如何在无Protobuf Schema时解析TCP传输的Protobuf数据?
无原始Protobuf Schema时解析捕获的Protobuf数据
第一步:剥离非Protobuf封装层
你手动删减后的十六进制能正常解码,说明原始十六流的开头部分是TCP帧头/应用层自定义包头,不属于Protobuf本身的内容。先把这部分剥离:
- 原始十六进制开头的
2000005c000000080db0020000100218800148022080042a4182203e是非Protobuf封装段,剩下的0a3c...才是有效的Protobuf数据段。
第二步:手动逆向推导Protobuf Schema
Protobuf的二进制格式是字段号+wire类型+值的结构,每个字段的第一个字节是(字段号 << 3) | wire类型,常见wire类型:
- 0:Varint(整数、bool、enum)
- 2:长度限定型(string、bytes、嵌套消息)
从你已解码的字段入手,逐步解析所有字段:
- 已知有效段的
0a是字段号1(1 << 3 | 2),wire类型为2(长度限定),3c是字符串长度(60),后续字节就是字符串内容,对应Schema字段:string field1 = 1; - 对原始封装段的字节逐一拆解:
080db002:08是字段号1(1<<3|0),wire类型0,0db002是Varint,解码为139264,对应int32 header_field1 = 1;(注:这里的字段号和业务消息的字段号1分属不同消息,原始数据大概率是嵌套结构)1002:10是字段号2(2<<3|0),wire类型0,值为2,对应int32 header_field2 = 2;188001:18是字段号3(3<<3|0),8001是Varint,解码为384,对应int32 header_field3 = 3;
- 把所有解析出的字段整理成
.proto文件,比如:
message RequestHeader { int32 field1 = 1; int32 field2 = 2; int32 field3 = 3; int32 field9 = 9; bytes field4 = 4; } message BusinessRequest { string page_identifier = 1; // 对应你解码的bumble_mobile_landing|... }
第三步:用工具辅助逆向解析
可以用专门的Protobuf逆向工具快速梳理结构:
- protoscope:将二进制Protobuf数据转换为结构化文本,直接显示字段号、wire类型和原始值。将十六进制转成二进制文件后,执行
protoscope input.bin即可得到解析结果。 - 动态消息构造(Python):通过手动构建Descriptor来解析数据,示例代码:
from google.protobuf.descriptor_pb2 import FileDescriptorProto from google.protobuf import descriptor_pool, message_factory # 构建动态消息描述 file_proto = FileDescriptorProto() file_proto.name = "dynamic_request.proto" msg_proto = file_proto.message_type.add() msg_proto.name = "BusinessRequest" # 添加已知的字段1 field = msg_proto.field.add() field.name = "page_id" field.number = 1 field.type = field.TYPE_STRING # 注册描述符并生成消息类 pool = descriptor_pool.Default() pool.Add(file_proto) RequestMsg = message_factory.GetMessageClass(pool.FindMessageTypeByName("BusinessRequest")) # 解码你的有效Protobuf数据 data = bytes.fromhex("0a3c62756d626c655f6d6f62696c655f6c616e64696e677c323a30306535653766312d653766312d663165362d653662662d626634303230613231313061") msg = RequestMsg() msg.ParseFromString(data) print(msg)
第四步:结合业务逻辑补全Schema
从解码出的字符串bumble_mobile_landing|2:00e5e7f1-e7f1-f1e6-e6bf-bf4020a2110a来看:
bumble_mobile_landing是业务页面标识,字段1可命名为page_identifier- 后面的UUID格式字符串大概率是设备ID或会话ID,可进一步对比同类型捕获数据的字段变化,推断更多字段的含义和类型。
内容的提问来源于stack exchange,提问作者coderduem
相关产品推荐
相关产品推荐

