如何查找带@后缀数字的Windows API函数名?
问题
我正在学习汇编语言(出于兴趣研究),需要实现控制台的打印与用户输入功能。我找到了微软官方的WriteConsole文档,但在汇编代码中引用该API时需要在函数名后添加@加数字,请问如何获取这个后缀数字?
附上我的汇编代码:
global _start extern _GetStdHandle@4 extern _WriteConsoleA@20 ;-----extern _ReadConsole@SOME_NUMBER_HERE extern _ExitProcess@4 %define STDOUT dword -11 ;init items section .data str: db 'hello, world', 0x0D, 0x0A strLen: equ $-str ;0-init items section .bss numCharsWritten: resd 1 ;code section .text _start: mov ebx, strLen mov ecx, str call .write push dword 0 call _ExitProcess@4 ;ebx - length, ecx - string .write: push STDOUT call _GetStdHandle@4 push dword 0 push numCharsWritten ;push dword strLen push ebx push ecx push eax call _WriteConsoleA@20 ret
编译命令:
nasm -f win32 $(FILE_NAME) -o $(NAME_PART).o ld -e _start $(NAME_PART).o -l kernel32 -o $(NAME_PART).exe
解答
这个@后面的数字是函数所有参数的总字节数,因为你用的是32位Windows平台的stdcall调用约定——这种约定要求调用者清理栈,后缀数字就是用来告诉链接器需要清理多少字节的栈空间。
具体计算步骤:
- 查对应Windows API的参数列表,32位下每个参数(dword类型)占4字节
- 把所有参数的字节数相加,总和就是
@后面的数字
以你需要的ReadConsoleA为例:
它的参数依次是:
HANDLE hConsoleInput(4字节)LPVOID lpBuffer(4字节)DWORD nNumberOfCharsToRead(4字节)LPDWORD lpNumberOfCharsRead(4字节)LPVOID pInputControl(4字节)
总共5个参数,5×4=20,所以完整函数名是_ReadConsoleA@20。
再对照你代码里的已有函数:
_GetStdHandle@4:仅1个参数,1×4=4,和后缀一致_WriteConsoleA@20:5个参数,5×4=20,也完全匹配
额外验证方法:
你可以用Windows自带的dumpbin工具查看kernel32.dll的导出表,执行命令dumpbin /exports kernel32.dll,就能看到所有导出函数的完整名称,包括@后的数字,直接抄用即可。
内容的提问来源于stack exchange,提问作者user20694960
相关产品推荐
相关产品推荐

