You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Python读取其他进程内存时遇ReadProcessMemory无效句柄问题

Fixing "ReadProcessMemory invalid handle" Error in Python ctypes

Let's break down why you're hitting this error and how to fix it:

First off, that "invalid handle" error almost always means your processHandle from OpenProcess is invalid—either the call failed entirely, or you don't have the right permissions to access the target process. Here's what to do:

1. Use Minimal Required Permissions Instead of PROCESS_ALL_ACCESS

PROCESS_ALL_ACCESS is an overly broad permission set that Windows often denies, even if you think you have the right access. For reading process memory, you only need two specific permissions:

  • PROCESS_VM_READ: Grants access to read the process's memory
  • PROCESS_QUERY_INFORMATION: Lets you query basic process info (helps avoid access denied issues)

Define these constants properly in your code:

PROCESS_VM_READ = 0x0010
PROCESS_QUERY_INFORMATION = 0x0400

2. Check if OpenProcess Actually Succeeded

Windows API calls don't throw exceptions by default—they just return invalid values if they fail. Always verify the handle returned by OpenProcess isn't 0 (a sign of failure). You can use GetLastError() to get a specific error code to diagnose what went wrong.

3. Verify Target PID and Memory Address

Double-check these critical details:

  • The PID 4580 is still active (the target process hasn't exited since you got the PID)
  • The memory address 0x04782FF8 is valid for that process (static addresses can change if the process restarts or uses Address Space Layout Randomization (ASLR))

Corrected Code with Error Checking

Here's your code updated with all these fixes, plus proper error handling to help you debug issues:

from ctypes import *
from ctypes.wintypes import *

# Define Windows API function signatures (critical for type safety)
windll.kernel32.OpenProcess.argtypes = [DWORD, BOOL, DWORD]
windll.kernel32.OpenProcess.restype = HANDLE

windll.kernel32.ReadProcessMemory.argtypes = [HANDLE, LPCVOID, LPVOID, SIZE_T, POINTER(SIZE_T)]
windll.kernel32.ReadProcessMemory.restype = BOOL

windll.kernel32.CloseHandle.argtypes = [HANDLE]
windll.kernel32.CloseHandle.restype = BOOL

windll.kernel32.GetLastError.argtypes = []
windll.kernel32.GetLastError.restype = DWORD

# Use minimal necessary permissions
PROCESS_VM_READ = 0x0010
PROCESS_QUERY_INFORMATION = 0x0400

pid = 4580
address = 0x04782FF8

# Initialize memory buffers
buffer = c_uint()
buffer_size = sizeof(buffer)
bytes_read = c_size_t(0)

# Attempt to open the target process
process_handle = windll.kernel32.OpenProcess(PROCESS_VM_READ | PROCESS_QUERY_INFORMATION, False, pid)

if not process_handle:
    error_code = windll.kernel32.GetLastError()
    print(f"OpenProcess failed with error code: {error_code}")
else:
    # Attempt to read the target memory address
    success = windll.kernel32.ReadProcessMemory(
        process_handle,
        address,
        byref(buffer),
        buffer_size,
        byref(bytes_read)
    )
    
    if success:
        print(f"Successfully read {bytes_read.value} bytes. Value: {buffer.value}")
    else:
        error_code = windll.kernel32.GetLastError()
        print(f"ReadProcessMemory failed with error code: {error_code}")
    
    # Always close the process handle when done to avoid resource leaks
    windll.kernel32.CloseHandle(process_handle)

Common Error Codes to Diagnose

  • 5 (ERROR_ACCESS_DENIED): You don't have permission to access the process (try running your script as Administrator)
  • 87 (ERROR_INVALID_PARAMETER): One of your arguments to OpenProcess or ReadProcessMemory is invalid
  • 122 (ERROR_INSUFFICIENT_BUFFER): Your buffer size is too small (unlikely here with c_uint, but worth checking if you modify the buffer type)

内容的提问来源于stack exchange,提问作者Invision

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 11:12:12