Win32 API 日本語リファレンス
ホームSystem.WindowsProgramming › RtlGetReturnAddressHijackTarget

RtlGetReturnAddressHijackTarget

関数
リターンアドレスハイジャック緩和用のターゲットアドレスを取得する。
DLLntdll.dll呼出規約winapi

シグネチャ

// ntdll.dll
#include <windows.h>

UINT_PTR RtlGetReturnAddressHijackTarget(void);

パラメーターなし。戻り値: UINT_PTR

各言語での呼び出し定義

// ntdll.dll
#include <windows.h>

UINT_PTR RtlGetReturnAddressHijackTarget(void);
[DllImport("ntdll.dll", ExactSpelling = true)]
static extern UIntPtr RtlGetReturnAddressHijackTarget();
<DllImport("ntdll.dll", ExactSpelling:=True)>
Public Shared Function RtlGetReturnAddressHijackTarget() As UIntPtr
End Function
Declare PtrSafe Function RtlGetReturnAddressHijackTarget Lib "ntdll" () As LongPtr
' VBA7前提(PtrSafe)。32bit Office では LongPtr→Long。Integer=16bit / Long=32bit / LongLong=64bit。
import ctypes
from ctypes import wintypes

RtlGetReturnAddressHijackTarget = ctypes.windll.ntdll.RtlGetReturnAddressHijackTarget
RtlGetReturnAddressHijackTarget.restype = ctypes.c_size_t
RtlGetReturnAddressHijackTarget.argtypes = []
require 'fiddle'
require 'fiddle/import'

lib = Fiddle.dlopen('ntdll.dll')
RtlGetReturnAddressHijackTarget = Fiddle::Function.new(
  lib['RtlGetReturnAddressHijackTarget'],
  [],
  Fiddle::TYPE_UINTPTR_T)
#[link(name = "ntdll")]
extern "system" {
    fn RtlGetReturnAddressHijackTarget() -> usize;
}
// crates: windows-sys provides ready-made bindings for this API.
$sig = @"
[DllImport("ntdll.dll")]
public static extern UIntPtr RtlGetReturnAddressHijackTarget();
"@
$api = Add-Type -MemberDefinition $sig -Name 'ntdll_RtlGetReturnAddressHijackTarget' -Namespace Win32 -PassThru
# $api::RtlGetReturnAddressHijackTarget()
#uselib "ntdll.dll"
#func global RtlGetReturnAddressHijackTarget "RtlGetReturnAddressHijackTarget"
; RtlGetReturnAddressHijackTarget   ; 戻り値は stat
; ※HSP3.7は #func のため戻り値はシステム変数 stat に格納されます。
#uselib "ntdll.dll"
#cfunc global RtlGetReturnAddressHijackTarget "RtlGetReturnAddressHijackTarget"
; res = RtlGetReturnAddressHijackTarget()
; UINT_PTR RtlGetReturnAddressHijackTarget()
#uselib "ntdll.dll"
#cfunc global RtlGetReturnAddressHijackTarget "RtlGetReturnAddressHijackTarget"
; res = RtlGetReturnAddressHijackTarget()
import (
	"golang.org/x/sys/windows"
	"unsafe"
)

var (
	ntdll = windows.NewLazySystemDLL("ntdll.dll")
	procRtlGetReturnAddressHijackTarget = ntdll.NewProc("RtlGetReturnAddressHijackTarget")
)

r1, _, err := procRtlGetReturnAddressHijackTarget.Call()
_ = err  // syscall.Errno (valid when the call sets last-error)
_ = r1   // UINT_PTR
function RtlGetReturnAddressHijackTarget: NativeUInt; stdcall;
  external 'ntdll.dll' name 'RtlGetReturnAddressHijackTarget';
result := DllCall("ntdll\RtlGetReturnAddressHijackTarget", "UPtr")
●RtlGetReturnAddressHijackTarget() = DLL("ntdll.dll", "int RtlGetReturnAddressHijackTarget()")
# 呼び出し: RtlGetReturnAddressHijackTarget()
# なでしこ1は32bit・ANSI(Shift_JIS)。文字列=char*(ANSI)、ポインタ/ハンドル=void*(4byte)。