|
|
|
|
|
|
|
Figure T9-5:
Organization of sections in an image file |
|
|
|
|
|
|
|
|
ExportSection = SectionCount - 1
For secnum = 0 To SectionCount - 1
If Sections(secnum).VirtualAddress > ExportDirectoryOffset Then
ExportSection = secnum - 1
Exit For
End If
Next secnum
' We now know the section number, calculate the file offset
ExportSectionOffset = Sections(ExportSection).VirtualAddress - _
Sections(ExportSection).PointerToRawData
ExportBase = ExportDirectoryOffset-ExportSectionOffset
End Sub |
|
|
|
|
|
|
|
|
If you look in the IMAGE_OPTIONAL_HEADER structure, you'll see at the end a list of sixteen IMAGE_DATA_DIRECTORY structures. Each of these contains an offset to a particular type of data along with the size of that data. The first of these data directory entries refers to the export function table. How do I know this? From the PE file format specification. |
|
|
|
|
|
|
|
|
The virtual address for the export table is loaded into the ExportDirectoryOffset variable. The virtual address describes the offset to a particular block of data once the image is loaded into memory, but we need the location of the export information in the file itself. The FindExportBase function scans through the sec- |
|
|
|
|
|