Skip to content

抓取 gRPC 流量 ​

📡 gRPC(基于 HTTP/2 + Protobuf)的抓取。

gRPC 特点 ​

  • 基于 HTTP/2(多路复用)
  • 用 Protobuf 编码 body(二进制,非可读)
  • 走标准 TLS

r0capture 抓取 ​

gRPC 走系统或自带 SSL 栈,r0capture SSL hook 能抓到密文之前的明文:

bash
r0capture -p -grpc.pcap com.example.app

抓到的样子 ​

[SSL_write] POST /helloworld.Greeter/SayHello HTTP/2
content-type: application/grpc+proto

<二进制 protobuf body>

HTTP/2 帧头 + protobuf 二进制。body 不可读,需 protobuf 解析。

解析 protobuf ​

抓到的是二进制 proto,需 .proto schema 解码:

bash
protoc --decode_raw < body.bin   # 无 schema 的 raw 解码
protoc --decode=my.Message --proto_path=. my.proto < body.bin  # 有 schema

HTTP/2 的 stream ​

gRPC 在一条 HTTP/2 连接上多 stream 并发,pcap 里靠 stream id 区分不同 RPC。

相关文档 ​

基于 VitePress 构建 · 教学用途