HTTP / HTTPS
🌐 最常见的应用层协议,r0capture 抓包的主要目标。
HTTP 明文特征
HTTP 是文本协议,明文可读:
http
GET /api/user HTTP/1.1
Host: api.example.com
User-Agent: okhttp/4.9.1
Accept: application/json
Authorization: Bearer eyJhbGc...
HTTP/1.1 200 OK
Content-Type: application/json
Content-Length: 128
{"id":123,"name":"r0ysue"}r0capture 在 SSL_write 抓到请求(上行),在 SSL_read 抓到响应(下行),明文直接可见。
在 r0capture 里的表现
| 方向 | hook 点 | function 字段 | 内容 |
|---|---|---|---|
| 请求 | SSL_write onEnter | SSL_write | GET/POST... 请求行+头+体 |
| 响应 | SSL_read onLeave | SSL_read | HTTP/1.1 200... 状态行+头+体 |
HTTPS 与 HTTP
- HTTP(明文):走裸 TCP,由
HTTP_send/HTTP_recvhook 抓 - HTTPS(加密):走 SSL,由
SSL_read/SSL_writehook 抓明文
无论哪种,r0capture 拿到的都是应用层明文。
Wireshark 分析
r0capture 写出的 pcap 里,HTTP 明文作为 TCP 载荷。Wireshark 里:
- 右键包 → Follow → TCP Stream,能看到完整请求+响应对话
- 因 linktype=228(裸 IPv4),无以太网头,直接是 IP+TCP+HTTP
常见 HTTP 头识别
| 头 | 含义 |
|---|---|
User-Agent | 客户端标识(可识别 OkHttp/Cronet 等) |
Authorization | 认证凭证(Bearer token / Basic) |
Content-Type | 请求/响应体类型 |
Cookie | 会话凭证 |