滴水逆向PE扩大最后一个节

#define _CRT_SECURE_NO_WARNINGS
#include<stdio.h>
#include<Windows.h>
#include<malloc.h>
char file_path[] = "C:\\CTF\\notepad.exe";
char save_path[] = "C:\\CTF\\extend_note.exe";

DWORD Fileread(char** Filebuffer) {
	FILE* fp = NULL;
	char* filebuffer = NULL;
	int file_size = 0;
	fp = fopen(file_path, "rb");
	fseek(fp, 0, SEEK_END);
	file_size = ftell(fp);
	fseek(fp, 0, SEEK_SET);
	filebuffer = (char*)malloc(file_size + 0x1000);
	fread(filebuffer, file_size, 1, fp);
	fclose(fp);
	*Filebuffer = filebuffer;
	return file_size+0x1000;
	}
DWORD kuodajie(int x,char *filebuffer) {
	PIMAGE_DOS_HEADER pDosHeader = NULL;
	PIMAGE_NT_HEADERS pNTHeader = NULL;
	PIMAGE_FILE_HEADER pPEHeader = NULL;
	PIMAGE_OPTIONAL_HEADER32 pOptionHeader = NULL;
	PIMAGE_SECTION_HEADER pSectionHeader = NULL;
	pDosHeader = (PIMAGE_DOS_HEADER)filebuffer;
	if (*((PDWORD)((DWORD)filebuffer + pDosHeader->e_lfanew)) != IMAGE_NT_SIGNATURE)
	{
		printf("不是有效的PE文件\n");
		return 0;
	}
	
	pNTHeader = (PIMAGE_NT_HEADERS)((DWORD)filebuffer + pDosHeader->e_lfanew);
	pPEHeader = (PIMAGE_FILE_HEADER)((DWORD)pNTHeader + 4); 
	pOptionHeader = (PIMAGE_OPTIONAL_HEADER32)((DWORD)pPEHeader + IMAGE_SIZEOF_FILE_HEADER);
	pSectionHeader = (PIMAGE_SECTION_HEADER)((DWORD)pOptionHeader + pPEHeader->SizeOfOptionalHeader);
	PIMAGE_SECTION_HEADER endsectionheader = pSectionHeader + pPEHeader->NumberOfSections-1;
	endsectionheader->Misc.VirtualSize += 0x1000;
	endsectionheader->SizeOfRawData += 0x1000;
	pOptionHeader->SizeOfImage += 0x1000;
	FILE* fp = NULL;
	fp = fopen(save_path, "wb");
	fwrite(filebuffer, 1, x, fp);
	fclose(fp);

	return 0;
}
DWORD extend() {
	char* filebuffer = NULL;
	int x = Fileread(&filebuffer);
	kuodajie(x, filebuffer);
	return 0;
}
int main() {
	extend();
	return 0;
}


  • 0
    点赞
  • 3
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值