You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在无Protobuf Schema时解析TCP传输的Protobuf数据?

无原始Protobuf Schema时解析捕获的Protobuf数据

第一步:剥离非Protobuf封装层

你手动删减后的十六进制能正常解码,说明原始十六流的开头部分是TCP帧头/应用层自定义包头,不属于Protobuf本身的内容。先把这部分剥离:

  • 原始十六进制开头的2000005c000000080db0020000100218800148022080042a4182203e是非Protobuf封装段,剩下的0a3c...才是有效的Protobuf数据段。

第二步:手动逆向推导Protobuf Schema

Protobuf的二进制格式是字段号+wire类型+值的结构,每个字段的第一个字节是(字段号 << 3) | wire类型,常见wire类型:

  • 0:Varint(整数、bool、enum)
  • 2:长度限定型(string、bytes、嵌套消息)

从你已解码的字段入手,逐步解析所有字段:

  1. 已知有效段的0a是字段号1(1 << 3 | 2),wire类型为2(长度限定),3c是字符串长度(60),后续字节就是字符串内容,对应Schema字段:string field1 = 1;
  2. 对原始封装段的字节逐一拆解:
    • 080db002:08是字段号1(1<<3|0),wire类型0,0db002是Varint,解码为139264,对应int32 header_field1 = 1;(注:这里的字段号和业务消息的字段号1分属不同消息,原始数据大概率是嵌套结构)
    • 1002:10是字段号2(2<<3|0),wire类型0,值为2,对应int32 header_field2 = 2;
    • 188001:18是字段号3(3<<3|0),8001是Varint,解码为384,对应int32 header_field3 = 3;
  3. 把所有解析出的字段整理成.proto文件,比如:
message RequestHeader {
  int32 field1 = 1;
  int32 field2 = 2;
  int32 field3 = 3;
  int32 field9 = 9;
  bytes field4 = 4;
}

message BusinessRequest {
  string page_identifier = 1; // 对应你解码的bumble_mobile_landing|...
}

第三步:用工具辅助逆向解析

可以用专门的Protobuf逆向工具快速梳理结构:

  • protoscope:将二进制Protobuf数据转换为结构化文本,直接显示字段号、wire类型和原始值。将十六进制转成二进制文件后,执行protoscope input.bin即可得到解析结果。
  • 动态消息构造(Python):通过手动构建Descriptor来解析数据,示例代码:
from google.protobuf.descriptor_pb2 import FileDescriptorProto
from google.protobuf import descriptor_pool, message_factory

# 构建动态消息描述
file_proto = FileDescriptorProto()
file_proto.name = "dynamic_request.proto"
msg_proto = file_proto.message_type.add()
msg_proto.name = "BusinessRequest"

# 添加已知的字段1
field = msg_proto.field.add()
field.name = "page_id"
field.number = 1
field.type = field.TYPE_STRING

# 注册描述符并生成消息类
pool = descriptor_pool.Default()
pool.Add(file_proto)
RequestMsg = message_factory.GetMessageClass(pool.FindMessageTypeByName("BusinessRequest"))

# 解码你的有效Protobuf数据
data = bytes.fromhex("0a3c62756d626c655f6d6f62696c655f6c616e64696e677c323a30306535653766312d653766312d663165362d653662662d626634303230613231313061")
msg = RequestMsg()
msg.ParseFromString(data)
print(msg)

第四步:结合业务逻辑补全Schema

从解码出的字符串bumble_mobile_landing|2:00e5e7f1-e7f1-f1e6-e6bf-bf4020a2110a来看:

  • bumble_mobile_landing是业务页面标识,字段1可命名为page_identifier
  • 后面的UUID格式字符串大概率是设备ID或会话ID,可进一步对比同类型捕获数据的字段变化,推断更多字段的含义和类型。

内容的提问来源于stack exchange,提问作者coderduem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 19:07:10