SSL_write(C 原型)
📤 OpenSSL/BoringSSL 的
SSL_write函数原型与 r0capture hook 方式。
C 原型
c
#include <openssl/ssl.h>
int SSL_write(SSL *ssl, const void *buf, int num);参数与返回值
| 参数 | 类型 | 含义 |
|---|---|---|
ssl | SSL* | SSL 连接对象 |
buf | const void* | 待发送的明文缓冲区 |
num | int | 要发送的字节数 |
返回值:
> 0:实际发送的字节数<= 0:出错
r0capture 的 hook
javascript
Interceptor.attach(addresses["SSL_write"], {
onEnter: function (args) {
var message = getPortsAndAddresses(SSL_get_fd(args[0]), false);
message["ssl_session_id"] = getSslSessionId(args[0]);
message["function"] = "SSL_write";
message["stack"] = SSLstackwrite;
send(message, args[1].readByteArray(parseInt(args[2])));
},
onLeave: function (retval) {}
});参数映射
| C 参数 | Frida | 含义 |
|---|---|---|
ssl | args[0] | 取 fd 和 session_id |
buf | args[1] | 待发明文,onEnter 直接读 |
num | args[2] | 读 parseInt(args[2]) 字节 |
为什么在 onEnter 读
待发明文在 args[1] 已现成,无需等返回值。详见 SSL_write hook。
与 SSL_read 的差异
| 维度 | SSL_read | SSL_write |
|---|---|---|
| 明文位置 | 执行后写 buf | args[1] 现成 |
| 读时机 | onLeave | onEnter |
| 长度来源 | retval | args[2] |
| 方向 | 服务端→本端 | 本端→服务端 |