标签:cto tab 依据 可变 mac 相同 imp copyright ase
由上往下依次为: IMAGE_ DOS_ HEADER-->DOS Stub
NT头: IMAGE_ NT HEADERS (下面介绍)
PE头与各节区的尾部存在一个区域, 称为NULL填充( NULL padding )。 00 00 00 00
MAGIC:
AddressOfEntryPoint
ImageBase
SectionAlignment,FileAlignment
SizeOflmage
SizeOfHeader
Subsystem
NumberOfRvaAndSizes
typedef struct _IMAGE_DATA_DIRECTORY {
DWORD VirtualAddress;
DWORD Size;
} IMAGE_DATA_DIRECTORY,*PIMAGE_DATA_DIRECTORY;
#define IMAGE_DIRECTORY_ENTRY_EXPORT?0
#define IMAGE_DIRECTORY_ENTRY_IMPORT?1
#define IMAGE_DIRECTORY_ENTRY_RESOURCE? 2
#define IMAGE_DIRECTORY_ENTRY_EXCEPTION 3
#define IMAGE_DIRECTORY_ENTRY_SECURITY? 4
#define IMAGE_DIRECTORY_ENTRY_BASERELOC 5
#define IMAGE_DIRECTORY_ENTRY_DEBUG 6
#define IMAGE_DIRECTORY_ENTRY_COPYRIGHT 7
#define IMAGE_DIRECTORY_ENTRY_ARCHITECTURE? 7
#define IMAGE_DIRECTORY_ENTRY_GLOBALPTR 8
#define IMAGE_DIRECTORY_ENTRY_TLS??9
#define IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG??10
#define IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT?11
#define IMAGE_DIRECTORY_ENTRY_IAT??12
#define IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT 13
#define IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR???14
标签:cto tab 依据 可变 mac 相同 imp copyright ase
原文地址:https://www.cnblogs.com/l0nmar/p/12850837.html