Skip to content

实战:快速开始 ​

从零到拿到第一个 pcap,全流程实操。

目标 ​

在 redroid 云手机(android-001)上,用 r0capture 抓 F-Droid 这个 App 的真实 HTTPS 流量,保存成 pcap 分析。

步骤总览 ​

① 连设备 ​

bash
adb connect 192.168.1.90:5555
adb devices
# 192.168.1.90:5555    device

② 启动 frida-server ​

bash
# redroid 默认 adb shell 即 root
adb -s 192.168.1.90:5555 shell \
  "nohup /data/local/tmp/frida-server -l 0.0.0.0:27042 >/data/local/tmp/frida.log 2>&1 &"

# 验证:要看到 root 身份的进程
adb -s 192.168.1.90:5555 shell "ps -A | grep frida-server"
# root  4506  1  ...  S  frida-server

如果不是 root

报 PermissionDeniedError 就说明 frida-server 不是 root。先 adb -s 192.168.1.90:5555 root,再重启 frida-server。

③ 建端口转发 ​

bash
adb -s 192.168.1.90:5555 forward tcp:27042 tcp:27042
# 验证
timeout 2 bash -c "echo > /dev/tcp/127.0.0.1/27042" && echo "frida 端口可连"

④ 启动 App 拿 PID ​

bash
# 用正确的 Activity 路径启动 F-Droid
adb -s 192.168.1.90:5555 shell \
  "am start -n org.fdroid.fdroid/.views.main.MainActivity"
sleep 8
adb -s 192.168.1.90:5555 shell "pidof org.fdroid.fdroid"
# 7033

⑤ attach 抓包 ​

bash
cd /home/cc11001100/github/android-security-engineer/r0capture-skills
python3 r0capture.py -H 127.0.0.1:27042 7033 -p fdroid.pcap
# attach
# Press Ctrl+C to stop logging.

⑥ 抓包中触发流量 ​

App 不一定主动联网。抓包运行时,另开终端用 adb input 触发刷新:

bash
# 下拉刷新
adb -s 192.168.1.90:5555 shell input swipe 360 500 360 1300 300
# 点右上角菜单
adb -s 192.168.1.90:5555 shell input tap 660 90

看到 r0capture 输出一堆 SSL_read/SSL_write,说明抓到了。Ctrl+C 停止。

⑦ 分析 pcap ​

bash
# 看统计
echo "pcap大小: $(wc -c < fdroid.pcap)字节"
echo "SSL_read: $(grep -c SSL_read fdroid.log)"
echo "SSL_write: $(grep -c SSL_write fdroid.log)"

# 用 tcpdump 看
tcpdump -r fdroid.pcap -n | head

# 抓到的 URL
grep -aoE 'https?://[a-zA-Z0-9./_-]+' fdroid.log | sort -u

期望结果 ​

抓到就成功了。接下来可以看 抓 HTTP/1.1 明文 学怎么解明文,或 抓真实 App 流量 深入分析 HTTP/2。

一键自检:--selftest ​

如果上面哪步不确定,先用 selftest 验证链路:

bash
python3 r0capture.py -H 127.0.0.1:27042 7033 --selftest -v -p st.pcap
# 看到 [selftest] result={'code': 200, 'bodylen': 558} 就是全通

基于 VitePress 构建 · 教学用途