS2cV1gCPFowF
J9vWIahEdxddcCgsE3eTyXlZ49IMlPH31/02LqGUOr+yWyVFC0ZfjQGfp2SwuoXM
EHsTiCn3CAPK8PI0
-----END CERTIFICATE-----
subject=CN=localhost
issuer=CN=localhost
---
No client certificate CA names sent
Peer signing digest: SHA256
Peer signature type: rsa_pss_rsae_sha256
Negotiated TLS1.3 group: X25519MLKEM768
---
SSL handshake has read 2460 bytes and written 1621 bytes
Verification error: self-signed certificate
---
New, TLSv1.3, Cipher is TLS_CHACHA20_POLY1305_SHA256
Protocol: TLSv1.3
Server public key is 2048 bit
This TLS version forbids renegotiation.
Compression: NONE
Expansion: NONE
No ALPN negotiated
Early data was not sent
Verify return code: 18 (self-signed certificate)
---
---
Post-Handshake New Session Ticket arrived:
SSL-Session:
Protocol : TLSv1.3
Cipher : TLS_CHACHA20_POLY1305_SHA256
Session-ID: 6FC3B5CBA2027303FB23A84092BB5A2A588EE9FDAAE88A0D82F64F128AF88371
Session-ID-ctx:
Resumption PSK: C35D7AF61258BA1B203FF525878B96B1D6D3A2A0009C4C8BC5F613336109F539
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 604800 (seconds)
TLS session ticket:
0000 - b4 67 8f ae 6d c3 ff cc-1c ae ba e2 28 dc e4 91 .g..m.......(...
0010 - 48 23 ba b0 f5 33 89 98-8f d9 37 fa 12 d8 91 fd H#...3....7.....
0020 - 3b 92 62 bf 48 b4 23 4e-b1 be 73 b7 7e a8 ec f5 ;.b.H.#N..s.~...
0030 - 50 77 28 c1 e1 49 5c d3-b4 74 a9 e3 65 e3 09 70 Pw(..I\..t..e..p
0040 - 09 1f 8a 16 e7 8c c9 8e-e8 4b ad a2 d8 1c d7 fd .........K......
0050 - 09 53 cc 8e 6b 76 f8 a4-e1 fa 7e 16 1c cf 3f 3f .S..kv....~...??
0060 - 15 33 2a 7f b6 2e 30 a8-66 .3*...0.f
Start Time: 1782769232
Timeout : 7200 (sec)
Verify return code: 18 (self-signed certificate)
Extended master secret: no
Max Early Data: 0
---
read R BLOCK
closed
$ Last edited by sukolyn (2026-06-29 21:44:50)
Offline
you have some local ssl terminator running - local proxy / vpn?
Offline
nope.
Offline
Connecting to 2a02:8400::5757:444e:0
That belongs to https://en.wikipedia.org/wiki/SFR but c-net is hosted on MS azure, the problem is your resolver
dig -ta paste.c-net.org
dig -taaaa paste.c-net.org
dig -ta @8.8.8.8 paste.c-net.org
resolvectl statusOffline
$ dig -ta paste.c-net.org
; <<>> DiG 9.20.24 <<>> -ta paste.c-net.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25392
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;paste.c-net.org. IN A
;; ANSWER SECTION:
paste.c-net.org. 300 IN A 109.0.66.29
;; Query time: 3 msec
;; SERVER: 192.168.1.1#53(192.168.1.1) (UDP)
;; WHEN: Tue Jun 30 01:38:11 CEST 2026
;; MSG SIZE rcvd: 60$ dig -taaaa paste.c-net.org
; <<>> DiG 9.20.24 <<>> -taaaa paste.c-net.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 46274
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;paste.c-net.org. IN AAAA
;; ANSWER SECTION:
paste.c-net.org. 300 IN AAAA 2a02:8400::5757:444e:0
;; Query time: 4 msec
;; SERVER: 192.168.1.1#53(192.168.1.1) (UDP)
;; WHEN: Tue Jun 30 01:38:27 CEST 2026
;; MSG SIZE rcvd: 72$ dig -ta @8.8.8.8 paste.c-net.org
; <<>> DiG 9.20.24 <<>> -ta @8.8.8.8 paste.c-net.org
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 25317
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;paste.c-net.org. IN A
;; ANSWER SECTION:
paste.c-net.org. 600 IN A 20.100.184.134
;; Query time: 17 msec
;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
;; WHEN: Tue Jun 30 01:38:41 CEST 2026
;; MSG SIZE rcvd: 60$ LC_ALL=C resolvectl status
Failed to connect to service /run/systemd/resolve/io.systemd.Resolve: No such file or directory
$$ cat /etc/resolv.conf
# Resolver configuration file.
# See resolv.conf(5) for details.
nameserver 192.168.1.1nameserver's address is SFR homebox.
Last edited by sukolyn (2026-06-29 23:51:56)
Offline
The IPv4 is also resolved to some SFR IP, check your router config - if that looks fine check back w/ your ISP and change the resolver to eg. 8.8.8.8, 1.1.1.1 or 9.9.9.9 (google, cloudflare and quad9)
Offline
indeed, SFR considers paste.c-net.org is a malware and blocks its access.
they activated an antiphishing protection, I need to contact them to deactivate it (they're worse each time they make a change).
thank you.
Offline
in such case i recommend setup local recursive resolver - the wiki has a good page about it
Offline
knot resolver, unbound, any other...
what's the most efficient AND simple ?
Offline
Just switching to some non-idiotic DNS (and in doubt use a locally caching stub like dnsmasq, stubby or resolved) would do?
Offline