Switch network_mitm Tutorial
Switch network_mitm Tutorial
Using network_mitm makes it easy to grab decrypted SSL packets without needing to set up an SSL proxy like Charles. This tutorial covers a sample use case for dumping the packets of getting an elicense id and your na_id to use with NintendoClients.
Requirements
- Switch with Atmosphere CFW
- network_mitm
- I've attached a compiled version for 23.0.0 since the official version is not compiled yet. This one was created by updating libnx and Atmosphere-libs.
- Wireshark
Installation
On your sd card create or modify /atmosphere/config/system_settings.ini
; network_mitm config
[network_mitm]
; Enable SSL: This should be set to 1 for certificate swapping, and also for PCAP capturing.
enable_ssl = u8!0x1
; Uncomment this line to enable mitm of everything (including system titles).
should_mitm_all = u8!0x1
; Uncomment this line to disable SSL verifications (DANGEROUS)
; should_disable_ssl_verification = u8!0x1
; Root CA filename: this should be present in the root of the SD (sd:/rootCA.pem for the below example)
; custom_ca_public_cert = str!rootCA.pem
; By default, the sysmodule will dump decrypted network traffic user-link PCAPs to the SD card only for the main application.
; Uncomment this line to disable.
; should_dump_ssl_traffic = u8!0x0
; Possible values "ethernet", "ip" or "user"
; pcap_link_type = str!user
Since in this tutorial we want to get the elicense id we need to enable mitm for all titles since the request we need is made by the system.
Next, copy the atmosphere directory from network_mitm to the root of your sd card to install it.
Making the capture
Boot into the CFW. Start playing the game you want the elicense id for. The capture is done automatically in the background. You can turn off the switch and mount the sd in your computer.
Inspecting the capture
The pcap files are found in sd:/atmosphere/pcap/{ProgramId} The easiest way to view them is using Wireshark. You can select all the pcap files in a directory and drag them on to Wireshark's main page to load them.
For this tutorial select all pcap files in 010000000000001e which is the account module and load them into Wireshark.
For the packets to be decoded better you can right click one then click Protocol Preferences -> DLT User -> Encapsulations Table.... Click the + button to add a new entry and set the payload dissector to http and the header size to 4. Now look for the packet with /v2/contents_authorization_token_for_aauth/issue. The POST body will contain the elicense id and the na_id.