๋ฆฌ๋ฒ„์‹ฑ #PE #VA #RVA 1

Reversing) PE(Portable Executable) File Format

PE File Format ? : Portable Executable File Format PE ํŒŒ์ผ์€ Windows ์šด์˜์ฒด์ œ์—์„œ ์‚ฌ์šฉ ๋˜๋Š” ์‹คํ–‰ ํŒŒ์ผ ํ˜•์‹์ด๋‹ค. Unix ๋Š” COFF ๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋งŒ๋“ค์–ด์ง Portable ์ด๋ผ๋Š” ๋‹จ์–ด๋Š” ์ด์‹์„ฑ์„ ์ข‹๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด์„œ ๋งŒ๋“ค์–ด ์ง„ ๊ฒƒ์ธ๋ฐ, ํ˜„์‹ค์€ Windows ์—์„œ๋งŒ ์“ฐ์ด๊ณ  ์žˆ๋‹ค. 32๋น„ํŠธ ํ˜•ํƒœ์˜ ์‹คํ–‰ํŒŒ์ผ์„ ์˜๋ฏธํ•˜๋ฉฐ , PE32 ๋ผ๊ณ  ๋ถˆ๋ฆฌ๊ธฐ๋„ ํ•œ๋‹ค. 64๋น„ํŠธ๋Š” PE+,PE32+ ๋ผ๊ณ  ๋ถˆ๋ฆฐ๋‹ค (PE64 ๊ฐ€ ์•„๋‹ˆ๋‹ค) 1. PE File Format ์ข…๋ฅ˜ ์ฃผ์š” ํ™•์žฅ์ž ์ข…๋ฅ˜ ์ฃผ์š” ํ™•์žฅ์ž ์‹คํ–‰๊ณ„์—ด EXE, SCR ๋“œ๋ผ์ด๋ฒ„ ๊ณ„์—ด SYS, VXD ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๊ณ„์—ด DLL,OCX,CPL,DRV ์˜ค๋ธŒ์ ํŠธ ํŒŒ์ผ ๊ณ„์—ด OBJ PE ํ—ค๋” ๋ถ€๋ถ„์— ํŒŒ์ผ์ด ์‹คํ–‰๋˜๊ธฐ ์œ„ํ•œ ๋ชจ๋“  ์ •๋ณด๋“ค์ด ์ ํ˜€..

Hacking 2020.04.12