如何使用Frida读取函数调用中的参数
Frida追踪C++函数参数读取方案
核心问题原因
你碰到的参数读取错误,本质是C++函数名字修饰和Windows调用约定导致的:
- C++编译器会对函数名进行修饰,
Add编译后实际导出名并非原名称 - Windows默认
__cdecl调用约定下,Frida的args数组第一个元素是返回地址,真实参数在后续位置
解决步骤
确认函数真实导出名
用dumpbin /exports SimpleCalculator.exe命令查看目标程序的导出表,会看到Add被修饰成类似?Add@@YA?AVstring@@HH@Z的格式。修改Frida脚本解析参数
打开frida-trace生成的对应函数脚本,替换为以下代码:{ onEnter: function(args) { // __cdecl调用约定:args[0]是返回地址,参数从args[1]、args[2]取 const a = args[1].toInt32(); const b = args[2].toInt32(); console.log(`Add调用参数:a=${a}, b=${b}`); }, onLeave: function(retval) { // 解析std::string返回值(VS编译结构) const strHeader = retval.readPointer(); const strLen = strHeader.add(24).readUInt32(); const strBuf = strHeader.add(16).readPointer(); const result = strBuf.readUtf8String(strLen); console.log(`Add返回结果:${result}`); } }用真实函数名启动追踪
替换成你查到的修饰后的函数名执行命令:frida-trace -s "?Add@@YA?AVstring@@HH@Z" SimpleCalculator.exe嫌麻烦也可以用通配符匹配:
frida-trace -s "*Add*" SimpleCalculator.exe
内容的提问来源于stack exchange,提问作者emrebener
相关产品推荐
相关产品推荐

