Skip to content

hook 客户端证书详解 ​

🗝️ script.js hook KeyStore$PrivateKeyEntry,捕获 mTLS 客户端私钥。

📎 源码在线查看:script.js(PrivateKeyEntry hook)

做什么 ​

双向认证(mTLS)时,App 从 KeyStore 取私钥+证书做客户端认证。r0capture hook 这个取的过程,顺便导出私钥+证书。

hook 点 ​

javascript
var PKEntry = Java.use("java.security.KeyStore$PrivateKeyEntry");

PKEntry.getPrivateKey.implementation = function () {
    var pri = this.getPrivateKey();
    var chain = this.getCertificateChain();
    console.log("捕获客户端私钥,导出 p12...");
    storeP12(pri, chain);   // 导出
    return pri;
};

触发时机 ​

App 在 TLS 握手被服务端索要证书时,从 KeyStore 取 PrivateKeyEntry → 触发 hook。

为什么 getPrivateKey ​

App 取私钥是为了用它签名握手。这个动作证明:这里有客户端证书。hook 它能可靠捕获,而不会在 App 不用证书时空触发。

storeP12 导出 ​

捕获后调 storeP12 把私钥+证书打包成 .p12(密码 r0ysue)写到 /sdcard/Download/。

前提 ​

  • spawn 模式:attach 太晚,握手已过,私钥可能已取走
  • App 确实用了客户端证书(非 mTLS 的 App 不触发)
  • 存储权限已授

用途 ​

导出的 p12 可导入 mitmproxy 做 mTLS 中间人:

bash
mitmproxy --client-cert com.x.p12 --client-cert-password r0ysue

相关文档 ​

基于 VitePress 构建 · 教学用途