跳转至

Wireshark#

如何用 Wireshark 过滤浏览器中的 HTTP/HTTPS 请求?#

  1. Option 1: Via macOS environment variable
  2. Open Wireshark, go to Preferences -> Protocols -> TLS
  3. Expand your "$HOME" PATH of the value of ~/.tlskeyfile you set on stage 1, fill in the blank at the (Pre)-Master-Secret log filename, or just click Browse to choose the file.

Export specific packets#

  1. Click on a packet you want to follow
  2. Right click, chose Follow -> TCP Stream, or use keyboard combine shortcut Option-Shift-Command-T (⌥⇧⌘T)
  3. Stop capturijng packets
  4. Open File -> Export specific packets...
  5. Chose location and write down a filename
  6. Save