如何用Frida获取get_Location返回的LatLng结构体经纬度值
问题描述
我定义了如下结构体:
public struct LatLng { public double Latitude; // 0x0 public double Longitude; // 0x8 }
还有如下函数:
public LatLng get_Location()
请问如何在Frida脚本中获取该函数返回的纬度(Latitude)和经度(Longitude)值?
以下是我编写的代码:
Interceptor.attach(il2cpp.add(0x23CCCCC),{ onEnter: function(args){ }, onLeave: function(ret_val){ this.instance = ret_val; var pointer = this.instance.readPointer(); var lat = pointer.add(0x0); console.log( "lat: "+lat.readDouble()); var lng = pointer.add(0x8); console.log( "long: "+lng.readDouble()); } });
解决方案
在IL2CPP环境中,值类型(比如struct)的返回逻辑和引用类型不同,你不需要额外读取指针,ret_val本身就指向存储结构体数据的内存区域。修改后的脚本如下:
Interceptor.attach(il2cpp.add(0x23CCCCC), { onLeave: function(ret_val) { // 直接从ret_val指向的内存读取结构体字段 const latitude = ret_val.readDouble(); // 对应0x0偏移的Latitude const longitude = ret_val.add(0x8).readDouble(); // 对应0x8偏移的Longitude console.log(`纬度: ${latitude}, 经度: ${longitude}`); } });
关键说明
- IL2CPP中,值类型函数返回时,结构体数据直接存放在返回值寄存器指向的内存块里,
ret_val就是这个内存块的指针,无需再调用readPointer()。 - 按照你定义的结构体内存布局,直接通过偏移量读取对应的double值即可,0x0对应Latitude,0x8对应Longitude。
内容的提问来源于stack exchange,提问作者trongtd1988
相关产品推荐
相关产品推荐

