Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I believe that's how https://github.com/gojue/ecapture works. I don't know the details, but it seems to work!


Yep, that's correct. It uses eBPF upprobes to attach to the SSL_write/SSL_read functions.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: