Skip to content

HTTP / HTTPS ​

🌐 最常见的应用层协议,r0capture 抓包的主要目标。

HTTP 明文特征 ​

HTTP 是文本协议,明文可读:

http
GET /api/user HTTP/1.1
Host: api.example.com
User-Agent: okhttp/4.9.1
Accept: application/json
Authorization: Bearer eyJhbGc...

HTTP/1.1 200 OK
Content-Type: application/json
Content-Length: 128

{"id":123,"name":"r0ysue"}

r0capture 在 SSL_write 抓到请求(上行),在 SSL_read 抓到响应(下行),明文直接可见。

在 r0capture 里的表现 ​

方向hook 点function 字段内容
请求SSL_write onEnterSSL_writeGET/POST... 请求行+头+体
响应SSL_read onLeaveSSL_readHTTP/1.1 200... 状态行+头+体

HTTPS 与 HTTP ​

  • HTTP(明文):走裸 TCP,由 HTTP_send/HTTP_recv hook 抓
  • HTTPS(加密):走 SSL,由 SSL_read/SSL_write hook 抓明文

无论哪种,r0capture 拿到的都是应用层明文。

Wireshark 分析 ​

r0capture 写出的 pcap 里,HTTP 明文作为 TCP 载荷。Wireshark 里:

  1. 右键包 → Follow → TCP Stream,能看到完整请求+响应对话
  2. 因 linktype=228(裸 IPv4),无以太网头,直接是 IP+TCP+HTTP

常见 HTTP 头识别 ​

头含义
User-Agent客户端标识(可识别 OkHttp/Cronet 等)
Authorization认证凭证(Bearer token / Basic)
Content-Type请求/响应体类型
Cookie会话凭证

相关文档 ​

基于 VitePress 构建 · 教学用途