Protobuf
📦 Google Protocol Buffers,二进制序列化协议,r0capture 抓到的是已序列化的二进制明文。
Protobuf 特征
Protobuf 是二进制协议,非文本可读。r0capture 抓到的是已序列化的二进制字节流:
# hexdump 里看到的是一串二进制
0A 05 72 30 79 73 75 65 12 0B ... → field1="r0ysue" field2=...需配合 .proto 定义或 protoc --decode_raw 解析。
在 r0capture 里的表现
Protobuf over TLS(如 gRPC)走 SSL:
| 方向 | function | 内容 |
|---|---|---|
| 请求序列化 | SSL_write | Protobuf 二进制 |
| 响应序列化 | SSL_read | Protobuf 二进制 |
不走 SSL 的裸 Protobuf 由 HTTP_send/HTTP_recv 抓。
gRPC 与 Protobuf
gRPC 基于 HTTP/2 + Protobuf。注意:r0capture 对 HTTP/2 支持有限(详见 HTTP/2 限制)。但有些 App 用 Protobuf over HTTP/1.1 或自定义 TCP,则可正常抓取。
解析方法
抓到二进制后:
bash
# 用 protoc 原始解码(无需 .proto)
cat captured.bin | protoc --decode_raw
# 有 .proto 时
protoc --decode=package.MessageType proto_file.proto < captured.bin