PE --导出表

导出表
关于导出表的遍历
1、序号表是函数名称表到函数地址表的一个中转,也就是说,必须通过序号才能找到对应的函数的地址
2、比如 需要找的函数是 “function7” 它位于名字表的第4项,所以要去序号表中的第4项找这个函数的函数序号,找到为0006h ..然后再加上BASE。所得到的值,就作为函数地址表中的索引,然后就可以找到对应函数的地址了

////////////////////根据名字查找函数地址////////////////
DWORD _GetApi(LPVOID pFileBuffer,LPSTR ApiName)
{
    PIMAGE_DOS_HEADER pDosHeader = NULL;
    PIMAGE_NT_HEADERS pNtHeaders = NULL;

    PIMAGE_EXPORT_DIRECTORY pExportDirectory=NULL;
    LPSTR DllName=NULL;
    PDWORD AddrOfFunction,AddrofNames;
    PWORD AddrofNameOrd;

    DWORD dwOrd=0;
    DWORD dwRVA=0;
    LPSTR pName=NULL;

    pDosHeader = (PIMAGE_DOS_HEADER)pFileBuffer;
    if (pDosHeader->e_magic != IMAGE_DOS_SIGNATURE)
    {
        printf("not a mz header!\n");
        return 0;
    }
    pNtHeaders = (PIMAGE_NT_HEADERS)((DWORD)pDosHeader + pDosHeader->e_lfanew);
    if (pNtHeaders->Signature != IMAGE_NT_SIGNATURE)
    {
        printf("not a PE header!\n");
        return 0;
    }

    //导出表的位置
    pExportDirectory=(PIMAGE_EXPORT_DIRECTORY)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pNtHeaders->OptionalHeader.DataDirectory[0].VirtualAddress));

    //遍历导出表
    DllName=(LPSTR)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->Name));
    AddrOfFunction=(PDWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfFunctions));
    AddrofNames=(PDWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfNames));
    AddrofNameOrd=(PWORD)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,pExportDirectory->AddressOfNameOrdinals));

    printf("///%s//\n",DllName);
    printf("characteristics: %x\n",pExportDirectory->Characteristics);
    printf("TimeDateStamp: %x\n",pExportDirectory->TimeDateStamp);
    printf("majorVersion: %ud\n",pExportDirectory->MajorVersion);
    printf("minorVersion: %ud\n",pExportDirectory->MinorVersion);
    printf("name: %s\n",DllName);
    printf("base: %x\n",pExportDirectory->Base);
    printf("NumberofFunctions: %x\n",pExportDirectory->NumberOfFunctions);
    printf("NumberofNames: %x\n",pExportDirectory->NumberOfNames);
    printf("AddressOfFunctions: %x\n",pExportDirectory->AddressOfFunctions);
    printf("AddressOfNames: %x\n",pExportDirectory->AddressOfNames);
    printf("AddressOfNameOrdinals: %x\n",pExportDirectory->AddressOfNameOrdinals);

    printf("\n");
    printf("ord           RVA             NAME\n");
    printf("---------------------------------------\n");

    for(int i=0;i<pExportDirectory->NumberOfNames;i++)
    {
        //序号
        dwOrd=*AddrofNameOrd+pExportDirectory->Base;
        //函数名
        pName=(LPSTR)((DWORD)pFileBuffer+_RVAToOffset(pFileBuffer,*AddrofNames));
        //函数的RVA
        dwRVA=*AddrOfFunction;
        printf("%x        %x               %s\n",dwOrd,dwRVA,pName);
        /////查找指定的API////////
        if(strcmp(pName,ApiName)==0)
        {
            printf("API.ADDR=%x\n",pNtHeaders->OptionalHeader.ImageBase+dwRVA);
            return pNtHeaders->OptionalHeader.ImageBase+dwRVA;
        }
        AddrofNameOrd++;
        AddrofNames++;
        AddrOfFunction++;

    }

    return 0;
}

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值