HTTPS 协议
🔒 HTTP over TLS,r0capture 最常抓的协议。
是什么
HTTPS = HTTP 跑在 TLS 之上。先 TLS 握手建加密通道,再在里面传 HTTP。
r0capture 的位置
r0capture hook SSL_write/SSL_read,正好在 HTTP 明文和 TLS 加密之间:
SSL_write(buf):App 把 HTTP 明文交给 TLS 加密前 → r0capture 拿到明文请求SSL_read(buf):TLS 解密后的明文 HTTP → r0capture 拿到明文响应
这就是 r0capture 抓 HTTPS 的根本——不需要解密 TLS,直接在加解密的"出入口"拿明文。
抓到的内容
[SSL_write] 192.168.1.5:54321 --> api.app.com:443
POST /api/login HTTP/1.1
Host: api.app.com
Content-Type: application/json
{"user":"alice"}
[SSL_read] api.app.com:443 --> 192.168.1.5:54321
HTTP/1.1 200 OK
Content-Type: application/json
{"token":"xxx"}与中间人代理的对比
| 方式 | 需装 CA? | 受 Pinning 影响? | 拿到 |
|---|---|---|---|
| 系统代理 + mitmproxy | 是 | 是(需绕 pinning) | 明文 |
| r0capture | 否 | 否 | 明文 |
详见 抓包方式对比。