关于导出表的遍历
1、序号表是函数名称表到函数地址表的一个中转,也就是说,必须通过序号才能找到对应的函数的地址
2、比如 需要找的函数是 “function7” 它位于名字表的第4项,所以要去序号表中的第4项找这个函数的函数序号,找到为0006h ..然后再加上BASE。所得到的值,就作为函数地址表中的索引,然后就可以找到对应函数的地址了
////////////////////根据名字查找函数地址////////////////
DWORD _GetApi(LPVOID pFileBuffer,LPSTR ApiName)
{
PIMAGE_DOS_HEADER pDosHeader = NULL;
PIMAGE_NT_HEADERS pNtHeaders = NULL;
PIMAGE_EXPORT_DIRECTORY pExportDirectory=NULL;
LPSTR DllName=NULL;
PDWORD AddrOfFunction,AddrofNames;
PWORD AddrofNameOrd;
DWORD dwOrd=0;
DWORD dwRVA=0;
LPSTR pName=NULL;
pDosHeader = (PIMAGE_DOS_HEADER)pFileBuffer;
if (pDosHeader->e_magic != IMAGE_DOS_SIGNATURE)
{
printf("not a mz header!\n");
return 0;
}
pNtHeaders = (PIMAGE_NT_HEADERS)((DWORD)pDosHeader + pDosHeader->e_lfanew);
if (pNtHeaders->Signature != IMAGE_NT_SIGNATURE)
{
printf("not a PE header!\n");
return 0;
}
//导出表的位置
pExportDirectory=(PIMAGE_EXPORT_DIRECTORY)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pNtHeaders->OptionalHeader.DataDirectory[0].VirtualAddress));
//遍历导出表
DllName=(LPSTR)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->Name));
AddrOfFunction=(PDWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfFunctions));
AddrofNames=(PDWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfNames));
AddrofNameOrd=(PWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfNameOrdinals));
printf("///%s//\n",DllName);
printf("characteristics: %x\n",pExportDirectory->Characteristics);
printf("TimeDateStamp: %x\n",pExportDirectory->TimeDateStamp);
printf("majorVersion: %ud\n",pExportDirectory->MajorVersion);
printf("minorVersion: %ud\n",pExportDirectory->MinorVersion);
printf("name: %s\n",DllName);
printf("base: %x\n",pExportDirectory->Base);
printf("NumberofFunctions: %x\n",pExportDirectory->NumberOfFunctions);
printf("NumberofNames: %x\n",pExportDirectory->NumberOfNames);
printf("AddressOfFunctions: %x\n",pExportDirectory->AddressOfFunctions);
printf("AddressOfNames: %x\n",pExportDirectory->AddressOfNames);
printf("AddressOfNameOrdinals: %x\n",pExportDirectory->AddressOfNameOrdinals);
printf("\n");
printf("ord RVA NAME\n");
printf("---------------------------------------\n");
for(int i=0;i<pExportDirectory->NumberOfNames;i++)
{
//序号
dwOrd=*AddrofNameOrd+pExportDirectory->Base;
//函数名
pName=(LPSTR)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,*AddrofNames));
//函数的RVA
dwRVA=*AddrOfFunction;
printf("%x %x %s\n",dwOrd,dwRVA,pName);
/////查找指定的API////////
if(strcmp(pName,ApiName)==0)
{
printf("API.ADDR=%x\n",pNtHeaders->OptionalHeader.ImageBase+dwRVA);
return pNtHeaders->OptionalHeader.ImageBase+dwRVA;
}
AddrofNameOrd++;
AddrofNames++;
AddrOfFunction++;
}
return 0;
}