charles ,我们亲切的把它称作茶壶,功能还是十分强大的,尤其是在mac上无法使用fiddler更是。。
其实很容易上手,下载安装,手机设置下ip代理不久可以了嘛?但是你发现包为https的时候就不那么容易了,所以写一个教程,也是自己设置的过程记录下来。顺便把正常http的抓包过程也叙述一下。
△
Charles是通过将自己设置成系统的网络访问代理服务器,使得所有的网络访问请求都通过它来完成,从而实现了网络封包的截取和分析。
△
除了在做移动开发中调试端口外,Charles 也可以用于分析第三方应用的通讯协议。配合 Charles 的 SSL 功能,Charles 还可以分析 Https 协议。
本文以mac为例子进行操作,windows下想使用charles的道理相同,不过windows下倒是更习惯用fiddler
- Charles安装
- HTTP抓包
- HTTPS抓包
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhNVEl5T1RrMFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
一. Charles安装
详细请见上一篇博客:
charles破解安装
二. HTTP抓包
(1)查看电脑IP地址[两种方法]
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXpNRE01T0RFNFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
方法一
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhNakV5TkRZeFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
方法二
(2)设置手机HTTP代理
手机连上电脑,点击“设置->无线局域网->连接的WiFi”,设置HTTP代理:
服务器为电脑IP地址:如192.168.1.169
端口:8888
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhNekF6TkRrelAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
(3)电脑上打开Charles进行HTTP抓包
手机上打开某个App或者浏览器什么的
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhNekU1T1RZeVAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
点击“Allow”允许,出现手机的HTTP请求列表
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhOREExTVRFNFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
HTTP抓包
三. HTTPS抓包
HTTPS的抓包需要在HTTP抓包基础上再进行设置
在没有设置前,对HTTPS抓包是这样的,看不到信息
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhOakkyTVRFd1AzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
设置后抓包HTTPS长这样
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhOekF3T1RBeFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
以下为在HTTP抓包基础上进行HTTP抓包的进一步设置步骤
(1)安装SSL证书
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXhOekUxTWpZeFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
(2)安装SSL证书到手机设备
点击 Help -> SSL Proxying -> Install Charles Root Certificate on a Mobile Device
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNREUzTWpnNFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
出现弹窗得到地址
chls.pro/ssl
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNRFE0TURjd1AzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
手机安装SSL证书的地址
手机设置有密码的输入密码进行安装
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNVEEwT0RJMVAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNVEV4TWpjMFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNVEU0TkRneFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlNVE0yT0RJeFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
安装证书
(3)Charles设置Proxy
Proxy -> SSL Proxying Settings...
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlORFUxTnprMVAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
勾选Enable SSL Proxying,点击Add
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlOVEE0T0RJM1AzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
Host设置要抓取的https接口,比如想抓这个
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlOVE01T1RNMlAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
Port填写:443
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlOVFUwTnpRNVAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
(3)进行HTTPS抓包
让手机重新发送https请求,可看到抓包
![Charles如何抓取http/https请求 Charles如何抓取http/https请求](https://image.shishitao.com:8440/aHR0cHM6Ly93d3cuaXRkYWFuLmNvbS9nby9hSFIwY0RvdkwybHRaeTVpYkc5bkxtTnpaRzR1Ym1WMEx6SXdNVGN3TVRFMU1UQXlOakV4T0RJNFAzZGhkR1Z5YldGeWF5OHlMM1JsZUhRdllVaFNNR05FYjNaTU1rcHpZakpqZFZrelRtdGlhVFYxV2xoUmRtUkliR1poUjFrOUwyWnZiblF2TldFMlREVk1NbFF2Wm05dWRITnBlbVV2TkRBd0wyWnBiR3d2U1RCS1FsRnJSa05OUVQwOUwyUnBjM052YkhabEx6Y3dMMmR5WVhacGRIa3ZRMlZ1ZEdWeQ%3D%3D.jpg?w=700&webp=1)
HTTPS抓包
注意:不抓包请关闭手机HTTP代理,否则断开与电脑连接后会连不上网
----end