-
-
[求助]windbg64位,怎么查看函数参数?
-
发表于:
2013-12-5 11:46
6122
-
我在LoadLibraryW下的断点。kb命令后显示的参数为00000000`0000000c,但这不是一个有效的地址,LoadLibraryW的参数在哪里呢?
0:000> kb
RetAddr : Args to Child : Call Site
000007fe`f83a09ee : 01800009`00000000 00000000`0000000c 00000000`00000000 00000000`02381914 : kernel32!LoadLibraryW
0:000> dd rsp
00000000`0012db38 f83a09ee 000007fe 00000000 01800009
00000000`0012db48 0000000c 00000000 00000000 00000000
00000000`0012db58 02381914 00000000 023819e0 00000000
00000000`0012db68 0000000c 000007fe 0027c710 00000000
00000000`0012db78 00000000 00000000 00000000 00000000
00000000`0012db88 fd67717b 000007fe 00000072 00000000
00000000`0012db98 00247970 00000000 02381914 00000000
00000000`0012dba8 00247b74 00000000 00248150 00000000
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!