|
|
|
|
|
|
|
Figure T9-4:
Architecture of a portable executable file |
|
|
|
|
|
|
|
|
depth understanding of all aspects of the file formatjust those portions that are necessary to find and interpret the export function information. |
|
|
|
|
|
|
|
|
The overall architecture of a PE file is shown in Figure T9-4, which is derived from the specification. |
|
|
|
|
|
|
|
|
The curious thing about a portable executable file is that it begins with the same kind of header that has been used by executables since the early days of MS-DOS. That header is followed by an MS-DOS stub program. The existence of this header and stub is the reason that you can run any Windows executable under MS-DOS and see the message ''This Program Requires Microsoft Windows." The message is generated by the stub program. |
|
|
|
|
|
|
|
|
The Win32-specific information starts with the PE header. This means that the first step performed by the scanning program will be to scan past the MS-DOS header and stub program to find the PE header. |
|
|
|
|
|
|
|
|
The DOS header is defined by the following structure from winnt.h: |
|
|
|
|
|