薇尔薇

Back

Pasted image 20250414140633

171-173:TCP三次握手阶段[[TCP握手.excalidraw]] 175-181:TLS握手[[TLS1.2握手.excalidraw]][[TLS1.3握手.excalidraw]] Pasted image 20250414162024 Pasted image 20250414162035

Pasted image 20250414162750

数据包信息#

数据包基本信息 Frame#

wireshark获取到的数据包基本信息

数据链路层 Ethernet II#

Ethernet II, Src: ASUSTekCOMPU_7b:35:8d (04:d4:c4:7b:35:8d), Dst: HuaweiDevice_26:97:02 (30:66:d0:26:97:02)
    Destination: HuaweiDevice_26:97:02 (30:66:d0:26:97:02)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
    Source: ASUSTekCOMPU_7b:35:8d (04:d4:c4:7b:35:8d)
        .... ..0. .... .... .... .... = LG bit: Globally unique address (factory default)
        .... ...0 .... .... .... .... = IG bit: Individual address (unicast)
    Type: IPv4 (0x0800)
    [Stream index: 0]
plaintext

定义以以太网帧的源MAC地址1和目标MAC地址

网络层 Internet#

目标IP和源IP

  • Internet Protocol Version 4:使用IPV4
  • Time to Live: 128:数据包在路由器中最大条数,每经过1跳-1
  • Protocol: TCP (6):协议类型为TCP

传输层 Transmission#

  • Source Port: 38415:本机端口
  • Destination Port: 443:目标服务器端口
  • Header Length: 20 bytes (5):TCP Header长度

Client Hello 175#

Pasted image 20250414141249

  • Content Type: Handshake (22):表示这是一个握手消息
  • Handshake Protocol: Client Hello:表示这是一个客户端发送的 Client Hello 消息
  • Version: TLS 1.2 (0x0303):表示客户端支持的最高 TLS 版本
  • Random:客户端生成的随机数,用户后续密钥生成
  • Session ID:会话ID
  • Cipher Suites (16 suites):客户端支持的加密套件,按优先级排序
  • Compression Methods:客户端支持的压缩算法
  • key_share:客户端生成的公钥
  • server_name:SNI
  • application_layer_protocol_negotiation:客户端支持的应用层协议,h2,http/1.1
  • supported_versions (len=7) TLS 1.3, TLS 1.2:客户端支持的 TLS 版本
  • signature_algorithms:客户端支持的签名算法
  • pre_shared_key:预共享密钥(PSK)信息,用于会话恢复
  • JA4:识别客户端的 TLS 实现


Client Hello ACK 179#

179	1.253799	47.108.167.197	192.168.3.104	TCP	60	443 → 38415 [ACK] Seq=1 Ack=1845 Win=62464 Len=0
plaintext

服务器收到客户端发送的Client Hello后发送的ACK

Server Hello 180#

180	1.254261	47.108.167.197	192.168.3.104	TLSv1.3	308	Server Hello, Change Cipher Spec, Application Data, Application Data
plaintext
  • TLSv1.3 Record Layer: Handshake Protocol: Server Hello:TLS层基本信息,Server Hello表示握手消息
  • Handshake Protocol: Server Hello:握手消息的具体类型和长度
  • Version: TLS 1.2 (0x0303):服务器支持的最高 TLS 版本(该字段应被忽略,实际使用的是 supported_versions 扩展中的版本信息)
  • Random:服务端生成的随机数
  • Session ID:会话ID
  • Cipher Suite: TLS_AES_256_GCM_SHA384 (0x1302):服务器选择的加密套件
  • Compression Method:服务器支持的压缩算法
  • supported_versions:服务器支持的协议版本
  • key_share:服务器生成的公钥
  • pre_shared_key:支持会话恢复,则选择预共享密钥
  • TLSv1.3 Record Layer: Change Cipher Spec Protocol: Change Cipher Spec:表示服务器已切换到加密通信模式
  • TLSv1.3 Record Layer: Application Data Protocol: Hypertext Transfer Protocol:加密的应用层数据,HTTP数据

Client Finished 181#

181	1.254855	192.168.3.104	47.108.167.197	TLSv1.3	134	Change Cipher Spec, Application Data
plaintext
Transport Layer Security
    TLSv1.3 Record Layer: Change Cipher Spec Protocol: Change Cipher Spec
        Content Type: Change Cipher Spec (20)
        Version: TLS 1.2 (0x0303)
        Length: 1
        Change Cipher Spec Message
    TLSv1.3 Record Layer: Application Data Protocol: Hypertext Transfer Protocol
        Opaque Type: Application Data (23)
        Version: TLS 1.2 (0x0303)
        Length: 69
        Encrypted Application Data: 61ee5f08513e506269de00aae940042238e8ce98b7810addc0e4e3a63490d823ba67d7b3a337aa2111dbe38f989b8cc2bcae0770894839be59ea2420e8f4a7c55abf7a57f0
        [Application Data Protocol: Hypertext Transfer Protocol]
plaintext
  • TLSv1.3 Record Layer: Change Cipher Spec Protocol: Change Cipher Spec:客户端使用协商好的加密参数对数据加密通讯
  • TLSv1.3 Record Layer: Application Data Protocol: Hypertext Transfer Protocol:加密的应用层数据

Footnotes#

  1. MAC 地址是一个 48 位的值,分为两部分:

    • 前 24 位(OUI,Organizationally Unique Identifier):由 IEEE 分配给设备制造商。
    • 后 24 位:由制造商分配给具体设备。
    ↩
HTTPS抓包
https://vio.vin/blog/https-zhua-bao
Author violet
Published at 2025年4月14日