1、拉伸到内存
2、分配一块新的空间:SizeOfImage + Ex
3、将最后一个节的SizeOfRawData和VirtualSize改成N
SizeOfRawData = VirtualSize = N
N = (SizeOfRawData或者VirtualSize 内存对齐后的值) + Ex
4、修改SizeOfImage大小
SizeOfImage = SizeOfImage + Ex
BOOL EnlargedNodalRegion(IN LPVOID pImageBuffer, OUT LPVOID* pNewBuffer, size_t EnlargeSize)
{
//DOC头
PIMAGE_DOS_HEADER pDosHeader = (PIMAGE_DOS_HEADER)pImageBuffer;
//NT头
PIMAGE_NT_HEADERS pNTHeader = (PIMAGE_NT_HEADERS)((DWORD)pDosHeader + pDosHeader->e_lfanew);
//标准PE头
PIMAGE_FILE_HEADER pPEHeader = (PIMAGE_FILE_HEADER)(((DWORD)pNTHeader) + 4);
//可选PE头
PIMAGE_OPTIONAL_HEADER32 pOptionHeader = (PIMAGE_OPTIONAL_HEADER32)((DWORD)pPEHeader + IMAGE_SIZEOF_FILE_HEADER);
if (*((PWORD)pImageBuffer) != IMAGE_DOS_SIGNATURE)
{
printf("MZ文件标志头不存在!");
free(pImageBuffer);
return false;
}
PIMAGE_SECTION_HEADER pSectionHeader = NULL;
//申请新的空间
pSectionHeader = (PIMAGE_SECTION_HEADER)((DWORD)pOptionHeader + pPEHeader->SizeOfOptionalHeader);
for (int i = 1; i < pPEHeader->NumberOfSections; i++)
pSectionHeader++;
pSectionHeader->SizeOfRawData = pSectionHeader->Misc.VirtualSize = Align((pSectionHeader->SizeOfRawData += EnlargeSize) > (pSectionHeader->Misc.VirtualSize += EnlargeSize) ?
pSectionHeader->SizeOfRawData: pSectionHeader->Misc.VirtualSize, pOptionHeader->SectionAlignment);
pOptionHeader->SizeOfImage += EnlargeSize;
*pNewBuffer = (PDWORD)malloc(pOptionHeader->SizeOfImage);
if (!*pNewBuffer)
{
printf("%s", "申请新扩大节后的空间失败!");
free(*pNewBuffer);
return false;
}
memset(*pNewBuffer, 0, pOptionHeader->SizeOfImage);
memcpy(*pNewBuffer, pImageBuffer, pOptionHeader->SizeOfImage);
return true;
}
Github地址:https://github.com/vShellCode/Analysis-of-PE-structure