Skip to content

HTTPS 协议 ​

🔒 HTTP over TLS,r0capture 最常抓的协议。

是什么 ​

HTTPS = HTTP 跑在 TLS 之上。先 TLS 握手建加密通道,再在里面传 HTTP。

r0capture 的位置 ​

r0capture hook SSL_write/SSL_read,正好在 HTTP 明文和 TLS 加密之间:

  • SSL_write(buf):App 把 HTTP 明文交给 TLS 加密前 → r0capture 拿到明文请求
  • SSL_read(buf):TLS 解密后的明文 HTTP → r0capture 拿到明文响应

这就是 r0capture 抓 HTTPS 的根本——不需要解密 TLS,直接在加解密的"出入口"拿明文。

抓到的内容 ​

[SSL_write] 192.168.1.5:54321 --> api.app.com:443
POST /api/login HTTP/1.1
Host: api.app.com
Content-Type: application/json

{"user":"alice"}

[SSL_read] api.app.com:443 --> 192.168.1.5:54321
HTTP/1.1 200 OK
Content-Type: application/json

{"token":"xxx"}

与中间人代理的对比 ​

方式需装 CA?受 Pinning 影响?拿到
系统代理 + mitmproxy是是(需绕 pinning)明文
r0capture否否明文

详见 抓包方式对比。

相关文档 ​

基于 VitePress 构建 · 教学用途