Patrefans
oalabs from patreon
oalabs patreon

Understanding PE Parsing for Reverse Engineers Part 4 - Data Directory and Exports

🕑 Added 2023-05-24 23:52:21 +0000 UTC
Understanding PE Parsing for Reverse Engineers Part 4 - Data Directory and Exports

Comments

OALABS

Only 20 lines of code away from knowing the answer!!

anests1a

I can perform the approach with Proccess Injection and create a child that inherits Virtual Address Descriptor and do the PE parsing with NtQueryVirtualMemory and then detect the memory pages with IMAGE_NT_HEADERS* ntHeaders = (IMAGE_NT_HEADERS*)(pAddress + dosHeader->e_lfanew); if (ntHeaders->SIGNATURE != IMAGE_NT_SIGNATURE) and achieve the same? I mean it would be more complicated but can it be done? If I read a valid Signature I can go through its EXPORT_DIRECTORY to see if it matches any hashing and know that I am inside the dll I want.

성일 배

I don't understand. Could you explain more?

June

Took me a while to figure out why there would be a "." 10 bytes into ntdll, kind of surprised there's not a way to make it show that it's the 6th character

m4n0w4r

For more complete content, I think you should do the Part 5 - Data Directory and Relocation


More Creators