< previous page page_389 next page >

Page 389
0389-01.gif
Figure T9-5:
Organization of sections in an image file
   ExportSection = SectionCount - 1
   For secnum = 0 To SectionCount - 1
      If Sections(secnum).VirtualAddress  > ExportDirectoryOffset Then
         ExportSection = secnum - 1
         Exit For
      End If
   Next secnum
  ' We now know the section number, calculate the file offset
   ExportSectionOffset = Sections(ExportSection).VirtualAddress - _
   Sections(ExportSection).PointerToRawData
   ExportBase = ExportDirectoryOffset-ExportSectionOffset
End Sub
If you look in the IMAGE_OPTIONAL_HEADER structure, you'll see at the end a list of sixteen IMAGE_DATA_DIRECTORY structures. Each of these contains an offset to a particular type of data along with the size of that data. The first of these data directory entries refers to the export function table. How do I know this? From the PE file format specification.
The virtual address for the export table is loaded into the ExportDirectoryOffset variable. The virtual address describes the offset to a particular block of data once the image is loaded into memory, but we need the location of the export information in the file itself. The FindExportBase function scans through the sec-

 
< previous page page_389 next page >