快速开始
30 秒看懂用法
命令速查
Spawn 模式(App 从头启动)
bash
python3 r0capture.py -U -f com.coolapk.market -v-f 会主动启动 App,从进程一创建就注入 hook,适合抓启动时的流量。
Attach 模式(挂到已运行的 App)—— 推荐
bash
python3 r0capture.py -U 酷安 -v -p out.pcapApp 名是 frida-ps -U 显示的那个名字。推荐用 Attach,从你感兴趣的时机开始抓,并保存成 pcap 供 Wireshark 分析。
参数说明
| 参数 | 含义 | 示例 |
|---|---|---|
-U | USB 设备(真机/云手机经 adb) | -U |
-f / --isSpawn | Spawn 模式,启动 App | -f com.coolapk.market |
<进程名或PID> | Attach 目标(默认模式) | 酷安 或 12345 |
-p / -pcap | 输出 pcap 文件 | -p out.pcap |
-v / -verbose | 详细输出(含 hexdump) | -v |
-H host:port | 连远程 frida-server(非标准端口/多机) | -H 127.0.0.1:27042 |
-ssl <lib> | 指定 SSL 库 | -ssl *libssl.so* |
--selftest | 进程内主动发 HTTPS,自检抓包链路 | --selftest |
一次完整的实战
下面是云手机上抓 F-Droid 真实流量的完整过程:
bash
# 1. 确认设备连上了
adb devices
# 192.168.1.90:5555 device
# 2. 启动 frida-server(redroid 默认 adb shell 即 root)
adb -s 192.168.1.90:5555 shell \
"nohup /data/local/tmp/frida-server -l 0.0.0.0:27042 >/data/local/tmp/frida.log 2>&1 &"
# 3. 建端口转发(本机 -> 设备 frida-server)
adb -s 192.168.1.90:5555 forward tcp:27042 tcp:27042
# 4. 启动目标 App,拿到 PID
adb -s 192.168.1.90:5555 shell "am start -n org.fdroid.fdroid/.views.main.MainActivity"
sleep 8
adb -s 192.168.1.90:5555 shell "pidof org.fdroid.fdroid" # 假设得到 7033
# 5. attach 抓包
python3 r0capture.py -H 127.0.0.1:27042 7033 -p fdroid.pcap
# 6. 抓包运行中,另开终端用 adb input 触发 App 刷新(产生流量)
adb -s 192.168.1.90:5555 shell input swipe 360 500 360 1300 300
# Ctrl+C 停止抓包
# 7. 用 Wireshark/tcpdump 分析
tcpdump -r fdroid.pcap -n | headselftest:一键自检
不确定环境对不对?用 --selftest,它会在目标进程内主动发一个 HTTPS 请求,验证整个抓包链路是否通畅:
bash
python3 r0capture.py -H 127.0.0.1:27042 7033 --selftest -p selftest.pcap -v正常会输出:
[SSL_write] 0.0.0.0:0 --> 0.0.0.0:0
GET / HTTP/1.1
User-Agent: Dalvik/2.1.0 (Linux; U; Android 13; redroid13_x86_64 ...)
Host: example.com
...
[SSL_read] 0.0.0.0:0 --> 0.0.0.0:0
HTTP/1.1 200 OK
Date: ...
Content-Type: text/html
...
[selftest] result={'code': 200, 'bodylen': 558}看到 code: 200 和明文 GET/HTTP,说明链路完全正常。
下一步:环境准备 →