Skip to content

快速开始 ​

30 秒看懂用法 ​

命令速查 ​

Spawn 模式(App 从头启动) ​

bash
python3 r0capture.py -U -f com.coolapk.market -v

-f 会主动启动 App,从进程一创建就注入 hook,适合抓启动时的流量。

Attach 模式(挂到已运行的 App)—— 推荐 ​

bash
python3 r0capture.py -U 酷安 -v -p out.pcap

App 名是 frida-ps -U 显示的那个名字。推荐用 Attach,从你感兴趣的时机开始抓,并保存成 pcap 供 Wireshark 分析。

参数说明 ​

参数含义示例
-UUSB 设备(真机/云手机经 adb)-U
-f / --isSpawnSpawn 模式,启动 App-f com.coolapk.market
<进程名或PID>Attach 目标(默认模式)酷安 或 12345
-p / -pcap输出 pcap 文件-p out.pcap
-v / -verbose详细输出(含 hexdump)-v
-H host:port连远程 frida-server(非标准端口/多机)-H 127.0.0.1:27042
-ssl <lib>指定 SSL 库-ssl *libssl.so*
--selftest进程内主动发 HTTPS,自检抓包链路--selftest

一次完整的实战 ​

下面是云手机上抓 F-Droid 真实流量的完整过程:

bash
# 1. 确认设备连上了
adb devices
#   192.168.1.90:5555    device

# 2. 启动 frida-server(redroid 默认 adb shell 即 root)
adb -s 192.168.1.90:5555 shell \
  "nohup /data/local/tmp/frida-server -l 0.0.0.0:27042 >/data/local/tmp/frida.log 2>&1 &"

# 3. 建端口转发(本机 -> 设备 frida-server)
adb -s 192.168.1.90:5555 forward tcp:27042 tcp:27042

# 4. 启动目标 App,拿到 PID
adb -s 192.168.1.90:5555 shell "am start -n org.fdroid.fdroid/.views.main.MainActivity"
sleep 8
adb -s 192.168.1.90:5555 shell "pidof org.fdroid.fdroid"   # 假设得到 7033

# 5. attach 抓包
python3 r0capture.py -H 127.0.0.1:27042 7033 -p fdroid.pcap

# 6. 抓包运行中,另开终端用 adb input 触发 App 刷新(产生流量)
adb -s 192.168.1.90:5555 shell input swipe 360 500 360 1300 300
#   Ctrl+C 停止抓包

# 7. 用 Wireshark/tcpdump 分析
tcpdump -r fdroid.pcap -n | head

selftest:一键自检 ​

不确定环境对不对?用 --selftest,它会在目标进程内主动发一个 HTTPS 请求,验证整个抓包链路是否通畅:

bash
python3 r0capture.py -H 127.0.0.1:27042 7033 --selftest -p selftest.pcap -v

正常会输出:

[SSL_write] 0.0.0.0:0 --> 0.0.0.0:0
GET / HTTP/1.1
User-Agent: Dalvik/2.1.0 (Linux; U; Android 13; redroid13_x86_64 ...)
Host: example.com
...

[SSL_read] 0.0.0.0:0 --> 0.0.0.0:0
HTTP/1.1 200 OK
Date: ...
Content-Type: text/html
...

[selftest] result={'code': 200, 'bodylen': 558}

看到 code: 200 和明文 GET/HTTP,说明链路完全正常。

下一步:环境准备 →

基于 VitePress 构建 · 教学用途