抓取 gRPC 流量
📡 gRPC(基于 HTTP/2 + Protobuf)的抓取。
gRPC 特点
- 基于 HTTP/2(多路复用)
- 用 Protobuf 编码 body(二进制,非可读)
- 走标准 TLS
r0capture 抓取
gRPC 走系统或自带 SSL 栈,r0capture SSL hook 能抓到密文之前的明文:
bash
r0capture -p -grpc.pcap com.example.app抓到的样子
[SSL_write] POST /helloworld.Greeter/SayHello HTTP/2
content-type: application/grpc+proto
<二进制 protobuf body>HTTP/2 帧头 + protobuf 二进制。body 不可读,需 protobuf 解析。
解析 protobuf
抓到的是二进制 proto,需 .proto schema 解码:
bash
protoc --decode_raw < body.bin # 无 schema 的 raw 解码
protoc --decode=my.Message --proto_path=. my.proto < body.bin # 有 schemaHTTP/2 的 stream
gRPC 在一条 HTTP/2 连接上多 stream 并发,pcap 里靠 stream id 区分不同 RPC。