|
|
|
|
|
|
|
tions to find the first section whose virtual address is greater than this ExportDirectoryOffset value. The section before this must contain the export table itself. |
|
|
|
|
|
|
|
|
So now we have the virtual address of the export table, the virtual address of the section that contains the export table, and the location of that section in the image file. |
|
|
|
|
|
|
|
|
The following expression can be used to calculate the location of the export table in the image file: |
|
|
|
|
|
|
|
|
ExportBase = ExportDirectoryOffset -
Sections(ExportSection).VirtualAddress +
Sections(ExportSection).PointerToRawData |
|
|
|
|
|
|
|
|
It takes the offset of the export table from the start of the section and adds it to the location of the start of the section. But this does not match the code in the FindExportBase function. Why is this? |
|
|
|
|
|
|
|
|
The code in the FindExportBase function does perform the same calculation, but rearranges the terms to first calculate a variable called ExportSectionOffset. The ExportSectionOffset variable now contains a value that can be subtracted from any virtual address in the specified section to find the corresponding location in the file. We'll be using this variable later, as many of the entries in the export table use virtual addresses as well. |
|
|
|
|
|
|
|
|
ExportSectionOffset = Sections(ExportSection).VirtualAddress - _
Sections(ExportSection).PointerToRawData
ExportBase = ExportDirectoryOffset - ExportSectionOffset |
|
|
|
|
|
|
|
|
The ExportBase variable now contains the file offset to the start of the export data. |
|
|
|
|
|
|
|
|
The export data begins with an export data directory that is defined by a structure of type IMAGE_EXPORT_DIRECTORY. This structure is defined in C as follows: |
|
|
|
|
|
|
|
|
typedef struct _IMAGE_EXPORT_DIRECTORY {
DWORD Characteristics;
DWORD TimeDateStamp;
WORD MajorVersion;
WORD MinorVersion;
DWORD Name;
DWORD Base; |
|
|
|
|
|