|
|
|
|
|
|
|
Public Type IMAGE_SECTION_HEADER
ShortName(7) As Byte
VirtualSize As Long
VirtualAddress As Long
SizeOfRawData As Long
PointerToRawData As Long
PointerToRelocations As Long
PointerToLinenumbers As Long
NumberOfRelocations As Integer
NumberOfLinenumbers As Integer
Characteristics As Long
End Type |
|
|
|
|
|
|
|
|
The SectionsOffset variable is loaded with the current offset into the file (which is the location immediately after the PE Header information). The following code loads the Sections array: |
|
|
|
|
|
|
|
|
SectionsOffset = Seek(FileHandle)
For x = 0 To SectionCount - 1
Get #FileHandle, , Sections(x)
Next x |
|
|
|
|
|
|
|
|
The section table includes information on the sections that appear in the image data area. There are three fields that are of interest to us. The VirtualAddress represents the address in memory where the section will start once it is loaded into memory. The PointerToRawData field contains the location of the section in the image file. The SizeOfRawData field contains the size of the section in the image file. Figure T9-5 illustrates the relationship of section tables to sections. As you can see, the export table appears as part of one of the sections. |
|
|
|
|
|
|
|
|
So far the program has loaded the PE file header, any optional headers, and the file's section table. We'll be looking for the section that contains the export table for the file. The FindExportBase function loads the ExportBase variable with the base to the export table: |
|
|
|
|
|
|
|
|
Private Sub FindExportBase()
Dim secnum%
ExportDirectoryOffset = _
PEHeader.OptionalHeader.DataDirectory(0).VirtualAddress |
|
|
|
|
|