Skip to content

Protobuf ​

📦 Google Protocol Buffers,二进制序列化协议,r0capture 抓到的是已序列化的二进制明文。

Protobuf 特征 ​

Protobuf 是二进制协议,非文本可读。r0capture 抓到的是已序列化的二进制字节流:

# hexdump 里看到的是一串二进制
0A 05 72 30 79 73 75 65 12 0B ...   →  field1="r0ysue" field2=...

需配合 .proto 定义或 protoc --decode_raw 解析。

在 r0capture 里的表现 ​

Protobuf over TLS(如 gRPC)走 SSL:

方向function内容
请求序列化SSL_writeProtobuf 二进制
响应序列化SSL_readProtobuf 二进制

不走 SSL 的裸 Protobuf 由 HTTP_send/HTTP_recv 抓。

gRPC 与 Protobuf ​

gRPC 基于 HTTP/2 + Protobuf。注意:r0capture 对 HTTP/2 支持有限(详见 HTTP/2 限制)。但有些 App 用 Protobuf over HTTP/1.1 或自定义 TCP,则可正常抓取。

解析方法 ​

抓到二进制后:

bash
# 用 protoc 原始解码(无需 .proto)
cat captured.bin | protoc --decode_raw

# 有 .proto 时
protoc --decode=package.MessageType proto_file.proto < captured.bin

相关文档 ​

基于 VitePress 构建 · 教学用途