Switch network_mitm Tutorial

View raw

Switch network_mitm Tutorial

Using network_mitm makes it easy to grab decrypted SSL packets without needing to set up an SSL proxy like Charles. This tutorial covers a sample use case for dumping the packets of getting an elicense id and your na_id to use with NintendoClients.

Requirements

  • Switch with Atmosphere CFW
  • network_mitm
    • I've attached a compiled version for 23.0.0 since the official version is not compiled yet. This one was created by updating libnx and Atmosphere-libs.
  • Wireshark

Installation

On your sd card create or modify /atmosphere/config/system_settings.ini

; network_mitm config
[network_mitm]
; Enable SSL: This should be set to 1 for certificate swapping, and also for PCAP capturing.
enable_ssl = u8!0x1
; Uncomment this line to enable mitm of everything (including system titles).
should_mitm_all = u8!0x1
; Uncomment this line to disable SSL verifications (DANGEROUS)
; should_disable_ssl_verification = u8!0x1
; Root CA filename: this should be present in the root of the SD (sd:/rootCA.pem for the below example)
; custom_ca_public_cert = str!rootCA.pem
; By default, the sysmodule will dump decrypted network traffic user-link PCAPs to the SD card only for the main application.
; Uncomment this line to disable.
; should_dump_ssl_traffic = u8!0x0
; Possible values "ethernet", "ip" or "user"
; pcap_link_type = str!user

Since in this tutorial we want to get the elicense id we need to enable mitm for all titles since the request we need is made by the system.

Next, copy the atmosphere directory from network_mitm to the root of your sd card to install it.

Making the capture

Boot into the CFW. Start playing the game you want the elicense id for. The capture is done automatically in the background. You can turn off the switch and mount the sd in your computer.

Inspecting the capture

The pcap files are found in sd:/atmosphere/pcap/{ProgramId} The easiest way to view them is using Wireshark. You can select all the pcap files in a directory and drag them on to Wireshark's main page to load them.

For this tutorial select all pcap files in 010000000000001e which is the account module and load them into Wireshark.

For the packets to be decoded better you can right click one then click Protocol Preferences -> DLT User -> Encapsulations Table.... Click the + button to add a new entry and set the payload dissector to http and the header size to 4. Now look for the packet with /v2/contents_authorization_token_for_aauth/issue. The POST body will contain the elicense id and the na_id.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论