You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Frida读取函数调用中的参数

Frida追踪C++函数参数读取方案

核心问题原因

你碰到的参数读取错误,本质是C++函数名字修饰和Windows调用约定导致的:

  • C++编译器会对函数名进行修饰,Add编译后实际导出名并非原名称
  • Windows默认__cdecl调用约定下,Frida的args数组第一个元素是返回地址,真实参数在后续位置

解决步骤

  1. 确认函数真实导出名
    用dumpbin /exports SimpleCalculator.exe命令查看目标程序的导出表,会看到Add被修饰成类似?Add@@YA?AVstring@@HH@Z的格式。

  2. 修改Frida脚本解析参数
    打开frida-trace生成的对应函数脚本,替换为以下代码:

    {
      onEnter: function(args) {
        // __cdecl调用约定:args[0]是返回地址,参数从args[1]、args[2]取
        const a = args[1].toInt32();
        const b = args[2].toInt32();
        console.log(`Add调用参数:a=${a}, b=${b}`);
      },
      onLeave: function(retval) {
        // 解析std::string返回值(VS编译结构)
        const strHeader = retval.readPointer();
        const strLen = strHeader.add(24).readUInt32();
        const strBuf = strHeader.add(16).readPointer();
        const result = strBuf.readUtf8String(strLen);
        console.log(`Add返回结果:${result}`);
      }
    }
    
  3. 用真实函数名启动追踪
    替换成你查到的修饰后的函数名执行命令:

    frida-trace -s "?Add@@YA?AVstring@@HH@Z" SimpleCalculator.exe
    

    嫌麻烦也可以用通配符匹配:

    frida-trace -s "*Add*" SimpleCalculator.exe
    

内容的提问来源于stack exchange,提问作者emrebener

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 14:41:06