Reversing : The Hacker's Guide to Reverse Engineering

(ff) #1
0 [ 0] RVA [size] of Architecture Directory
0 [ 0] RVA [size] of Global Pointer Directory
0 [ 0] RVA [size] of Thread Storage Directory
3ED30 [ 48] RVA [size] of Load Configuration Directory
270 [ 4C] RVA [size] of Bound Import Directory
1000 [ 4E4] RVA [size] of Import Address Table Directory
5DE70 [ A0] RVA [size] of Delay Import Directory
0 [ 0] RVA [size] of COM Descriptor Directory
0 [ 0] RVA [size] of Reserved Directory

SECTION HEADER #1
.text name
5EDA7 virtual size
1000 virtual address (77D41000 to 77D9FDA6)
5EE00 size of raw data
400 file pointer to raw data (00000400 to 0005F1FF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers
60000020 flags
Code
Execute Read

Debug Directories

Time Type Size RVA Pointer
-------- ------ -------- -------- --------
41107EEC cv 23 0005FD84 5F184 Format: RSDS,
{036A117A-6A5C-43DE-835A-E71302E90504}, 2, user32.pdb
41107EEC ( A) 4 0005FD80 5F180 BB030D70

SECTION HEADER #2
.data name
1160 virtual size
60000 virtual address (77DA0000 to 77DA115F)
C00 size of raw data
5F200 file pointer to raw data (0005F200 to 0005FDFF)
0 file pointer to relocation table
0 file pointer to line numbers
0 number of relocations
0 number of line numbers

Listing 4.1 (continued)


Reversing Tools 135
Free download pdf