Skip to content

NativeFunction ​

🧰 Frida 把 Native 函数地址包装成可调 JS 函数的 API。

用法 ​

javascript
var SSL_get_fd = new NativeFunction(address, "int", ["pointer"]);
// 之后可像普通函数调用: var fd = SSL_get_fd(sslPtr);

签名:new NativeFunction(addr, returnType, [argTypes])

r0capture 的用法 ​

initializeGlobals 把所有解析出的地址包装成 NativeFunction:

javascript
SSL_get_fd = new NativeFunction(addresses["SSL_get_fd"], "int", ["pointer"]);
SSL_get_session = new NativeFunction(addresses["SSL_get_session"], "pointer", ["pointer"]);
SSL_SESSION_get_id = new NativeFunction(addresses["SSL_SESSION_get_id"], "pointer", ["pointer", "pointer"]);
getpeername = new NativeFunction(addresses["getpeername"], "int", ["int", "pointer", "pointer"]);
ntohs = new NativeFunction(addresses["ntohs"], "uint16", ["uint16"]);
ntohl = new NativeFunction(addresses["ntohl"], "uint32", ["uint32"]);

之后在 getPortsAndAddresses、getSslSessionId 里像调普通 JS 函数一样调它们。

类型映射 ​

Frida 类型C 类型说明
"int"int32 位有符号
"uint16"uint16_t16 位无符号
"uint32"uint32_t32 位无符号
"pointer"void*指针

return_zero 桩 ​

当 SSL_get_fd 找不到时,用 return_zero(普通 JS 函数,返回 0)代替 NativeFunction,使后续调用 SSL_get_fd(...) 不崩。详见 return_zero。

相关文档 ​

基于 VitePress 构建 · 教学用途