a亚洲精品_精品国产91乱码一区二区三区_亚洲精品在线免费观看视频_欧美日韩亚洲国产综合_久久久久久久久久久成人_在线区

首頁 > 編程 > C > 正文

C語言怎么獲得進(jìn)程的PE文件信息

2020-01-26 14:47:15
字體:
供稿:網(wǎng)友

一、打印Sections信息。下面的程序打印出Windows_Graphics_Programming 1.1中第三個程序“Hello World Version 3:Create a Full-Screen Window"生成的可執(zhí)行文件的Sections結(jié)構(gòu)字節(jié)的信息

#include<stdio.h>#include<windows.h>char *strPath="C:/c1_hwv3/Debug/c1_hwv3.exe";int main(){  IMAGE_DOS_HEADER myDosHeader;  LONG e_lfanew;  FILE *pFile;  pFile=fopen(strPath,"rb+");  fread(&myDosHeader,sizeof(IMAGE_DOS_HEADER),1,pFile);  e_lfanew=myDosHeader.e_lfanew;  IMAGE_FILE_HEADER myFileHeader;  int nSectionCount;  fseek(pFile,(e_lfanew+sizeof(DWORD)),SEEK_SET);  fread(&myFileHeader,sizeof(IMAGE_FILE_HEADER),1,pFile);  nSectionCount=myFileHeader.NumberOfSections;  IMAGE_SECTION_HEADER *pmySectionHeader=    (IMAGE_SECTION_HEADER *)calloc(nSectionCount,sizeof(IMAGE_SECTION_HEADER));  fseek(pFile,(e_lfanew+sizeof(IMAGE_NT_HEADERS)),SEEK_SET);  fread(pmySectionHeader,sizeof(IMAGE_SECTION_HEADER),nSectionCount,pFile);  for(int i=0;i<nSectionCount;i++,pmySectionHeader++)  {    printf("Name: %s/n", pmySectionHeader->Name);    printf("union_PhysicalAddress: %08x/n", pmySectionHeader->Misc.PhysicalAddress);    printf("union_VirtualSize: %04x/n", pmySectionHeader->Misc.VirtualSize);    printf("VirtualAddress: %08x/n", pmySectionHeader->VirtualAddress);    printf("SizeOfRawData: %08x/n", pmySectionHeader->SizeOfRawData);    printf("PointerToRawData: %04x/n", pmySectionHeader->PointerToRawData);    printf("PointerToRelocations: %04x/n", pmySectionHeader->PointerToRelocations);    printf("PointerToLinenumbers: %04x/n", pmySectionHeader->PointerToLinenumbers);    printf("NumberOfRelocations: %04x/n", pmySectionHeader->NumberOfRelocations);    printf("NumberOfLinenumbers: %04x/n", pmySectionHeader->NumberOfLinenumbers);    printf("Charateristics: %04x/n", pmySectionHeader->Characteristics);  }//  pmySectionHeader-=m_nSectionCount;  if(pmySectionHeader!=NULL)  {    free(pmySectionHeader);    pmySectionHeader=NULL;  }  fclose(pFile);  return 0;}

運行程序打印出如下信息

Name: .textunion_PhysicalAddress: 00022350union_VirtualSize: 22350VirtualAddress: 00001000SizeOfRawData: 00023000PointerToRawData: 1000PointerToRelocations: 0000PointerToLinenumbers: 0000NumberOfRelocations: 0000NumberOfLinenumbers: 0000Charateristics: 60000020Name: .rdataunion_PhysicalAddress: 00001615union_VirtualSize: 1615VirtualAddress: 00024000SizeOfRawData: 00002000PointerToRawData: 24000PointerToRelocations: 0000PointerToLinenumbers: 0000NumberOfRelocations: 0000NumberOfLinenumbers: 0000Charateristics: 40000040Name: .dataunion_PhysicalAddress: 00005650union_VirtualSize: 5650VirtualAddress: 00026000SizeOfRawData: 00004000PointerToRawData: 26000PointerToRelocations: 0000PointerToLinenumbers: 0000NumberOfRelocations: 0000NumberOfLinenumbers: 0000Charateristics: c0000040Name: .idataunion_PhysicalAddress: 00000b23union_VirtualSize: 0b23VirtualAddress: 0002c000SizeOfRawData: 00001000PointerToRawData: 2a000PointerToRelocations: 0000PointerToLinenumbers: 0000NumberOfRelocations: 0000NumberOfLinenumbers: 0000Charateristics: c0000040Name: .relocunion_PhysicalAddress: 00000f00union_VirtualSize: 0f00VirtualAddress: 0002d000SizeOfRawData: 00001000PointerToRawData: 2b000PointerToRelocations: 0000PointerToLinenumbers: 0000NumberOfRelocations: 0000NumberOfLinenumbers: 0000Charateristics: 42000040

pe文件結(jié)構(gòu)圖:

時間,時間,會給我答案 time will give me the answer

再給大家分享一則

#include <windows.h>#include <stdio.h>#define MAX_SECTION_NUM  16#define MAX_IMPDESC_NUM  64 HANDLE hHeap;PIMAGE_DOS_HEADER pDosHeader;PCHAR  pDosStub;DWORD  dwDosStubSize;DWORD  dwDosStubOffset;PIMAGE_NT_HEADERS      pNtHeaders;PIMAGE_FILE_HEADER     pFileHeader;PIMAGE_OPTIONAL_HEADER32  pOptHeader;PIMAGE_SECTION_HEADER  pSecHeaders;PIMAGE_SECTION_HEADER  pSecHeader[MAX_SECTION_NUM];WORD wSecNum;PBYTE pSecData[MAX_SECTION_NUM];DWORD dwSecSize[MAX_SECTION_NUM];DWORD dwFileSize; void OutputPEInMem(HANDLE hd){  // 請在這里填入你的代碼  DWORD             dwBase;  dwBase = (DWORD)hd;  pDosHeader = (PIMAGE_DOS_HEADER)dwBase;  pNtHeaders = (PIMAGE_NT_HEADERS)(dwBase + pDosHeader->e_lfanew);  pOptHeader = &(pNtHeaders->OptionalHeader);  pFileHeader = &(pNtHeaders->FileHeader);  printf("Address Of Entry Point: 0x%08x/n", pOptHeader->AddressOfEntryPoint);  printf("ImageBase: 0x%08x/n", pOptHeader->ImageBase);  printf("Number Of Sections: %d/n", pFileHeader->NumberOfSections);  printf("Size Of Image: 0x%04x/n", pOptHeader->SizeOfImage);  return;} int main(int argc, char *argv[]){  DWORD pid = 0;  pid=atoi(argv[1]);  HANDLE hd=OpenProcess(PROCESS_ALL_ACCESS,FALSE,pid);     LPCSTR lpszFileName = "hello.exe";  LPCSTR lpszInjFileName = "hello_inj0.exe";      OutputPEInMem(hd);  hHeap = GetProcessHeap();   if (! CopyPEFileToMem(lpszFileName)) {    return 1;  }  return 0;}

發(fā)表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發(fā)表

圖片精選

主站蜘蛛池模板: 一区二区三区免费网站 | 色婷婷综合久久久久中文一区二 | www.久久 | 国产传媒在线观看 | 欧洲视频一区二区三区 | 成人在线看片网站 | 玖玖在线| 国产成人精品网站 | 欧美一区二区大片 | 91精品久久久久久久久久入口 | 亚洲天堂一区 | 可以免费看黄的网站 | 91视频三区 | 天天看片天天操 | 成人免费一区二区三区视频网站 | 91成人免费视频 | 国产亚洲网站 | 午夜精品一区二区三区在线播放 | 国产精品久久久久久久 | 国产91网| 免费国产视频 | 亚洲毛片在线观看 | 国产日韩欧美一区二区 | 久久色av | 毛片网站在线观看 | 国产成人一区二区 | 国产日韩欧美在线观看 | 成人av播放 | 欧美日韩中文字幕 | 久久精品国产77777蜜臀 | 玖玖成人 | 久久伊人操 | 国产亚洲精品久久久久动 | 成人免费一区二区三区视频网站 | 成人午夜视频在线观看 | 奇米影 | 久久久久综合 | 国产一区二区三区视频在线观看 | 欧美一二区 | 青草视频在线播放 | 伊人久久视频 |