函数在内存中的具体执行
等待函數返回以后再從中取出,跳到該處繼續執行。
#include <stdio.h>
void TestFunction()
{
?int i = 10;
?return;
}
void main()
{
?TestFunction();
?return;
}
?
?
?EAX = CCCCCCCC EBX = 7FFD5000 ECX = 00000000 EDX = 00591030 ESI = 00000000 EDI = 0012FF48 EIP = 0040D468 ESP = 0012FEFC EBP = 0012FF48 EFL = 00000202
?
0012FEE4? 00 00 00 00 02 00 00 00 30 2F? ........0/
0012FEEE? 42 00 83 00 00 00 E0 06 59 00? B.......Y.
0012FEF8? 1C FF 12 00 00 00 00 00 00 00? ..........
0012FF02? 00 00 00 50 FD 7F CC CC CC CC? ...P?燙燙
0012FF0C? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF16? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF20? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF2A? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF34? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF3E? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF48? 88 FF 12 00 89 11 40 00 01 00? ......@...
0012FF52? 00 00 B8 0F 59 00 30 10 59 00? ....Y.0.Y.
?
9:??????? TestFunction();
0040D468?? call??????? @ILT+5(TestFunction) (0040100a)
10:?????? return;
11:?? }
0040D46D?? pop???????? edi
0040D46E?? pop???????? esi
0040D46F?? pop???????? ebx
?
我們可以看到TestFunction下一條指令是0040D46D,也就是函數返回的地址,我們按F11鍵單步執行就會發現,0040D46D被壓入
了棧中。
?
?EAX = CCCCCCCC EBX = 7FFD5000 ECX = 00000000 EDX = 00591030 ESI = 00000000 EDI = 0012FF48 EIP = 0040100A ESP = 0012FEF8 EBP = 0012FF48 EFL = 00000202
0012FEE4? 00 00 00 00 02 00 00 00 30 2F? ........0/
0012FEEE? 42 00 83 00 00 00 E0 06 59 00? B.......Y.
0012FEF8? 6D D4 40 00 00 00 00 00 00 00? m訞.......
0012FF02? 00 00 00 50 FD 7F CC CC CC CC? ...P?燙燙
0012FF0C? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF16? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF20? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF2A? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF34? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF3E? CC CC CC CC CC CC CC CC CC CC? 燙燙燙燙燙
0012FF48? 88 FF 12 00 89 11 40 00 01 00? ......@...
0012FF52? 00 00 B8 0F 59 00 30 10 59 00? ....Y.0.Y.
?
然后單步執行到TestFunction函數里,
?
4:??????? int i = 10;
00401028?? mov???????? dword ptr [ebp-4],0Ah
5:??????? return;
6:??? }
0040102F?? pop???????? edi
00401030?? pop???????? esi
00401031?? pop???????? ebx
00401032?? mov???????? esp,ebp
00401034?? pop???????? ebp
00401035?? ret
?
當執行到ret之后,TestFunction函數就會返回,跳轉到0040D46D這個地址。
?
0040D46D?? pop???????? edi
0040D46E?? pop???????? esi
0040D46F?? pop???????? ebx
0040D470?? add???????? esp,40h
0040D473?? cmp???????? ebp,esp
0040D475?? call??????? __chkesp (00401060)
0040D47A?? mov???????? esp,ebp
0040D47C?? pop???????? ebp
0040D47D?? ret
?
??? 正是因為先放入棧里的地址在前,而后進入棧的數據一旦很長,就會覆蓋到前面的地址,
這就會導致程序發生錯誤。這也就是溢出的原因。
總結
以上是生活随笔為你收集整理的函数在内存中的具体执行的全部內容,希望文章能夠幫你解決所遇到的問題。