{"id":16,"date":"2025-12-21T22:18:11","date_gmt":"2025-12-21T14:18:11","guid":{"rendered":"http:\/\/8.210.123.186\/?p=16"},"modified":"2025-12-22T19:24:45","modified_gmt":"2025-12-22T11:24:45","slug":"pe-elf%e5%ad%a6%e4%b9%a0","status":"publish","type":"post","link":"http:\/\/8.210.123.186\/index.php\/2025\/12\/21\/pe-elf%e5%ad%a6%e4%b9%a0\/","title":{"rendered":"PE\/ELF\u5b66\u4e60"},"content":{"rendered":"\n<h1 class=\"wp-block-heading\">PE<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">\u5e38\u89c1\u540e\u7f00<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>.exe\uff0c\u53ef\u6267\u884c\u7a0b\u5e8f\uff0c\u5e38\u89c1pe\u6587\u4ef6\u7c7b\u578b\uff0c\u5305\u542b\u7a0b\u5e8f\u5165\u53e3\u70b9\u548c\u5b8c\u6574\u6267\u884c\u903b\u8f91<\/li>\n\n\n\n<li>.dll\uff0c\u52a8\u6001\u94fe\u63a5\u5e93\uff0c\u63d0\u4f9b\u53ef\u88ab\u591a\u4e2a\u7a0b\u5e8f\u5171\u4eab\u7684\u51fd\u6570\u548c\u8d44\u6e90\uff0c\u65e0\u6cd5\u76f4\u63a5\u8fd0\u884c<\/li>\n\n\n\n<li>.sys,\u7cfb\u7edf\u9a71\u52a8\u7a0b\u5e8f\uff0c\u8fd0\u884c\u4e8e\u5185\u6838\u6001\uff0c\u7528\u4e8e\u786c\u4ef6\u4ea4\u4e92\u6216\u7cfb\u7edf\u7ea7\u529f\u80fd<\/li>\n\n\n\n<li>.ocx,activex\u63a7\u4ef6\uff0c\u5f53\u7279\u6b8adll<\/li>\n\n\n\n<li>.scr\uff0c\u5c4f\u5e55\u4fdd\u62a4\u7a0b\u5e8f\uff0c\u6539\u540e\u7f00exe<\/li>\n\n\n\n<li>.cpl,\u63a7\u5236\u9762\u677f\u5c0f\u7a0b\u5e8f\uff0c\u7cfb\u7edf\u914d\u7f6e\u754c\u9762\uff0c\u5f53dll<\/li>\n\n\n\n<li>.efi\uff0c\u53ef\u6269\u5c55\u56fa\u4ef6\u63a5\u53e3\u6587\u4ef6\uff0c\u7528\u4e8eUEFI\u56fa\u4ef6\u542f\u52a8\uff0cPE\u6269\u5c55<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">PE\u6587\u4ef6\u7684\u4e24\u79cd\u72b6\u6001<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">pe\u6587\u4ef6\u5206\u4e3a\u8fd0\u884c\u6001\u548c\u975e\u8fd0\u884c\u6001<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u975e\u8fd0\u884c\u6001\uff1a\u5f53\u4e00\u4e2ape\u6587\u4ef6\u5c1a\u672a\u88ab\u8fd0\u884c\u65f6\uff0c\u6570\u636e\u5b58\u50a8\u5728\u78c1\u76d8\u4e2d<\/li>\n\n\n\n<li>\u8fd0\u884c\u6001\uff1a\u5f53\u4e00\u4e2ape\u6587\u4ef6\u88ab\u6253\u5f00\u540e\uff0cpe\u6587\u4ef6\u76f8\u5173\u6570\u636e\u5c06\u88ab\u88c5\u5728\u5230\u5185\u5b58\u4e2d<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">\u6587\u4ef6\u7ed3\u6784<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u57fa\u4e8ecoff\uff08Common Object File Format\uff09\u6269\u5c55\uff0c\u6587\u4ef6\u5934\u52a0\u8282\u533a<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PE \u6587\u4ef6\u7ed3\u6784\u6982\u89c8\u8868\uff0832\u4f4d PE32\uff09<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u7ed3\u6784\u540d\u79f0<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5bf9\u5e94 C \u6570\u636e\u7ed3\u6784<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u9ed8\u8ba4\u5360\u7528\u7a7a\u95f4 (\u5b57\u8282)<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5907\u6ce8<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>DOS MZ \u5934<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>_IMAGE_DOS_HEADER<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>64<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u56fa\u5b9a\u5927\u5c0f (0x40)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>DOS Stub<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">(\u65e0\u56fa\u5b9a\u7ed3\u6784)<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e0d\u56fa\u5b9a<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4ec5\u7528\u4e8e DOS \u63d0\u793a\uff0c\u5982\u679c\u4e0d\u8fd0\u884c\u5728 DOS \u4e0b\u53ef\u5ffd\u7565<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>PE \u6587\u4ef6\u5934 (\u603b)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>_IMAGE_NT_HEADERS<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>248<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5305\u542b\u4ee5\u4e0b\u4e09\u90e8\u5206 (4 + 20 + 224)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u251c\u2500\u2500 <strong>PE \u7b7e\u540d<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>Signature<\/code> (DWORD)<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u503c\u4e3a <code>PE\\0\\0<\/code> (0x00004550)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u251c\u2500\u2500 <strong>\u6807\u51c6 PE \u5934<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>_IMAGE_FILE_HEADER<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">20<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5305\u542b\u673a\u5668\u7c7b\u578b\u3001\u8282\u6570\u91cf\u7b49\u57fa\u7840\u4fe1\u606f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u2514\u2500\u2500 <strong>\u6269\u5c55 PE \u5934<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>_IMAGE_OPTIONAL_HEADER<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">224<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u6ce8\uff1a<\/strong> 64\u4f4d\u7a0b\u5e8f\u6b64\u5904\u4e3a 240 \u5b57\u8282<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u8282\u8868 (Section Table)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>_IMAGE_SECTION_HEADER<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>40<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u6bcf\u4e2a\u8282\u8868\u9879<\/strong>\u7684\u5927\u5c0f\u3002\u603b\u5927\u5c0f = 40 \u00d7 \u8282\u6570\u91cf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u8282\u6570\u636e (Sections)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">(\u65e0\u7279\u5b9a\u7ed3\u6784\u4f53)<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e0d\u56fa\u5b9a<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b9e\u9645\u7684\u4ee3\u7801\u3001\u6570\u636e\u3001\u8d44\u6e90\u7b49\uff0c\u5927\u5c0f\u7531\u8282\u8868\u51b3\u5b9a<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">DOS\u5934\u90e8<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u53ef\u4ee5\u5f80\u91cc\u9762\u585e\u4e1c\u897f\uff0c\u4e5f\u4e0d\u4f1a\u5f71\u54cd\u540e\u9762\u7684pe\u7ed3\u6784\uff0cDOS Header\u56fa\u5b9a64\u5b57\u8282\uff0c\u517c\u5bb9dos\u7cfb\u7edf\u6267\u884c\uff0c\u4e00\u4e2amz\u5f00\u5934\uff0c4D 5A 90 00\uff0c\u8fd8\u6709\u4e2aDOS Stub\uff0c\u5927\u5c0f\u4e0d\u56fa\u5b9a\uff0c\u901a\u5e38\u4f1a\u586b\u6ee1\u5230128\u5b57\u8282<br>\u5173\u952e\u5b57\u6bb5\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>e_magic\uff1ados\u7b7e\u540d\uff0c\u56fa\u5b9a\u4e3a0x5A4D\uff08\u5b57\u7b26\u4e32MZ\uff09<\/li>\n\n\n\n<li>e_lfanew\uff1ape\u6587\u4ef6\u5934\u504f\u79fb\u91cf\uff0832\u4f4d\u621664\u4f4d\uff09\uff0cdos\u5934\u8fc7\u6e21\u5230pe\u5934\u5173\u952e\u6307\u9488<br>\u5b9a\u4e49\u7684\u7ed3\u6784\u4f53\u4f4d\u4e3a\uff0c\u5b9a\u4e49\u4e8ewinnt.h<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct _IMAGE_DOS_HEADER {      \/\/ DOS .EXE \u5934\u90e8\u7ed3\u6784\u4f53\n\n    \/\/ --- \u6838\u5fc3\u6807\u8bc6 ---\n    WORD   e_magic;                     \/\/ &#91;0x00] \u9b54\u6570 (Magic number)\uff0c\u56fa\u5b9a\u4e3a \"MZ\"\n\n    \/\/ --- DOS \u7a0b\u5e8f\u52a0\u8f7d\u4fe1\u606f (\u73b0\u4ee3 Windows \u901a\u5e38\u5ffd\u7565) ---\n    WORD   e_cblp;                      \/\/ &#91;0x02] \u6587\u4ef6\u6700\u540e\u4e00\u9875\u7684\u5b57\u8282\u6570\n    WORD   e_cp;                        \/\/ &#91;0x04] \u6587\u4ef6\u603b\u9875\u6570\n    WORD   e_crlc;                      \/\/ &#91;0x06] \u91cd\u5b9a\u4f4d\u9879\u7684\u6570\u91cf\n    WORD   e_cparhdr;                   \/\/ &#91;0x08] \u5934\u90e8\u5927\u5c0f (\u4ee5\u6bb5\/Paragraph\u4e3a\u5355\u4f4d)\n    WORD   e_minalloc;                  \/\/ &#91;0x0A] \u6240\u9700\u7684\u6700\u5c0f\u9644\u52a0\u6bb5\u6570\n    WORD   e_maxalloc;                  \/\/ &#91;0x0C] \u6240\u9700\u7684\u6700\u5927\u9644\u52a0\u6bb5\u6570\n    WORD   e_ss;                        \/\/ &#91;0x0E] \u521d\u59cb SS (\u5806\u6808\u6bb5) \u76f8\u5bf9\u503c\n    WORD   e_sp;                        \/\/ &#91;0x10] \u521d\u59cb SP (\u5806\u6808\u6307\u9488) \u503c\n    WORD   e_csum;                      \/\/ &#91;0x12] \u6821\u9a8c\u548c\n    WORD   e_ip;                        \/\/ &#91;0x14] \u521d\u59cb IP (\u6307\u4ee4\u6307\u9488) \u503c\n    WORD   e_cs;                        \/\/ &#91;0x16] \u521d\u59cb CS (\u4ee3\u7801\u6bb5) \u76f8\u5bf9\u503c\n    WORD   e_lfarlc;                    \/\/ &#91;0x18] \u91cd\u5b9a\u4f4d\u8868\u5728\u6587\u4ef6\u4e2d\u7684\u5730\u5740\n    WORD   e_ovno;                      \/\/ &#91;0x1A] \u8986\u76d6\u53f7 (Overlay number)\n\n    \/\/ --- \u4fdd\u7559\u53ca OEM \u5b57\u6bb5 ---\n    WORD   e_res&#91;4];                    \/\/ &#91;0x1C] \u4fdd\u7559\u5b57\u6bb5 (4\u4e2a\u5b57)\n    WORD   e_oemid;                     \/\/ &#91;0x24] OEM \u6807\u8bc6\u7b26 (\u7528\u4e8e e_oeminfo)\n    WORD   e_oeminfo;                   \/\/ &#91;0x26] OEM \u4fe1\u606f (\u5177\u4f53\u7531 e_oemid \u5b9a\u4e49)\n    WORD   e_res2&#91;10];                  \/\/ &#91;0x28] \u4fdd\u7559\u5b57\u6bb5 (10\u4e2a\u5b57)\n\n    \/\/ --- PE \u5934\u90e8\u6307\u9488 (\u6838\u5fc3\u5b57\u6bb5) ---\n    LONG   e_lfanew;                    \/\/ &#91;0x3C] \u65b0 EXE \u5934\u90e8 (PE Header) \u7684\u6587\u4ef6\u5730\u5740\n\n} IMAGE_DOS_HEADER, *PIMAGE_DOS_HEADER;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u7ed3\u6784\u4f53\u5b9a\u4e49<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct _IMAGE_DOS_HEADER {\n    WORD   e_magic;      \/\/ 0x00: \u9b54\u6570 \"MZ\" (4D 5A)\n    WORD   e_cblp;       \/\/ 0x02\n    \/\/ ......\n    LONG   e_lfanew;     \/\/ 0x3C: \u6307\u5411 PE \u5934\u7684\u504f\u79fb\u91cf (\u8fd9\u662f\u7ed3\u6784\u4f53\u7684\u6700\u540e\u4e00\u4e2a\u6210\u5458)\n} IMAGE_DOS_HEADER, *PIMAGE_DOS_HEADER;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd8\u6709\u81ea\u5199\u4ee3\u7801\u8bfb\u53d6dos mz\u5934\u5417\uff0c\u5413\u54ed\u4e86<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ PE.cpp : Defines the entry point for the console application.\n\/\/\n\n#include \"stdafx.h\"\n\n#include &lt;malloc.h&gt;\n#include &lt;windows.h&gt;\n\nint main(int argc, char* argv&#91;])\n{\n    \/\/\u521b\u5efaDOS\u5bf9\u5e94\u7684\u7ed3\u6784\u4f53\u6307\u9488\n        _IMAGE_DOS_HEADER* dos;\n    \/\/\u8bfb\u53d6\u6587\u4ef6\uff0c\u8fd4\u56de\u6587\u4ef6\u53e5\u67c4\n        HANDLE hFile = CreateFileA(\"C:\\\\Documents and Settings\\\\Administrator\\\\\u684c\u9762\\\\dbghelp.dll\",GENERIC_READ,FILE_SHARE_READ,NULL,OPEN_EXISTING,0,0);\n    \/\/\u6839\u636e\u6587\u4ef6\u53e5\u67c4\u521b\u5efa\u6620\u5c04\n        HANDLE hMap = CreateFileMappingA(hFile,NULL,PAGE_READONLY,0,0,0);\n    \/\/\u6620\u5c04\u5185\u5bb9\n        LPVOID pFile = MapViewOfFile(hMap,FILE_MAP_READ,0,0,0);\n    \/\/\u7c7b\u578b\u8f6c\u6362\uff0c\u7528\u7ed3\u6784\u4f53\u7684\u65b9\u5f0f\u6765\u8bfb\u53d6\n        dos=(_IMAGE_DOS_HEADER*)pFile;\n    \/\/\u8f93\u51fa\u7ed3\u6784\u4f53\u7684\u7b2c\u4e00\u4e2a\u6210\u5458\uff0c\u4ee5\u5341\u516d\u8fdb\u5236\u8f93\u51fa\n        printf(\"%X\\n\",dos-&gt;e_magic);\n        return 0;\n}<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">PE\u5934<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u524d\u56db\u4e2a\u5b57\u8282 50 45 00 00pe\u6807\u8bc6,20\u4e2a\u5b57\u8282\u6807\u51c6pe\u5934\uff0c\u6269\u5c55pe\u5934\u770b\u7ed3\u6784\u4f53\uff0c\u6709\u54ea\u4e9b\uff0c\u7136\u540e\u4e4b\u540e\u6587\u4ef6\u5bf9\u9f50\u4e4b\u540e\u7684\u5927\u5c0f\uff0c\u5934\u7684\u5927\u5c0f\u4e00\u5b9a\u662f\u6587\u4ef6\u500d\u6570<br>32\u4f4d\u7ed3\u6784\u4f53<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct _IMAGE_NT_HEADERS {\n    DWORD Signature;                            \/\/PE\u6587\u4ef6\u5934\u6807\u8bc6\n    IMAGE_FILE_HEADER FileHeader;               \/\/\u6807\u51c6PE\u5934\n    IMAGE_OPTIONAL_HEADER32 OptionalHeader;     \/\/\u6269\u5c55PE\u5934 32\u4f4d\n} IMAGE_NT_HEADERS32, *PIMAGE_NT_HEADERS32;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">64\u4f4d\u7ed3\u6784\u4f53<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct _IMAGE_NT_HEADERS64 {\n    DWORD Signature;                            \/\/PE\u6587\u4ef6\u5934\u6807\u8bc6\n    IMAGE_FILE_HEADER FileHeader;               \/\/\u6807\u51c6PE\u5934 \n    IMAGE_OPTIONAL_HEADER64 OptionalHeader;     \/\/\u6269\u5c55PE\u5934 64\u4f4d\n} IMAGE_NT_HEADERS64, *PIMAGE_NT_HEADERS64;<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">PE\u7b7e\u540d<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u7c7b\u578b\u4e3adword\uff0c\u5b58\u50a8\u5728signature\u53d8\u91cf\u4e2d<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\u6807\u51c6PE\u5934\uff08IMAGE_FILE_HEADER\uff09\uff08\u53c8\u79f0coff\u6587\u4ef6\u5934\uff09<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u7ed3\u6784\u4f53<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct _IMAGE_FILE_HEADER {\n    WORD    Machine;\/\/\u53ef\u4ee5\u8fd0\u884c\u5728\u4ec0\u4e48\u6837\u7684CPU\u4e0a\uff0c\u5982\u679c\u5b83\u7684\u503c\u4e3a0x0\u5219\u8868\u793a\u53ef\u4ee5\u8fd0\u884c\u5728\u4efb\u610f\u7684CPU\u4e0a\uff0c\u652f\u6301\u5728Intel 386\u4ee5\u53ca\u540e\u7eed\u7684\u578b\u53f7CPU\u8fd0\u884c\u5219\u503c\u4e3a0x14c\uff0c\u652f\u630164\u4f4d\u7684CPU\u578b\u53f7\u5219\u503c\u4e3a0x8664\u3002\u6570\u636e\u5bbd\u5ea6word2\u5b57\u8282\uff0c\u7a0b\u5e8f\u652f\u6301\u7684cpu\n    WORD    NumberOfSections;\/\/\u8868\u793a\u8282\u7684\u6570\u91cf\uff0c\u4e5f\u5c31\u662f\u8282\u8868\u4e2d\u6709\u51e0\u4e2a\u7ed3\u6784\u4f53\uff0cword2\u5b57\u8282\uff0c\u4e0d\u5927\u4e8e96\n    DWORD   TimeDateStamp;\/\/\u7f16\u8bd1\u5668\u586b\u5199\u7684\u65f6\u95f4\u6233 \u4e0e\u6587\u4ef6\u5c5e\u6027\u91cc\u9762(\u521b\u5efa\u65f6\u95f4\u3001\u4fee\u6539\u65f6\u95f4)\u65e0\u5173\uff0cdword4\u5b57\u8282\n    DWORD   PointerToSymbolTable;\/\/\u8c03\u8bd5\u76f8\u5173\uff0c\u6307\u5411\u7b26\u53f7\u8868\uff0cdword4\u5b57\u8282\n    DWORD   NumberOfSymbols;\/\/\u8c03\u8bd5\u76f8\u5173\uff0c\u7b26\u53f7\u8868\u4e2d\u7684\u7b26\u53f7\u4e2a\u6570\uff0cdword4\u5b57\u8282\n    WORD    SizeOfOptionalHeader;\/\/\u53ef\u9009PE\u5934\u7684\u5927\u5c0f(32\u4f4dPE\u6587\u4ef6\uff1a0xE0  64\u4f4dPE\u6587\u4ef6\uff1a0xF0)word2\u5b57\u8282\n    WORD    Characteristics;\/\/\u6587\u4ef6\u5c5e\u6027\uff0c\u6570\u636e\u4f4d\u62fc\u63a5\u800c\u6210\uff0cword2\u5b57\u8282\n} IMAGE_FILE_HEADER, *PIMAGE_FILE_HEADER;<\/code><\/pre>\n\n\n\n<h5 class=\"wp-block-heading\">Machine<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">IMAGE_FILE_MACHINE \u5e38\u91cf\u5bf9\u7167\u8868<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u8fd4\u56de\u7684\u5e38\u91cf (Constant)<\/th><th class=\"has-text-align-left\" data-align=\"left\">Value (Hex)<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8bf4\u660e (Description)<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_UNKNOWN<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x0<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5047\u5b9a\u6b64\u5b57\u6bb5\u7684\u5185\u5bb9\u9002\u7528\u4e8e\u4efb\u4f55\u8ba1\u7b97\u673a\u7c7b\u578b<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_AM33<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1d3<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u677e\u7530 (Matsushita) AM33<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_AMD64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x8664<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>x64 (AMD64 \u6216 Intel 64)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_ARM<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1c0<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">ARM \u5c0f\u7aef\u5e8f (Little Endian)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_ARM64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0xaa64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">ARM64 \u5c0f\u7aef\u5e8f (Little Endian)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_ARMNT<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1c4<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">ARM Thumb-2 \u5c0f\u7aef\u5e8f (Little Endian)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_EBC<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0xebc<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">EFI \u5b57\u8282\u4ee3\u7801 (EFI Byte Code)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_I386<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x14c<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>Intel 386 \u6216\u66f4\u9ad8\u7248\u672c\u7684\u5904\u7406\u5668 (x86 32\u4f4d)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_IA64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x200<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Intel Itanium \u5904\u7406\u5668\u7cfb\u5217<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_LOONGARCH32<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x6232<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">LoongArch 32 \u4f4d\u5904\u7406\u5668\u7cfb\u5217 (\u9f99\u82af)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_LOONGARCH64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x6264<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">LoongArch 64 \u4f4d\u5904\u7406\u5668\u7cfb\u5217 (\u9f99\u82af)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_M32R<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x9041<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e09\u83f1 M32R \u5c0f\u7aef\u5e8f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_MIPS16<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x266<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">MIPS16<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_MIPSFPU<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x366<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4f7f\u7528 FPU \u7684 MIPS<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_MIPSFPU16<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x466<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5177\u6709 FPU \u7684 MIPS16<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_POWERPC<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1f0<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">PowerPC \u5c0f\u7aef\u5e8f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_POWERPCFP<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1f1<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u652f\u6301\u6d6e\u70b9\u8fd0\u7b97\u7684 PowerPC<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_R4000<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x166<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">MIPS \u5c0f\u7aef\u5e8f (\u901a\u5e38\u6307 R4000)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_RISCV32<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x5032<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">RISC-V 32 \u4f4d\u5730\u5740\u7a7a\u95f4<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_RISCV64<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x5064<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">RISC-V 64 \u4f4d\u5730\u5740\u7a7a\u95f4<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_RISCV128<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x5128<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">RISC-V 128 \u4f4d\u5730\u5740\u7a7a\u95f4<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_SH3<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1a2<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Hitachi SH3<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_SH3DSP<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1a3<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Hitachi SH3 DSP<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_SH4<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1a6<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Hitachi SH4<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_SH5<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1a8<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Hitachi SH5<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_THUMB<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x1c2<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">Thumb<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_MACHINE_WCEMIPSV2<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x169<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">MIPS \u5c0f\u7aef WCE v2<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">\u5e38\u89c1\uff1a<\/td><td class=\"has-text-align-left\" data-align=\"left\"><\/td><td class=\"has-text-align-left\" data-align=\"left\"><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<ol class=\"wp-block-list\">\n<li>0x014C (I386)\uff1a\u4ee3\u8868 32\u4f4d\u7a0b\u5e8f\u3002<\/li>\n\n\n\n<li>0x8664 (AMD64)\uff1a\u4ee3\u8868 64\u4f4d \u7a0b\u5e8f\u3002<\/li>\n<\/ol>\n\n\n\n<h5 class=\"wp-block-heading\">NumberOfSections<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">machine\u540e\u9762\u7684\u4e24\u4e2a\u5b57\u8282\uff0c\u8bf4\u660e\u533a\u6bb5\u6570\u91cf<br>\u533a\u6bb5\uff1a\u64cd\u4f5c\u7cfb\u7edf\u52a0\u8f7d\u7a0b\u5e8f\u65f6\uff0c\u6839\u636e\u5185\u5b58\u5c5e\u6027\uff08\u6743\u9650\uff09\u6765\u7ba1\u7406\uff0c\u5e38\u89c1\u533a\u6bb5<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>.text\u6216.code\uff0c\u6307\u4ee4\u4ee3\u7801\uff0c\u53ef\u8bfb\uff0c\u53ef\u6267\u884c<\/li>\n\n\n\n<li>.data\uff0c\u5df2\u7ecf\u521d\u59cb\u5316\u7684\u5168\u5c40\u53d8\u91cf\uff0c\u53ef\u8bfb\uff0c\u53ef\u5199<\/li>\n\n\n\n<li>.rdata\u6216.idata\uff0c\u5b58\u653e\u5e38\u91cf\uff08const\u6216\u8005\u5b57\u7b26\u4e32\uff09\uff0c\u5bfc\u5165\u8868\uff08\u8c03\u7528\u4e86\u54ea\u4e9bapi\uff09\uff0c\u53ea\u8bfb<\/li>\n\n\n\n<li>.rsrc\uff0c\u5b58\u653e\u7684\u7a0b\u5e8f\u7684ui\u8d44\u6e90\uff0c\u53ea\u8bfb<\/li>\n\n\n\n<li>.reloc\uff0c\u91cd\u5b9a\u4f4d\uff0c\u5982\u679c\u7a0b\u5e8f\u4e0d\u80fd\u5728\u9884\u671f\u7684\u5185\u5b58\u5730\u5740\uff08\u57fa\u5740\uff09\u52a0\u8f7d\uff0c\u8981\u4fee\u6b63\u65f6\u7528\u7684\u6570\u636e\uff0c\u6bd4\u5982\u5f00\u542f\u4e86ASLR\uff08\u968f\u673a\u57fa\u5740\u7684\uff09\u7684\u7a0b\u5e8f\u8981\u7528<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">SizeOfOptionalHeader<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u8868\u793a\u53ef\u9009\u6807\u5934\u5927\u5c0f\uff0c\u53ef\u6267\u884c\u6587\u4ef6\u5fc5\u9700<br>\u8f6c\u6362\u4e3a\u5341\u8fdb\u5236\u5c31\u662f\u5927\u5c0f,SizeOfOptionalHeader\u53d8\u91cf\u4e2d\u7684\u6570\u636e\u5bf9\u4e8e32\u4f4dPE\u6587\u4ef6\u901a\u5e38\u4e3a00E0h\uff0c\u5bf9\u4e8e64\u4f4dPE\u6587\u4ef6\u901a\u5e38\u4e3a00F0h\u3002\u8fd9\u91cc\u7684h\u662f\u7528\u6765\u8868\u793a\u8fd9\u4e2a\u6570\u636e\u4e3a16\u8fdb\u5236\u3002\u4e0a\u56fe\u6211\u4eec\u53ef\u4ee5\u770b\u5230SizeOfOptionalHeader\u53d8\u91cf\u5f53\u4e2d\u7684\u6570\u636e\u4e3a00 E0\uff0c\u6269\u5c55PE\u5934\u5927\u5c0f\u4e3a224\uff0c\u6587\u4ef6\u4e3a32\u4f4dPE\u6587\u4ef6\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Characteristics<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u770b\u6700\u540e\u4e24\u4e2a\u5b57\u8282\uff0c\u8f6c\u6362\u4e3a\u4e8c\u8fdb\u5236\uff0c\u7136\u540e\u5bf9\u5e94\u76841\u7684\u542b\u4e49\u5728\u4e0b\u8868<br>IMAGE_FILE_HEADER &#8211; Characteristics \u5b57\u6bb5\u8be6\u89e3<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-center\" data-align=\"center\">\u6570\u636e\u4f4d (Bit)<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5e38\u91cf\u7b26\u53f7 (Constant)<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u4e3a 1 \u65f6\u7684\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>0<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_RELOCS_STRIPPED<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u4e2d\u4e0d\u5b58\u5728\u91cd\u5b9a\u4f4d\u4fe1\u606f<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>1<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_EXECUTABLE_IMAGE<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u662f\u53ef\u6267\u884c\u7684<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>2<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_LINE_NUMS_STRIPPED<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u5b58\u5728\u884c\u4fe1\u606f<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>3<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_LOCAL_SYMS_STRIPPED<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u5b58\u5728\u7b26\u53f7\u4fe1\u606f<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>4<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_AGGRESSIVE_WS_TRIM<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8c03\u6574\u5de5\u4f5c\u96c6<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>5<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_LARGE_ADDRESS_AWARE<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5e94\u7528\u7a0b\u5e8f\u53ef\u5904\u7406\u5927\u4e8e 2GB \u7684\u5730\u5740<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>6<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">(\u4fdd\u7559)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6b64\u6807\u5fd7\u4fdd\u7559<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>7<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_BYTES_REVERSED_LO<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5c0f\u5c3e\u65b9\u5f0f (Little Endian)<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_32BIT_MACHINE<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u53ea\u5728 32 \u4f4d\u5e73\u53f0\u4e0a\u8fd0\u884c<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>9<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_DEBUG_STRIPPED<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u5305\u542b\u8c03\u8bd5\u4fe1\u606f<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>10<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u80fd\u4ece\u53ef\u79fb\u52a8\u76d8\u8fd0\u884c (\u9700\u590d\u5236\u5230\u4ea4\u6362\u6587\u4ef6)<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>11<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_NET_RUN_FROM_SWAP<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u80fd\u4ece\u7f51\u7edc\u8fd0\u884c (\u9700\u590d\u5236\u5230\u4ea4\u6362\u6587\u4ef6)<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>12<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_SYSTEM<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7cfb\u7edf\u6587\u4ef6\uff08\u5982\u9a71\u52a8\u7a0b\u5e8f\uff09\uff0c\u4e0d\u80fd\u76f4\u63a5\u8fd0\u884c<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>13<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_DLL<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8fd9\u662f\u4e00\u4e2a DLL \u6587\u4ef6<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>14<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_UP_SYSTEM_ONLY<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u4e0d\u80fd\u5728\u591a\u5904\u7406\u5668\u8ba1\u7b97\u673a\u4e0a\u8fd0\u884c<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\"><strong>15<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>IMAGE_FILE_BYTES_REVERSED_HI<\/code><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5927\u5c3e\u65b9\u5f0f (Big Endian)<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h4 class=\"wp-block-heading\">\u6269\u5c55PE\u5934<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u6807\u51c6PE\u5934\u4e2d\u7684SizeOfOptionalHeader\u7528\u4e8e\u6807\u8bc6\u6269\u5c55PE\u5934\u7684\u5927\u5c0f\uff0c\u5927\u5c0f\u4e0d\u56fa\u5b9a\uff0c\u6bcf\u4e2ape\u6587\u4ef6\u90fd\u6709\u4e00\u4e2a\u6269\u5c55pe\u5934\uff0c\u7528\u4e8e\u5411\u52a0\u8f7d\u7a0b\u5e8f\u63d0\u4f9b\u4fe1\u606f<br>\u6709\u6807\u5934magic\u7f16\u53f7\u4fdd\u8bc1\u683c\u5f0f\u517c\u5bb9\u6027\uff0c\u53ef\u9009\u7684\u6807\u5934magic\u7528\u4e8e\u786e\u5b9ape\u6587\u4ef6\u662fpe32\u8fd8\u662fre32+\u53ef\u6267\u884c\u6587\u4ef6<br>\u53ef\u9009\u6807\u5934\uff0c\u6bcf\u4e2a\u6620\u50cf\u6587\u4ef6\u90fd\u6709\u4e00\u4e2a\u7528\u4e8e\u5411\u52a0\u8f7d\u7a0b\u5e8f\u63d0\u4f9b\u4fe1\u606f\u7684\u53ef\u9009\u6807\u5934\u3002 \u6b64\u6807\u5934\u662f\u53ef\u9009\u6807\u5934\uff0c\u56e0\u4e3a\u67d0\u4e9b\u6587\u4ef6\uff08\u7279\u522b\u662f\u5bf9\u8c61\u6587\u4ef6\uff09\u6ca1\u6709\u6b64\u6807\u5934\u3002 \u5bf9\u4e8e\u6620\u50cf\u6587\u4ef6\uff0c\u6b64\u6807\u5934\u662f\u5fc5\u9700\u7684\u3002 \u5bf9\u8c61\u6587\u4ef6\u53ef\u4ee5\u5177\u6709\u53ef\u9009\u6807\u5934\uff0c\u4f46\u901a\u5e38\u6b64\u6807\u5934\u5728\u5bf9\u8c61\u6587\u4ef6\u4e2d\u6ca1\u6709\u51fd\u6570\uff0c\u53ea\u662f\u4e3a\u4e86\u589e\u52a0\u5176\u5927\u5c0f\u3002\u53ef\u9009\u6807\u5934\u7684\u5927\u5c0f\u4e0d\u662f\u56fa\u5b9a\u7684\u3002 COFF \u6807\u5934\u4e2d\u7684 SizeOfOptionalHeader \u5b57\u6bb5\u5fc5\u987b\u7528\u4e8e\u9a8c\u8bc1\u5bf9\u7279\u5b9a\u6570\u636e\u76ee\u5f55\u7684\u6587\u4ef6\u7684\u63a2\u6d4b\u662f\u5426\u672a\u8d85\u51fa SizeOfOptionalHeader\u3002<br>\u8fd8\u5e94\u8be5\u4f7f\u7528\u53ef\u9009\u6807\u5934\u7684 NumberOfRvaAndSizes \u5b57\u6bb5\u6765\u786e\u4fdd\u5bf9\u7279\u5b9a\u6570\u636e\u76ee\u5f55\u6761\u76ee\u7684\u63a2\u6d4b\u4e0d\u4f1a\u8d85\u51fa\u53ef\u9009\u6807\u5934\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u53ef\u9009\u6807\u5934\u5e7b\u6570\u786e\u5b9a\u6620\u50cf\u662f PE32 \u8fd8\u662f PE32+ \u53ef\u6267\u884c\u6587\u4ef6\u3002<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u6620\u5c04\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5750\u6807\u7cfb\u53d8\u5316\uff0c\u504f\u79fb\u53d8\u6210\u5730\u5740\uff08FOA\u53d8\u6210VA\uff09\uff0cfoa\uff0c\u76f8\u5bf9\u4e8e\u6587\u4ef6\u5f00\u5934\u7684\u8ddd\u79bb\uff0c\u865a\u62df\u5730\u5740 (VA) = \u57fa\u5740 (Image Base) + RVA\uff0c\u56e0\u4e3acpu\u6267\u884c\u6307\u4ee4\u9700\u8981\u5185\u5b58\u4e2d\u7684\u7edd\u5bf9\u5730\u5740<\/li>\n\n\n\n<li>\u8d4b\u4e88\u6743\u9650\uff0c\u6620\u5c04text\u6bb5\u6216\u8005data\u6bb5\u8fd9\u4e9b\uff0c\u8ba9\u4ed6\u4eec\u53d8\u5f97\u4e0d\u53ef\u5199\u4e4b\u7c7b\u7684<\/li>\n\n\n\n<li>\u52a8\u6001\u4fee\u6b63\uff0c\u91cd\u5b9a\u4f4d\uff0c\u627e\u5230\u8c03\u7528\u4e1c\u897f\u7684\u771f\u5b9e\u5730\u5740<\/li>\n<\/ol>\n\n\n\n<h5 class=\"wp-block-heading\">1. 32\u4f4d\u4e0e64\u4f4d\u7ed3\u6784\u4f53\u5bf9\u6bd4<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">64\u4f4d\u76f8\u6bd4\u4e8e32\u4f4d\u533a\u522b\u5e76\u4e0d\u5927\uff0c\u4e3b\u8981\u662f\u5220\u53bb\u4e86\u4e00\u4e2a\u6210\u5458\uff08BaseOfData\uff09\uff0c\u4ee5\u53ca\u4e94\u4e2a\u6210\u5458\u7684\u6570\u636e\u7c7b\u578b\u7531 <code>DWORD<\/code> \u53d8\u4e3a <code>ULONGLONG<\/code>\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u6210\u5458<\/th><th class=\"has-text-align-left\" data-align=\"left\">32\u4f4d\u7c7b\u578b<\/th><th class=\"has-text-align-left\" data-align=\"left\">64\u4f4d\u7c7b\u578b<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>BaseOfData<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u65e0\u6b64\u6210\u5458<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u6bb5\u57fa\u5740\uff0864\u4f4d\u79fb\u9664\uff09<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>ImageBase<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ULONGLONG<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5185\u5b58\u955c\u50cf\u57fa\u5740<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfStackReserve<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ULONGLONG<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6808\u4fdd\u7559\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfStackCommit<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ULONGLONG<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6808\u63d0\u4ea4\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfHeapReserve<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ULONGLONG<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5806\u4fdd\u7559\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfHeapCommit<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ULONGLONG<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5806\u63d0\u4ea4\u5927\u5c0f<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>\u6ce8<\/strong>\uff1a\u56e0\u533a\u522b\u4e0d\u660e\u663e\uff0c\u4ee5\u4e0b\u5206\u6790\u4ee5 <strong>32\u4f4d\u7ed3\u6784\u4f53<\/strong> \u4e3a\u4f8b\u3002<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">32\u4f4d\u6269\u5c55 PE \u5934\u6210\u5458\u6982\u89c8<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u6269\u5c55 PE \u5934\u6210\u5458\u8f83\u591a\uff0c\u52a0\u7c97\u662f\u91cd\u70b9<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u6210\u5458<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u5bbd\u5ea6<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Magic<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u955c\u50cf\u6587\u4ef6\u7684\u72b6\u6001\uff0c\u53ef\u7528\u4e8e\u5224\u65ad\u7a0b\u5e8f\u662f32\u4f4d\u8fd8\u662f64\u4f4d<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MajorLinkerVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">BYTE (1\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u94fe\u63a5\u5668\u7684\u4e3b\u8981\u7248\u672c\u53f7<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MinorLinkerVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">BYTE (1\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u94fe\u63a5\u5668\u7684\u6b21\u8981\u7248\u672c\u53f7<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfCode<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4ee3\u7801\u6bb5\u7684\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfInitializedData<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u521d\u59cb\u5316\u6570\u636e\u6bb5\u7684\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfUninitializedData<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u672a\u521d\u59cb\u5316\u6570\u636e\u6bb5\u7684\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>AddressOfEntryPoint<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7a0b\u5e8f\u5165\u53e3 (OEP)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">BaseOfCode<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4ee3\u7801\u5f00\u59cb\u7684\u57fa\u5740<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>BaseOfData<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u5f00\u59cb\u7684\u57fa\u5740<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>ImageBase<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5185\u5b58\u955c\u50cf\u57fa\u5740<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SectionAlignment<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5185\u5b58\u5bf9\u9f50<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>FileAlignment<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u5bf9\u9f50<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MajorOperatingSystemVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6807\u8bc6\u64cd\u4f5c\u7cfb\u7edf\u7248\u672c\u53f7 (\u4e3b)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MinorOperatingSystemVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6807\u8bc6\u64cd\u4f5c\u7cfb\u7edf\u7248\u672c\u53f7 (\u6b21)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MajorImageVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">PE\u6587\u4ef6\u81ea\u8eab\u7684\u7248\u672c\u53f7 (\u4e3b)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MinorImageVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">PE\u6587\u4ef6\u81ea\u8eab\u7684\u7248\u672c\u53f7 (\u6b21)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MajorSubsystemVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8fd0\u884c\u6240\u9700\u5b50\u7cfb\u7edf\u7248\u672c\u53f7 (\u4e3b)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">MinorSubsystemVersion<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8fd0\u884c\u6240\u9700\u5b50\u7cfb\u7edf\u7248\u672c\u53f7 (\u6b21)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Win32VersionValue<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b50\u7cfb\u7edf\u7248\u672c\u7684\u503c\uff0c\u5fc5\u987b\u4e3a0<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfImage<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">Image\u5927\u5c0f (\u5185\u5b58\u4e2d)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>SizeOfHeaders<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6240\u6709\u5934+\u8282\u8868\u6309\u7167\u6587\u4ef6\u5bf9\u9f50\u540e\u7684\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">CheckSum<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6821\u9a8c\u548c<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">Subsystem<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b50\u7cfb\u7edf\u7c7b\u578b<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">DllCharacteristics<\/td><td class=\"has-text-align-left\" data-align=\"left\">WORD (2\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u7279\u6027 (\u4e0d\u53ea\u662f\u9488\u5bf9DLL)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfStackReserve<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u521d\u59cb\u5316\u65f6\u4fdd\u7559\u7684\u6808\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfStackCommit<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u521d\u59cb\u5316\u65f6\u5b9e\u9645\u63d0\u4ea4\u7684\u6808\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfHeapReserve<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u521d\u59cb\u5316\u65f6\u4fdd\u7559\u7684\u5806\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">SizeOfHeapCommit<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u521d\u59cb\u5316\u65f6\u5b9e\u9645\u63d0\u4ea4\u7684\u5806\u5927\u5c0f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">LoaderFlags<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8c03\u8bd5\u76f8\u5173 (\u5df2\u8fc7\u65f6)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">NumberOfRvaAndSizes<\/td><td class=\"has-text-align-left\" data-align=\"left\">DWORD (4\u5b57\u8282)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u76ee\u5f55\u9879\u6570\u76ee<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>DataDirectory[16]<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7ed3\u6784\u4f53\u6570\u7ec4<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u76ee\u5f55\u8868\uff0c\u6307\u5411\u5bfc\u51fa\u8868\u3001\u5bfc\u5165\u8868\u7b49<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Magic<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u955c\u50cf\u6587\u4ef6\u7684\u72b6\u6001\uff0c\u7528\u4e8e\u533a\u5206 PE \u6587\u4ef6\u7684\u7c7b\u578b\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u5b8f\u5b9a\u4e49<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u503c<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_NT_OPTIONAL_HDR32_MAGIC<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>0x10b<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">32\u4f4d\u53ef\u6267\u884c\u6620\u50cf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_NT_OPTIONAL_HDR64_MAGIC<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>0x20b<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">64\u4f4d\u53ef\u6267\u884c\u6620\u50cf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_ROM_OPTIONAL_HDR_MAGIC<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>0x107<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">ROM \u955c\u50cf<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">\u7248\u672c\u53f7\u4e0e\u6bb5\u5927\u5c0f<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>MajorLinkerVersion \/ MinorLinkerVersion<\/strong>: \u94fe\u63a5\u5668\u7248\u672c\u53f7\u3002<\/li>\n\n\n\n<li><strong>SizeOfCode \/ SizeOfInitializedData \/ SizeOfUninitializedData<\/strong>: \u5206\u522b\u4e3a\u4ee3\u7801\u6bb5\u3001\u521d\u59cb\u5316\u6570\u636e\u6bb5\u3001\u672a\u521d\u59cb\u5316\u6570\u636e\u6bb5\u7684\u5927\u5c0f\u3002<br>\u8fd9\u4e9b\u503c\u662f\u6587\u4ef6\u5bf9\u9f50\u540e\u7684\u5927\u5c0f\uff0c\u7531\u7f16\u8bd1\u5668\u586b\u5199\uff0c\u4e0d\u4e00\u5b9a\u51c6\u786e<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">AddressOfEntryPoint (OEP)<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6307\u5411\u5165\u53e3\u70b9\u51fd\u6570\u7684\u6307\u9488\uff0c\u662f\u76f8\u5bf9\u4e8e ImageBase \u7684\u504f\u79fb\uff08RVA\uff09\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e8e\u53ef\u6267\u884c\u6587\u4ef6\uff1a\u7a0b\u5e8f\u7684\u8d77\u59cb\u6267\u884c\u5730\u5740\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e8e\u9a71\u52a8\u7a0b\u5e8f\uff1a\u521d\u59cb\u5316\u51fd\u6570\u7684\u5730\u5740\u3002<\/li>\n\n\n\n<li>\u5bf9\u4e8e DLL\uff1a\u53ef\u9009\uff0c\u82e5\u65e0\u5165\u53e3\u70b9\u5219\u4e3a 0\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">BaseOfCode \/ BaseOfData<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6307\u5411\u4ee3\u7801\u6bb5\/\u6570\u636e\u6bb5\u5f00\u5934\u7684\u6307\u9488\uff08RVA\uff09\u3002<br>\u6ce8: \u7f16\u8bd1\u5668\u586b\u5199\uff0c<strong>\u4e0d\u4e00\u5b9a\u51c6\u786e<\/strong>\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">ImageBase<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">Image (PE\u6587\u4ef6) \u8f7d\u5165\u5185\u5b58\u65f6\u7b2c\u4e00\u4e2a\u5b57\u8282\u7684\u9996\u9009\u5730\u5740\uff08\u57fa\u5740\uff09\u3002\u8be5\u503c\u901a\u5e38\u662f 64K \u7684\u500d\u6570\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u7c7b\u578b<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u9ed8\u8ba4\u503c<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>DLL<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x10000000<\/code><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5e94\u7528\u7a0b\u5e8f (EXE)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x00400000<\/code><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Windows CE<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><code>0x00010000<\/code><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">Alignment (\u5bf9\u9f50)<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SectionAlignment<\/strong>: \u5185\u5b58\u4e2d\u7684\u8282\u5bf9\u9f50\u5927\u5c0f\u3002\u9ed8\u8ba4\u662f\u7cfb\u7edf\u9875\u9762\u5927\u5c0f\u3002<\/li>\n\n\n\n<li><strong>FileAlignment<\/strong>: \u6587\u4ef6\u4e2d\u7684\u8282\u5bf9\u9f50\u5927\u5c0f\u3002\u901a\u5e38\u4e3a 512 (0x200) \u5230 64K \u4e4b\u95f4\u76842\u7684\u5e42\u3002<br>\u89c4\u5219: <code>SectionAlignment<\/code> \u5fc5\u987b\u5927\u4e8e\u6216\u7b49\u4e8e <code>FileAlignment<\/code>\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">SizeOfImage<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u5185\u5b58\u4e2d\u6574\u4e2a PE \u6587\u4ef6\u7684\u6620\u5c04\u5c3a\u5bf8\u3002<\/li>\n\n\n\n<li>\u5927\u5c0f\u5305\u62ec\u6240\u6709\u5934\u548c\u8282\u3002<\/li>\n\n\n\n<li>\u5fc5\u987b\u662f <code>SectionAlignment<\/code> \u7684\u6574\u6570\u500d\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">SizeOfHeaders<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u6240\u6709\u5934 + \u8282\u8868\u6309\u7167 <strong>\u6587\u4ef6\u5bf9\u9f50<\/strong> \u540e\u7684\u5927\u5c0f\u3002<\/li>\n\n\n\n<li><strong>\u8ba1\u7b97\u516c\u5f0f<\/strong>:<br><code>text SizeOfHeaders = Align( e_lfanew (DOS\u5934\u6307\u5411PE\u5934\u7684\u504f\u79fb) + 4 (PE\u7b7e\u540d Signature) + sizeof(IMAGE_FILE_HEADER) + sizeof(IMAGE_OPTIONAL_HEADER) + sizeof(IMAGE_SECTION_HEADER) * \u8282\u6570\u91cf, FileAlignment )<\/code><\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">CheckSum<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">PE \u6587\u4ef6\u6821\u9a8c\u548c\u3002\u5173\u952e\u7cfb\u7edf\u8fdb\u7a0b\u3001\u9a71\u52a8\u7a0b\u5e8f\u3001\u5f15\u5bfc\u65f6\u52a0\u8f7d\u7684 DLL \u4f1a\u8fdb\u884c\u9a8c\u8bc1\u3002<\/p>\n\n\n\n<h5 class=\"wp-block-heading\">Subsystem<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u8fd0\u884c\u6b64\u6620\u50cf\u6240\u9700\u7684\u5b50\u7cfb\u7edf\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u5b8f\u5b9a\u4e49<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u503c<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_UNKNOWN<\/td><td class=\"has-text-align-left\" data-align=\"left\">0<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u672a\u77e5\u7684\u5b50\u7cfb\u7edf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_NATIVE<\/td><td class=\"has-text-align-left\" data-align=\"left\">1<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u9700\u8981\u5b50\u7cfb\u7edf (\u9a71\u52a8\/\u672c\u673a\u7cfb\u7edf\u8fdb\u7a0b)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_SUBSYSTEM_WINDOWS_GUI<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>2<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>Windows \u56fe\u5f62\u7528\u6237\u754c\u9762 (GUI)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_SUBSYSTEM_WINDOWS_CUI<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>3<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>Windows \u5b57\u7b26\u6a21\u5f0f (\u63a7\u5236\u53f0)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_OS2_CUI<\/td><td class=\"has-text-align-left\" data-align=\"left\">5<\/td><td class=\"has-text-align-left\" data-align=\"left\">OS\/2 CUI \u5b50\u7cfb\u7edf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_POSIX_CUI<\/td><td class=\"has-text-align-left\" data-align=\"left\">7<\/td><td class=\"has-text-align-left\" data-align=\"left\">POSIX CUI \u5b50\u7cfb\u7edf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_WINDOWS_CE_GUI<\/td><td class=\"has-text-align-left\" data-align=\"left\">9<\/td><td class=\"has-text-align-left\" data-align=\"left\">Windows CE \u7cfb\u7edf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_EFI_APPLICATION<\/td><td class=\"has-text-align-left\" data-align=\"left\">10<\/td><td class=\"has-text-align-left\" data-align=\"left\">EFI \u5e94\u7528\u7a0b\u5e8f<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_EFI_BOOT_SERVICE_DRIVER<\/td><td class=\"has-text-align-left\" data-align=\"left\">11<\/td><td class=\"has-text-align-left\" data-align=\"left\">EFI \u5f15\u5bfc\u670d\u52a1\u9a71\u52a8<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_EFI_RUNTIME_DRIVER<\/td><td class=\"has-text-align-left\" data-align=\"left\">12<\/td><td class=\"has-text-align-left\" data-align=\"left\">EFI \u8fd0\u884c\u65f6\u670d\u52a1\u9a71\u52a8<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_EFI_ROM<\/td><td class=\"has-text-align-left\" data-align=\"left\">13<\/td><td class=\"has-text-align-left\" data-align=\"left\">EFI ROM \u955c\u50cf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_XBOX<\/td><td class=\"has-text-align-left\" data-align=\"left\">14<\/td><td class=\"has-text-align-left\" data-align=\"left\">Xbox \u7cfb\u7edf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_SUBSYSTEM_WINDOWS_BOOT_APPLICATION<\/td><td class=\"has-text-align-left\" data-align=\"left\">16<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u542f\u52a8\u5e94\u7528\u7a0b\u5e8f<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">DllCharacteristics<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u5b9a\u4e49\u4e86 Image \u7684 DLL \u7279\u6027\uff08\u4e5f\u53ef\u7528\u4e8e EXE\uff09\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u5b8f\u5b9a\u4e49<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u503c<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">(Reserved)<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0001 &#8211; 0x0008<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4fdd\u7559\uff0c\u5fc5\u987b\u4e3a 0<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLL_CHARACTERISTICS_HIGH_ENTROPY_VA<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0020<\/td><td class=\"has-text-align-left\" data-align=\"left\">64\u4f4d\u5730\u5740\u7a7a\u95f4 ASLR (\u9ad8\u71b5)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>0x0040<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u652f\u6301 ASLR (\u52a0\u8f7d\u65f6\u91cd\u5b9a\u4f4d)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0080<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5f3a\u5236\u4ee3\u7801\u5b8c\u6574\u6027\u68c0\u67e5<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DLLCHARACTERISTICS_NX_COMPAT<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>0x0100<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u652f\u6301 DEP (\u6570\u636e\u6267\u884c\u4fdd\u62a4)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_NO_ISOLATION<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0200<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u5e94\u88ab\u9694\u79bb<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_NO_SEH<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0400<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u4f7f\u7528\u7ed3\u6784\u5316\u5f02\u5e38\u5904\u7406 (SEH)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_NO_BIND<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x0800<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0d\u8981\u7ed1\u5b9a\u6620\u50cf<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLL_CHARACTERISTICS_APPCONTAINER<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x1000<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5728 AppContainer \u4e2d\u6267\u884c<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_WDM_DRIVER<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x2000<\/td><td class=\"has-text-align-left\" data-align=\"left\">WDM \u9a71\u52a8<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLL_CHARACTERISTICS_GUARD_CF<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x4000<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u652f\u6301\u63a7\u5236\u6d41\u4fdd\u62a4 (CFG)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE<\/td><td class=\"has-text-align-left\" data-align=\"left\">0x8000<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7ec8\u7aef\u670d\u52a1\u5668\u611f\u77e5<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h5 class=\"wp-block-heading\">\u6808\u4e0e\u5806<\/h5>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>SizeOfStackReserve<\/strong>: \u521d\u59cb\u5316\u4fdd\u7559\u7684\u6808\u5927\u5c0f\u3002<\/li>\n\n\n\n<li><strong>SizeOfStackCommit<\/strong>: \u521d\u59cb\u5316\u5b9e\u9645\u63d0\u4ea4\u7684\u6808\u5927\u5c0f\u3002<\/li>\n\n\n\n<li><strong>SizeOfHeapReserve<\/strong>: \u521d\u59cb\u5316\u4fdd\u7559\u7684\u5806\u5927\u5c0f\u3002<\/li>\n\n\n\n<li><strong>SizeOfHeapCommit<\/strong>: \u521d\u59cb\u5316\u5b9e\u9645\u63d0\u4ea4\u7684\u5806\u5927\u5c0f\u3002<\/li>\n<\/ul>\n\n\n\n<h5 class=\"wp-block-heading\">DataDirectory (\u6570\u636e\u76ee\u5f55)<\/h5>\n\n\n\n<p class=\"wp-block-paragraph\">\u6307\u5411\u6570\u636e\u76ee\u5f55\u4e2d\u7b2c\u4e00\u4e2a <code>IMAGE_DATA_DIRECTORY<\/code> \u7ed3\u6784\u7684\u6307\u9488\u3002\u6bcf\u4e2a\u6761\u76ee\u5305\u542b\u5730\u5740\uff08RVA\uff09\u548c\u5927\u5c0f\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u7d22\u5f15<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5b8f\u5b9a\u4e49<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u542b\u4e49<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>0<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_EXPORT<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5bfc\u51fa\u8868<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>1<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_IMPORT<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5bfc\u5165\u8868<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>2<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_RESOURCE<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u8d44\u6e90\u8868<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">3<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_EXCEPTION<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5f02\u5e38\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_SECURITY<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b89\u5168\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>5<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_BASERELOC<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u57fa\u5730\u5740\u91cd\u5b9a\u4f4d\u8868<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">6<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_DEBUG<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8c03\u8bd5\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">7<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_ARCHITECTURE<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u67b6\u6784\u6570\u636e (\u4fdd\u75590)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">8<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_GLOBALPTR<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5168\u5c40\u6307\u9488 RVA<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>9<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_TLS<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>TLS \u8868 (\u7ebf\u7a0b\u672c\u5730\u5b58\u50a8)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">10<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u52a0\u8f7d\u914d\u7f6e\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">11<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7ed1\u5b9a\u5bfc\u5165\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>12<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>IMAGE_DIRECTORY_ENTRY_IAT<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5bfc\u5165\u5730\u5740\u8868 (IAT)<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">13<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5ef6\u8fdf\u5bfc\u5165\u8868<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">14<\/td><td class=\"has-text-align-left\" data-align=\"left\">IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR<\/td><td class=\"has-text-align-left\" data-align=\"left\">COM \u63cf\u8ff0\u7b26\u8868 (.NET)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">15<\/td><td class=\"has-text-align-left\" data-align=\"left\">(Reserved)<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4fdd\u7559<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">\u8282\u8868<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u63cf\u8ff0\u6570\u636e\u5757\uff0c\u4e0a\u6587pe\u6587\u4ef6\u4ece\u78c1\u76d8\u6620\u5c04\u5230\u5185\u5b58\u4e2d\uff0c\u8282\u8868\u63cf\u8ff0\u8fd9\u79cd\u6620\u5c04\u5173\u7cfb\uff0c\u8282\u8868\u7684\u6bcf\u4e00\u884c\u5b9e\u9645\u4e0a\u662f\u4e00\u4e2a\u8282\u6807\u9898\u3002 \u6b64\u8868\u7d27\u8ddf\u53ef\u9009\u6807\u5934\uff08\u5982\u679c\u6709\uff09\u3002\u56e0\u4e3a\u6587\u4ef6\u5934\u4e0d\u5305\u542b\u6307\u5411\u8282\u8868\u7684\u76f4\u63a5\u6307\u9488\u3002\u8282\u8868\u7684\u4f4d\u7f6e\u662f\u901a\u8fc7\u8ba1\u7b97\u6807\u5934\u540e\u7b2c\u4e00\u4e2a\u5b57\u8282\u7684\u4f4d\u7f6e\u6765\u786e\u5b9a\u7684\u3002\u8282\u8868\u4e2d\u7684\u6761\u76ee\u6570\u7531\u6587\u4ef6\u6807\u5934\u4e2d\u7684 NumberOfSections \u5b57\u6bb5\u63d0\u4f9b\u3002 \u8282\u8868\u4e2d\u7684\u6761\u76ee\u4ece 1 (1) \u5f00\u59cb\u7f16\u53f7\u3002 \u4ee3\u7801\u548c\u6570\u636e\u5185\u5b58\u90e8\u5206\u6761\u76ee\u6309\u94fe\u63a5\u5668\u9009\u62e9\u7684\u987a\u5e8f\u6392\u5217\u3002<br>\u8282\u7684va\u5fc5\u987b\u7531\u94fe\u63a5\u5668\u5206\u914d\u4ee5\u4fbf\u4e8e\u6309\u5347\u5e8f\u548c\u76f8\u90bb\uff0c\u5fc5\u987b\u662f\u53ef\u9009\u6807\u5934\u4e2d SectionAlignment \u503c\u7684\u500d\u6570\u3002<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Offset<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5927\u5c0f<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u5b57\u6bb5<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\">0<\/td><td class=\"has-text-align-left\" data-align=\"left\">8<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u540d\u79f0<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e00\u4e2a 8 \u5b57\u8282\u3001null \u586b\u5145\u7684 UTF-8 \u7f16\u7801\u5b57\u7b26\u4e32\u3002\u5982\u679c\u5b57\u7b26\u4e32\u957f\u5ea6\u6b63\u597d\u4e3a 8 \u4e2a\u5b57\u7b26\uff0c\u5219\u4e0d\u5b58\u5728\u7ec8\u6b62 null\u3002\u5bf9\u4e8e\u8f83\u957f\u7684\u540d\u79f0\uff0c\u6b64\u5b57\u6bb5\u5305\u542b\u659c\u6760 (\/)\uff0c\u540e\u8ddf\u5341\u8fdb\u5236\u6570\u7684 ASCII \u8868\u793a\u5f62\u5f0f\uff0c\u8be5\u6570\u5b57\u662f\u5b57\u7b26\u4e32\u8868\u4e2d\u7684\u504f\u79fb\u91cf\u3002\u53ef\u6267\u884c\u6620\u50cf\u4e0d\u4f7f\u7528\u5b57\u7b26\u4e32\u8868\uff0c\u5e76\u4e14\u4e0d\u652f\u6301\u957f\u5ea6\u8d85\u8fc7 8 \u4e2a\u5b57\u7b26\u7684\u8282\u540d\u79f0\u3002\u5982\u679c\u5bf9\u8c61\u6587\u4ef6\u4e2d\u7684\u957f\u540d\u79f0\u88ab\u53d1\u9001\u5230\u53ef\u6267\u884c\u6587\u4ef6\uff0c\u5219\u4f1a\u622a\u65ad\u5b83\u4eec\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">8<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">VirtualSize<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u52a0\u8f7d\u5230\u5185\u5b58\u4e2d\u7684\u8282\u7684\u603b\u5927\u5c0f\u3002\u5982\u679c\u6b64\u503c\u5927\u4e8e SizeOfRawData\uff0c\u5219\u8282\u4e3a\u96f6\u586b\u5145\u3002\u6b64\u5b57\u6bb5\u4ec5\u5bf9\u53ef\u6267\u884c\u6620\u50cf\u6709\u6548\uff0c\u5e94\u5c06\u5bf9\u8c61\u6587\u4ef6\u8bbe\u7f6e\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">12<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">VirtualAddress<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5bf9\u4e8e\u53ef\u6267\u884c\u6620\u50cf\uff0c\u662f\u90e8\u5206\u52a0\u8f7d\u5230\u5185\u5b58\u4e2d\u65f6\u76f8\u5bf9\u4e8e\u6620\u50cf\u5e93\u7684\u7b2c\u4e00\u4e2a\u5b57\u8282\u7684\u5730\u5740\u3002\u5bf9\u4e8e\u5bf9\u8c61\u6587\u4ef6\uff0c\u6b64\u5b57\u6bb5\u662f\u5e94\u7528\u91cd\u5b9a\u4f4d\u524d\u7b2c\u4e00\u4e2a\u5b57\u8282\u7684\u5730\u5740;\u4e3a\u7b80\u5355\u8d77\u89c1\uff0c\u7f16\u8bd1\u5668\u5e94\u5c06\u6b64\u8bbe\u7f6e\u4e3a\u96f6\u3002\u5426\u5219\uff0c\u5b83\u662f\u5728\u91cd\u5b9a\u4f4d\u671f\u95f4\u4ece\u504f\u79fb\u91cf\u4e2d\u51cf\u53bb\u7684\u4efb\u610f\u503c\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">16<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">SizeOfRawData<\/td><td class=\"has-text-align-left\" data-align=\"left\">) \u5bf9\u8c61\u6587\u4ef6 (\u8282\u7684\u5927\u5c0f\uff0c\u6216\u56fe\u50cf\u6587\u4ef6) \u78c1\u76d8 (\u4e0a\u521d\u59cb\u5316\u6570\u636e\u7684\u5927\u5c0f\u3002\u5bf9\u4e8e\u53ef\u6267\u884c\u6620\u50cf\uff0c\u8fd9\u5fc5\u987b\u662f\u53ef\u9009\u6807\u5934\u4e2d\u7684 FileAlignment \u7684\u500d\u6570\u3002\u5982\u679c\u5c0f\u4e8e VirtualSize\uff0c\u5219\u90e8\u5206\u7684\u5176\u4f59\u90e8\u5206\u4e3a\u96f6\u586b\u5145\u3002\u7531\u4e8e SizeOfRawData \u5b57\u6bb5\u662f\u820d\u5165\u7684\uff0c\u4f46 VirtualSize \u5b57\u6bb5\u4e0d\u662f\uff0c\u56e0\u6b64 SizeOfRawData \u4e5f\u53ef\u80fd\u5927\u4e8e VirtualSize\u3002\u5982\u679c\u8282\u4ec5\u5305\u542b\u672a\u521d\u59cb\u5316\u7684\u6570\u636e\uff0c\u5219\u6b64\u5b57\u6bb5\u5e94\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">20<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">PointerToRawData<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6307\u5411 COFF \u6587\u4ef6\u4e2d\u8282\u7684\u7b2c\u4e00\u9875\u7684\u6587\u4ef6\u6307\u9488\u3002\u5bf9\u4e8e\u53ef\u6267\u884c\u6620\u50cf\uff0c\u8fd9\u5fc5\u987b\u662f\u53ef\u9009\u6807\u5934\u4e2d\u7684 FileAlignment \u7684\u500d\u6570\u3002\u5bf9\u4e8e\u5bf9\u8c61\u6587\u4ef6\uff0c\u503c\u5e94\u5728 4 \u5b57\u8282\u8fb9\u754c\u4e0a\u5bf9\u9f50\uff0c\u4ee5\u83b7\u5f97\u6700\u4f73\u6027\u80fd\u3002\u5982\u679c\u8282\u4ec5\u5305\u542b\u672a\u521d\u59cb\u5316\u7684\u6570\u636e\uff0c\u5219\u6b64\u5b57\u6bb5\u5e94\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">24<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">PointerToRelocations<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6307\u5411\u8282\u91cd\u5b9a\u4f4d\u6761\u76ee\u5f00\u5934\u7684\u6587\u4ef6\u6307\u9488\u3002\u5bf9\u4e8e\u53ef\u6267\u884c\u6620\u50cf\uff0c\u5982\u679c\u6ca1\u6709\u4efb\u4f55\u91cd\u5b9a\u4f4d\uff0c\u5219\u8bbe\u7f6e\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">28<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">PointerToLinenumbers<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6307\u5411\u8282\u7684\u884c\u53f7\u6761\u76ee\u5f00\u5934\u7684\u6587\u4ef6\u6307\u9488\u3002\u5982\u679c\u6ca1\u6709 COFF \u884c\u53f7\uff0c\u5219\u6b64\u503c\u8bbe\u7f6e\u4e3a\u96f6\u3002\u6620\u50cf\u7684\u6b64\u503c\u5e94\u4e3a\u96f6\uff0c\u56e0\u4e3a COFF \u8c03\u8bd5\u4fe1\u606f\u5df2\u5f03\u7528\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">32<\/td><td class=\"has-text-align-left\" data-align=\"left\">2<\/td><td class=\"has-text-align-left\" data-align=\"left\">NumberOfRelocations<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8282\u7684\u91cd\u5b9a\u4f4d\u6761\u76ee\u6570\u3002\u5bf9\u4e8e\u53ef\u6267\u884c\u6620\u50cf\uff0c\u6b64\u503c\u8bbe\u7f6e\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">34<\/td><td class=\"has-text-align-left\" data-align=\"left\">2<\/td><td class=\"has-text-align-left\" data-align=\"left\">NumberOfLinenumbers<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8282\u7684\u884c\u53f7\u6761\u76ee\u6570\u3002\u6620\u50cf\u7684\u6b64\u503c\u5e94\u4e3a\u96f6\uff0c\u56e0\u4e3a COFF \u8c03\u8bd5\u4fe1\u606f\u5df2\u5f03\u7528\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\">36<\/td><td class=\"has-text-align-left\" data-align=\"left\">4<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7279\u5f81<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u63cf\u8ff0\u90e8\u5206\u7279\u5f81\u7684\u6807\u5fd7\u3002\u6709\u5173\u8be6\u7ec6\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605 \u8282\u6807\u5fd7\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">VA\u548cFOA\u8f6c\u6362<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>VA\uff1a\u5728\u5185\u5b58\u4e2d\u7684\u865a\u62df\u5730\u5740<\/li>\n\n\n\n<li>RVA\uff1a\u76f8\u5bf9\u865a\u62df\u5730\u5740<\/li>\n\n\n\n<li>FOA\uff1a\u6587\u4ef6\u504f\u79fb\u5730\u5740<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u6d41\u7a0b<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">va\u5230foa<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5f97\u5230PVA\u7684\u503c\uff1aRVA = VA &#8211; ImageBase<\/li>\n\n\n\n<li>\u5224\u65adRVA\u662f\u5426\u5904\u4e8ePE\u6587\u4ef6\u5934\u4e2d<\/li>\n\n\n\n<li>\u5728\u6587\u4ef6\u5934\u4e2d\u5219FOA=RVA\uff0c\u4e0d\u5728\u5219\u5224\u65adRVA\u4f4d\u4e8e\u54ea\u4e2a\u8282\uff0c\u5dee\u503c = RVA &#8211; \u8282.VirtualAddress(RVA)\uff0cFOA = \u8282.PointerToRawData + \u5dee\u503c<br>\u4ee3\u7801\u5b9e\u73b0<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ PE.cpp : Defines the entry point for the console application.\n\/\/\n#include &lt;stdio.h&gt;\n#include &lt;malloc.h&gt;\n#include &lt;windows.h&gt;\n#include &lt;winnt.h&gt;\n#include &lt;math.h&gt;\n\/\/\u5728VC6\u8fd9\u4e2a\u6bd4\u8f83\u65e7\u7684\u73af\u5883\u91cc\uff0c\u6ca1\u6709\u5b9a\u4e4964\u4f4d\u7684\u8fd9\u4e2a\u5b8f\uff0c\u9700\u8981\u81ea\u5df1\u5b9a\u4e49\uff0c\u5728VS2019\u4e2d\u65e0\u9700\u81ea\u5df1\u5b9a\u4e49\n#define IMAGE_FILE_MACHINE_AMD64  0x8664\n\n\/\/VA\u8f6cFOA 32\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u5185\u5b58\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT VaToFoa32(UINT va, _IMAGE_DOS_HEADER *dos,_IMAGE_NT_HEADERS* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u5f97\u5230RVA\u7684\u503c\uff1aRVA = VA - ImageBase\n    UINT rva = va - nt-&gt;OptionalHeader.ImageBase;\n    \/\/\u8f93\u51farva\n    printf(\"rva:%X\\n\", rva);\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew+sizeof(_IMAGE_NT_HEADERS);\n    \/\/\u8f93\u51faPeEnd\n    printf(\"PeEnd:%X\\n\", PeEnd);\n    \/\/\u5224\u65adrva\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (rva &lt; PeEnd) {\n        \/\/\u5982\u679crva\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56derva\u5373\u53ef\n        printf(\"foa:%X\\n\", rva);        \n        return rva;\n    }\n    else {\n        \/\/\u5982\u679crva\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adrva\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n            \/\/\u8ba1\u7b97\u5185\u5b58\u5bf9\u9f50\u540e\u8282\u7684\u5927\u5c0f\n            UINT SizeInMemory = ceil((double)max((UINT)sectionArr&#91;i]-&gt;Misc.VirtualSize ,(UINT)sectionArr&#91;i]-&gt;SizeOfRawData ) \/ (double)nt-&gt;OptionalHeader.SectionAlignment)* nt-&gt;OptionalHeader.SectionAlignment;\n\n            if (rva &gt;= sectionArr&#91;i]-&gt;VirtualAddress &amp;&amp; rva &lt; (sectionArr&#91;i]-&gt;VirtualAddress + SizeInMemory)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282\n                \/\/\u8f93\u51fa\u5185\u5b58\u5bf9\u9f50\u540e\u7684\u8282\u7684\u5927\u5c0f\n                printf(\"SizeInMemory:%X\\n\", SizeInMemory);\n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= RVA - \u8282.VirtualAddress\n            int offset = rva - sectionArr&#91;i]-&gt;VirtualAddress;\n            \/\/FOA = \u8282.PointerToRawData + \u5dee\u503c\n            int foa = sectionArr&#91;i]-&gt;PointerToRawData + offset;\n            printf(\"foa:%X\\n\", foa);\n            return foa;\n        }\n\n    }\n\n}\n\n\/\/VA\u8f6cFOA 64\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u5185\u5b58\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT VaToFoa64(UINT va, _IMAGE_DOS_HEADER* dos, _IMAGE_NT_HEADERS64* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u5f97\u5230RVA\u7684\u503c\uff1aRVA = VA - ImageBase\n    UINT rva = va - nt-&gt;OptionalHeader.ImageBase;\n    \/\/\u8f93\u51farva\n    printf(\"rva:%X\\n\", rva);\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew + sizeof(_IMAGE_NT_HEADERS64);\n    \/\/\u8f93\u51faPeEnd\n    printf(\"PeEnd:%X\\n\", PeEnd);\n    \/\/\u5224\u65adrva\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (rva &lt; PeEnd) {\n        \/\/\u5982\u679crva\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56derva\u5373\u53ef\n        printf(\"foa:%X\\n\", rva);\n        return rva;\n    }\n    else {\n        \/\/\u5982\u679crva\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adrva\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n            \/\/\u8ba1\u7b97\u5185\u5b58\u5bf9\u9f50\u540e\u8282\u7684\u5927\u5c0f\n            UINT SizeInMemory = ceil((double)max((UINT)sectionArr&#91;i]-&gt;Misc.VirtualSize ,(UINT)sectionArr&#91;i]-&gt;SizeOfRawData ) \/ (double)nt-&gt;OptionalHeader.SectionAlignment)* nt-&gt;OptionalHeader.SectionAlignment;\n\n            if (rva &gt;= sectionArr&#91;i]-&gt;VirtualAddress &amp;&amp; rva &lt; (sectionArr&#91;i]-&gt;VirtualAddress + SizeInMemory)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282\n                \/\/\u8f93\u51fa\u5185\u5b58\u5bf9\u9f50\u540e\u7684\u8282\u7684\u5927\u5c0f\n                printf(\"SizeInMemory:%X\\n\", SizeInMemory);\n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= RVA - \u8282.VirtualAddress\n            int offset = rva - sectionArr&#91;i]-&gt;VirtualAddress;\n            \/\/FOA = \u8282.PointerToRawData + \u5dee\u503c\n            int foa = sectionArr&#91;i]-&gt;PointerToRawData + offset;\n            printf(\"foa:%X\\n\", foa);\n            return foa;\n        }\n\n    }\n\n}\nint main(int argc, char* argv&#91;])\n{\n    \/\/\u521b\u5efaDOS\u5bf9\u5e94\u7684\u7ed3\u6784\u4f53\u6307\u9488\n    _IMAGE_DOS_HEADER* dos;\n    \/\/\u8bfb\u53d6\u6587\u4ef6\uff0c\u8fd4\u56de\u6587\u4ef6\u53e5\u67c4\n    HANDLE hFile = CreateFileA(\"C:\\\\Users\\\\lyl610abc\\\\Desktop\\\\GlobalVariety.exe\", GENERIC_READ, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0, 0);\n    \/\/\u6839\u636e\u6587\u4ef6\u53e5\u67c4\u521b\u5efa\u6620\u5c04\n    HANDLE hMap = CreateFileMappingA(hFile, NULL, PAGE_READONLY, 0, 0, 0);\n    \/\/\u6620\u5c04\u5185\u5bb9\n    LPVOID pFile = MapViewOfFile(hMap, FILE_MAP_READ, 0, 0, 0);\n    \/\/\u7c7b\u578b\u8f6c\u6362\uff0c\u7528\u7ed3\u6784\u4f53\u7684\u65b9\u5f0f\u6765\u8bfb\u53d6\n    dos = (_IMAGE_DOS_HEADER*)pFile;\n    \/\/\u8f93\u51fados-&gt;e_magic\uff0c\u4ee5\u5341\u516d\u8fdb\u5236\u8f93\u51fa\n    printf(\"dos-&gt;e_magic:%X\\n\", dos-&gt;e_magic);\n\n    \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u6807\u5fd7\u7684\u6307\u9488\n    DWORD* peId;\n    \/\/\u8ba9PE\u6587\u4ef6\u5934\u6807\u5fd7\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=DOS\u9996\u5730\u5740+\u504f\u79fb\n    peId = (DWORD*)((UINT)dos + dos-&gt;e_lfanew);\n    \/\/\u8f93\u51faPE\u6587\u4ef6\u5934\u6807\u5fd7\uff0c\u5176\u503c\u5e94\u4e3a4550\uff0c\u5426\u5219\u4e0d\u662fPE\u6587\u4ef6\n    printf(\"peId:%X\\n\", *peId);\n\n    \/\/\u521b\u5efa\u6307\u5411\u53ef\u9009PE\u5934\u7684\u7b2c\u4e00\u4e2a\u6210\u5458magic\u7684\u6307\u9488\n    WORD* magic;\n    \/\/\u8ba9magic\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=PE\u6587\u4ef6\u5934\u6807\u5fd7\u5730\u5740+PE\u6587\u4ef6\u5934\u6807\u5fd7\u5927\u5c0f+\u6807\u51c6PE\u5934\u5927\u5c0f\n    magic = (WORD*)((UINT)peId + sizeof(DWORD) + sizeof(_IMAGE_FILE_HEADER));\n    \/\/\u8f93\u51famagic\uff0c\u5176\u503c\u4e3a0x10b\u4ee3\u886832\u4f4d\u7a0b\u5e8f\uff0c\u5176\u503c\u4e3a0x20b\u4ee3\u886864\u4f4d\u7a0b\u5e8f\n    printf(\"magic:%X\\n\", *magic);\n    \/\/\u6839\u636emagic\u5224\u65ad\u4e3a32\u4f4d\u7a0b\u5e8f\u8fd8\u662f64\u4f4d\u7a0b\u5e8f\n    switch (*magic) {\n    case IMAGE_NT_OPTIONAL_HDR32_MAGIC:\n    {\n        printf(\"32\u4f4d\u7a0b\u5e8f\\n\");\n        \/\/\u786e\u5b9a\u4e3a32\u4f4d\u7a0b\u5e8f\u540e\uff0c\u5c31\u53ef\u4ee5\u4f7f\u7528_IMAGE_NT_HEADERS\u6765\u63a5\u6536\u6570\u636e\u4e86\n        \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u7684\u6307\u9488\n        _IMAGE_NT_HEADERS* nt;\n        \/\/\u8ba9PE\u6587\u4ef6\u5934\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\n        nt = (_IMAGE_NT_HEADERS*)peId;\n        printf(\"Machine:%X\\n\", nt-&gt;FileHeader.Machine);\n        printf(\"Magic:%X\\n\", nt-&gt;OptionalHeader.Magic);\n\n        \/\/\u521b\u5efa\u4e00\u4e2a\u6307\u9488\u6570\u7ec4\uff0c\u8be5\u6307\u9488\u6570\u7ec4\u7528\u6765\u5b58\u50a8\u6240\u6709\u7684\u8282\u8868\u6307\u9488\n        \/\/\u8fd9\u91cc\u76f8\u5f53\u4e8e_IMAGE_SECTION_HEADER* sectionArr&#91;nt-&gt;FileHeader.NumberOfSections],\u58f0\u660e\u4e86\u4e00\u4e2a\u52a8\u6001\u6570\u7ec4\n        _IMAGE_SECTION_HEADER** sectionArr = (_IMAGE_SECTION_HEADER**) malloc(sizeof(_IMAGE_SECTION_HEADER*) * nt-&gt;FileHeader.NumberOfSections);\n\n        \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n        _IMAGE_SECTION_HEADER* sectionHeader;\n        \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\n        sectionHeader = (_IMAGE_SECTION_HEADER*)((UINT)nt + sizeof(_IMAGE_NT_HEADERS));\n        \/\/\u8ba1\u6570\uff0c\u7528\u6765\u8ba1\u7b97\u5757\u8868\u5730\u5740\n        int cnt = 0;\n        \/\/\u6bd4\u8f83 \u8ba1\u6570 \u548c \u5757\u8868\u7684\u4e2a\u6570\uff0c\u5373\u904d\u5386\u6240\u6709\u5757\u8868\n        while(cnt&lt; nt-&gt;FileHeader.NumberOfSections){\n            \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n            _IMAGE_SECTION_HEADER* section;\n            \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=\u7b2c\u4e00\u4e2a\u5757\u8868\u5730\u5740+\u8ba1\u6570*\u5757\u8868\u7684\u5927\u5c0f\n            section = (_IMAGE_SECTION_HEADER*)((UINT)sectionHeader + sizeof(_IMAGE_SECTION_HEADER)*cnt);\n            \/\/\u5c06\u5f97\u5230\u7684\u5757\u8868\u6307\u9488\u5b58\u5165\u6570\u7ec4\n            sectionArr&#91;cnt++] = section;\n            \/\/\u8f93\u51fa\u5757\u8868\u540d\u79f0\n            printf(\"%s\\n\", section-&gt;Name);\n        }\n\n        VaToFoa32(0x4198B0,dos, nt, sectionArr);\n\n        break;\n    }\n\n    case IMAGE_NT_OPTIONAL_HDR64_MAGIC:\n    {\n        printf(\"64\u4f4d\u7a0b\u5e8f\\n\");\n        \/\/\u786e\u5b9a\u4e3a64\u4f4d\u7a0b\u5e8f\u540e\uff0c\u5c31\u53ef\u4ee5\u4f7f\u7528_IMAGE_NT_HEADERS64\u6765\u63a5\u6536\u6570\u636e\u4e86\n        \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u7684\u6307\u9488\n        _IMAGE_NT_HEADERS64* nt;\n        nt = (_IMAGE_NT_HEADERS64*)peId;\n        printf(\"Machine:%X\\n\", nt-&gt;FileHeader.Machine);\n        printf(\"Magic:%X\\n\", nt-&gt;OptionalHeader.Magic);\n\n        \/\/\u521b\u5efa\u4e00\u4e2a\u6307\u9488\u6570\u7ec4\uff0c\u8be5\u6307\u9488\u6570\u7ec4\u7528\u6765\u5b58\u50a8\u6240\u6709\u7684\u8282\u8868\u6307\u9488\n        \/\/\u8fd9\u91cc\u76f8\u5f53\u4e8e_IMAGE_SECTION_HEADER* sectionArr&#91;nt-&gt;FileHeader.NumberOfSections],\u58f0\u660e\u4e86\u4e00\u4e2a\u52a8\u6001\u6570\u7ec4\n        _IMAGE_SECTION_HEADER** sectionArr = (_IMAGE_SECTION_HEADER**)malloc(sizeof(_IMAGE_SECTION_HEADER*) * nt-&gt;FileHeader.NumberOfSections);\n\n        \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n        _IMAGE_SECTION_HEADER* sectionHeader;\n        \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\uff0c\u533a\u522b\u5728\u4e8e\u8fd9\u91cc\u52a0\u4e0a\u7684\u504f\u79fb\u4e3a_IMAGE_NT_HEADERS64\n        sectionHeader = (_IMAGE_SECTION_HEADER*)((UINT)nt + sizeof(_IMAGE_NT_HEADERS64));\n        \/\/\u8ba1\u6570\uff0c\u7528\u6765\u8ba1\u7b97\u5757\u8868\u5730\u5740\n        int cnt = 0;\n        \/\/\u6bd4\u8f83 \u8ba1\u6570 \u548c \u5757\u8868\u7684\u4e2a\u6570\uff0c\u5373\u904d\u5386\u6240\u6709\u5757\u8868\n        while (cnt &lt; nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n            _IMAGE_SECTION_HEADER* section;\n            \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=\u7b2c\u4e00\u4e2a\u5757\u8868\u5730\u5740+\u8ba1\u6570*\u5757\u8868\u7684\u5927\u5c0f\n            section = (_IMAGE_SECTION_HEADER*)((UINT)sectionHeader + sizeof(_IMAGE_SECTION_HEADER) * cnt);\n            \/\/\u5c06\u5f97\u5230\u7684\u5757\u8868\u6307\u9488\u5b58\u5165\u6570\u7ec4\n            sectionArr&#91;cnt++] = section;\n            \/\/\u8f93\u51fa\u5757\u8868\u540d\u79f0\n            printf(\"%s\\n\", section-&gt;Name);\n        }\n        break;\n    }\n\n    default:\n    {\n        printf(\"error!\\n\");\n        break;\n    }\n\n    }\n    return 0;\n}<\/code><\/pre>\n\n\n\n<h4 class=\"wp-block-heading\">foa\u5230va<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5224\u65adfoa\u662f\u5426\u4f4d\u4e8epe\u6587\u4ef6\u5934\u4e2d<\/li>\n\n\n\n<li>\u662f\u5219\uff0cfoa=rva\uff0c\u4e0d\u662f\u5219\u5224\u65ad\u4f4d\u4e8e\u54ea\u4e2a\u8282\uff0c\u5dee\u503c =&nbsp;&nbsp;FOA &#8211; \u8282.PointerToRawData \uff0cRVA = \u5dee\u503c + \u8282.VirtualAddress(RVA)<\/li>\n\n\n\n<li>VA = ImageBase + RVA<br>\u4ee3\u7801\u5b9e\u73b0<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/\/ PE.cpp : Defines the entry point for the console application.\n\/\/\n#include &lt;stdio.h&gt;\n#include &lt;malloc.h&gt;\n#include &lt;windows.h&gt;\n#include &lt;winnt.h&gt;\n#include &lt;math.h&gt;\n\/\/\u5728VC6\u8fd9\u4e2a\u6bd4\u8f83\u65e7\u7684\u73af\u5883\u91cc\uff0c\u6ca1\u6709\u5b9a\u4e4964\u4f4d\u7684\u8fd9\u4e2a\u5b8f\uff0c\u9700\u8981\u81ea\u5df1\u5b9a\u4e49\uff0c\u5728VS2019\u4e2d\u65e0\u9700\u81ea\u5df1\u5b9a\u4e49\n#define IMAGE_FILE_MACHINE_AMD64  0x8664\n\n\/\/VA\u8f6cFOA 32\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u5185\u5b58\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT VaToFoa32(UINT va, _IMAGE_DOS_HEADER *dos,_IMAGE_NT_HEADERS* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u5f97\u5230RVA\u7684\u503c\uff1aRVA = VA - ImageBase\n    UINT rva = va - nt-&gt;OptionalHeader.ImageBase;\n    \/\/\u8f93\u51farva\n    printf(\"rva:%X\\n\", rva);\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew+sizeof(_IMAGE_NT_HEADERS);\n    \/\/\u8f93\u51faPeEnd\n    printf(\"PeEnd:%X\\n\", PeEnd);\n    \/\/\u5224\u65adrva\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (rva &lt; PeEnd) {\n        \/\/\u5982\u679crva\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56derva\u5373\u53ef\n        printf(\"foa:%X\\n\", rva);        \n        return rva;\n    }\n    else {\n        \/\/\u5982\u679crva\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adrva\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n            \/\/\u8ba1\u7b97\u5185\u5b58\u5bf9\u9f50\u540e\u8282\u7684\u5927\u5c0f\n            UINT SizeInMemory = ceil((double)max((UINT)sectionArr&#91;i]-&gt;Misc.VirtualSize ,(UINT)sectionArr&#91;i]-&gt;SizeOfRawData ) \/ (double)nt-&gt;OptionalHeader.SectionAlignment)* nt-&gt;OptionalHeader.SectionAlignment;\n\n            if (rva &gt;= sectionArr&#91;i]-&gt;VirtualAddress &amp;&amp; rva &lt; (sectionArr&#91;i]-&gt;VirtualAddress + SizeInMemory)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282\n                \/\/\u8f93\u51fa\u5185\u5b58\u5bf9\u9f50\u540e\u7684\u8282\u7684\u5927\u5c0f\n                printf(\"SizeInMemory:%X\\n\", SizeInMemory);\n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= RVA - \u8282.VirtualAddress\n            UINT offset = rva - sectionArr&#91;i]-&gt;VirtualAddress;\n            \/\/FOA = \u8282.PointerToRawData + \u5dee\u503c\n            UINT foa = sectionArr&#91;i]-&gt;PointerToRawData + offset;\n            printf(\"foa:%X\\n\", foa);\n            return foa;\n        }\n\n    }\n\n}\n\n\/\/VA\u8f6cFOA 64\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u5185\u5b58\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT VaToFoa64(UINT va, _IMAGE_DOS_HEADER* dos, _IMAGE_NT_HEADERS64* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u5f97\u5230RVA\u7684\u503c\uff1aRVA = VA - ImageBase\n    UINT rva = va - nt-&gt;OptionalHeader.ImageBase;\n    \/\/\u8f93\u51farva\n    printf(\"rva:%X\\n\", rva);\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew + sizeof(_IMAGE_NT_HEADERS64);\n    \/\/\u8f93\u51faPeEnd\n    printf(\"PeEnd:%X\\n\", PeEnd);\n    \/\/\u5224\u65adrva\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (rva &lt; PeEnd) {\n        \/\/\u5982\u679crva\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56derva\u5373\u53ef\n        printf(\"foa:%X\\n\", rva);\n        return rva;\n    }\n    else {\n        \/\/\u5982\u679crva\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adrva\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n            \/\/\u8ba1\u7b97\u5185\u5b58\u5bf9\u9f50\u540e\u8282\u7684\u5927\u5c0f\n            UINT SizeInMemory = ceil((double)max((UINT)sectionArr&#91;i]-&gt;Misc.VirtualSize ,(UINT)sectionArr&#91;i]-&gt;SizeOfRawData ) \/ (double)nt-&gt;OptionalHeader.SectionAlignment)* nt-&gt;OptionalHeader.SectionAlignment;           \n            if (rva &gt;= sectionArr&#91;i]-&gt;VirtualAddress &amp;&amp; rva &lt; (sectionArr&#91;i]-&gt;VirtualAddress + SizeInMemory)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282\n                \/\/\u8f93\u51fa\u5185\u5b58\u5bf9\u9f50\u540e\u7684\u8282\u7684\u5927\u5c0f\n                printf(\"SizeInMemory:%X\\n\", SizeInMemory);\n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= RVA - \u8282.VirtualAddress\n            UINT offset = rva - sectionArr&#91;i]-&gt;VirtualAddress;\n            \/\/FOA = \u8282.PointerToRawData + \u5dee\u503c\n            UINT foa = sectionArr&#91;i]-&gt;PointerToRawData + offset;\n            printf(\"foa:%X\\n\", foa);\n            return foa;\n        }\n\n    }\n\n}\n\n\/\/FOA\u8f6cVA 32\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u6587\u4ef6\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT FoaToVa32(UINT foa, _IMAGE_DOS_HEADER* dos, _IMAGE_NT_HEADERS* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew + sizeof(_IMAGE_NT_HEADERS);\n    \/\/\u5224\u65adFOA\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (foa &lt; PeEnd) {\n        \/\/\u5982\u679cfoa\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56defoa+ImageBase\u5373\u53ef\n        printf(\"va:%X\\n\", foa+nt-&gt;OptionalHeader.ImageBase);\n        return foa + nt-&gt;OptionalHeader.ImageBase;\n    }\n    else {\n        \/\/\u5982\u679cfoa\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adfoa\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n\n            if (foa &gt;= sectionArr&#91;i]-&gt;PointerToRawData &amp;&amp; foa &lt; (sectionArr&#91;i]-&gt;PointerToRawData + sectionArr&#91;i]-&gt;SizeOfRawData)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282                \n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= FOA - \u8282.PointerToRawData \n            UINT offset = foa - sectionArr&#91;i]-&gt;PointerToRawData;\n            \/\/RVA = \u5dee\u503c + \u8282.VirtualAddress(RVA)\n            UINT rva =  offset+ sectionArr&#91;i]-&gt;VirtualAddress;\n            printf(\"va:%X\\n\", rva + nt-&gt;OptionalHeader.ImageBase);\n            return rva + nt-&gt;OptionalHeader.ImageBase;\n        }\n    }\n    return 0;\n}\n\n\/\/FOA\u8f6cVA 64\u4f4d\n\/\/\u7b2c\u4e00\u4e2a\u53c2\u6570\u4e3a\u8981\u8f6c\u6362\u7684\u5728\u6587\u4ef6\u4e2d\u7684\u5730\u5740\uff1aVA\n\/\/\u7b2c\u4e8c\u4e2a\u53c2\u6570\u4e3a\u6307\u5411dos\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u4e09\u4e2a\u53c2\u6570\u4e3a\u6307\u5411nt\u5934\u7684\u6307\u9488\n\/\/\u7b2c\u56db\u4e2a\u53c2\u6570\u4e3a\u5b58\u50a8\u6307\u5411\u8282\u6307\u9488\u7684\u6570\u7ec4\nUINT FoaToVa64(UINT foa, _IMAGE_DOS_HEADER* dos, _IMAGE_NT_HEADERS64* nt, _IMAGE_SECTION_HEADER** sectionArr) {\n    \/\/\u627e\u5230PE\u6587\u4ef6\u5934\u540e\u7684\u5730\u5740 = PE\u6587\u4ef6\u5934\u9996\u5730\u5740+PE\u6587\u4ef6\u5934\u5927\u5c0f\n    UINT PeEnd = (UINT)dos-&gt;e_lfanew + sizeof(_IMAGE_NT_HEADERS64);\n    \/\/\u5224\u65adFOA\u662f\u5426\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\n    if (foa &lt; PeEnd) {\n        \/\/\u5982\u679cfoa\u4f4d\u4e8ePE\u6587\u4ef6\u5934\u4e2d\uff0c\u5219foa==rva\uff0c\u76f4\u63a5\u8fd4\u56defoa+ImageBase\u5373\u53ef\n        printf(\"va:%X\\n\", foa + nt-&gt;OptionalHeader.ImageBase);\n        return foa + nt-&gt;OptionalHeader.ImageBase;\n    }\n    else {\n        \/\/\u5982\u679cfoa\u5728PE\u6587\u4ef6\u5934\u5916\n        \/\/\u5224\u65adfoa\u5c5e\u4e8e\u54ea\u4e2a\u8282\n        int i;\n        for (i = 0; i &lt; nt-&gt;FileHeader.NumberOfSections; i++) {\n\n            if (foa &gt;= sectionArr&#91;i]-&gt;PointerToRawData &amp;&amp; foa &lt; (sectionArr&#91;i]-&gt;PointerToRawData + sectionArr&#91;i]-&gt;SizeOfRawData)) {\n                \/\/\u627e\u5230\u6240\u5c5e\u7684\u8282                \n                break;\n            }\n        }\n        if (i &gt;= nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u672a\u627e\u5230\n            printf(\"\u6ca1\u6709\u627e\u5230\u5339\u914d\u7684\u8282\\n\");\n            return -1;\n        }\n        else {\n            \/\/\u8ba1\u7b97\u5dee\u503c= FOA - \u8282.PointerToRawData \n            UINT offset = foa - sectionArr&#91;i]-&gt;PointerToRawData;\n            \/\/RVA = \u5dee\u503c + \u8282.VirtualAddress(RVA)\n            UINT rva = offset + sectionArr&#91;i]-&gt;VirtualAddress;\n            printf(\"va:%X\\n\", rva + nt-&gt;OptionalHeader.ImageBase);\n            return rva + nt-&gt;OptionalHeader.ImageBase;\n        }\n    }\n    return 0;\n}\n\nint main(int argc, char* argv&#91;])\n{\n    \/\/\u521b\u5efaDOS\u5bf9\u5e94\u7684\u7ed3\u6784\u4f53\u6307\u9488\n    _IMAGE_DOS_HEADER* dos;\n    \/\/\u8bfb\u53d6\u6587\u4ef6\uff0c\u8fd4\u56de\u6587\u4ef6\u53e5\u67c4\n    HANDLE hFile = CreateFileA(\"C:\\\\Users\\\\sixonezero\\\\Desktop\\\\GlobalVariety.exe\", GENERIC_READ, FILE_SHARE_READ, NULL, OPEN_EXISTING, 0, 0);\n    \/\/\u6839\u636e\u6587\u4ef6\u53e5\u67c4\u521b\u5efa\u6620\u5c04\n    HANDLE hMap = CreateFileMappingA(hFile, NULL, PAGE_READONLY, 0, 0, 0);\n    \/\/\u6620\u5c04\u5185\u5bb9\n    LPVOID pFile = MapViewOfFile(hMap, FILE_MAP_READ, 0, 0, 0);\n    \/\/\u7c7b\u578b\u8f6c\u6362\uff0c\u7528\u7ed3\u6784\u4f53\u7684\u65b9\u5f0f\u6765\u8bfb\u53d6\n    dos = (_IMAGE_DOS_HEADER*)pFile;\n    \/\/\u8f93\u51fados-&gt;e_magic\uff0c\u4ee5\u5341\u516d\u8fdb\u5236\u8f93\u51fa\n    printf(\"dos-&gt;e_magic:%X\\n\", dos-&gt;e_magic);\n\n    \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u6807\u5fd7\u7684\u6307\u9488\n    DWORD* peId;\n    \/\/\u8ba9PE\u6587\u4ef6\u5934\u6807\u5fd7\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=DOS\u9996\u5730\u5740+\u504f\u79fb\n    peId = (DWORD*)((UINT)dos + dos-&gt;e_lfanew);\n    \/\/\u8f93\u51faPE\u6587\u4ef6\u5934\u6807\u5fd7\uff0c\u5176\u503c\u5e94\u4e3a4550\uff0c\u5426\u5219\u4e0d\u662fPE\u6587\u4ef6\n    printf(\"peId:%X\\n\", *peId);\n\n    \/\/\u521b\u5efa\u6307\u5411\u53ef\u9009PE\u5934\u7684\u7b2c\u4e00\u4e2a\u6210\u5458magic\u7684\u6307\u9488\n    WORD* magic;\n    \/\/\u8ba9magic\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=PE\u6587\u4ef6\u5934\u6807\u5fd7\u5730\u5740+PE\u6587\u4ef6\u5934\u6807\u5fd7\u5927\u5c0f+\u6807\u51c6PE\u5934\u5927\u5c0f\n    magic = (WORD*)((UINT)peId + sizeof(DWORD) + sizeof(_IMAGE_FILE_HEADER));\n    \/\/\u8f93\u51famagic\uff0c\u5176\u503c\u4e3a0x10b\u4ee3\u886832\u4f4d\u7a0b\u5e8f\uff0c\u5176\u503c\u4e3a0x20b\u4ee3\u886864\u4f4d\u7a0b\u5e8f\n    printf(\"magic:%X\\n\", *magic);\n    \/\/\u6839\u636emagic\u5224\u65ad\u4e3a32\u4f4d\u7a0b\u5e8f\u8fd8\u662f64\u4f4d\u7a0b\u5e8f\n    switch (*magic) {\n    case IMAGE_NT_OPTIONAL_HDR32_MAGIC:\n    {\n        printf(\"32\u4f4d\u7a0b\u5e8f\\n\");\n        \/\/\u786e\u5b9a\u4e3a32\u4f4d\u7a0b\u5e8f\u540e\uff0c\u5c31\u53ef\u4ee5\u4f7f\u7528_IMAGE_NT_HEADERS\u6765\u63a5\u6536\u6570\u636e\u4e86\n        \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u7684\u6307\u9488\n        _IMAGE_NT_HEADERS* nt;\n        \/\/\u8ba9PE\u6587\u4ef6\u5934\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\n        nt = (_IMAGE_NT_HEADERS*)peId;\n        printf(\"Machine:%X\\n\", nt-&gt;FileHeader.Machine);\n        printf(\"Magic:%X\\n\", nt-&gt;OptionalHeader.Magic);\n\n        \/\/\u521b\u5efa\u4e00\u4e2a\u6307\u9488\u6570\u7ec4\uff0c\u8be5\u6307\u9488\u6570\u7ec4\u7528\u6765\u5b58\u50a8\u6240\u6709\u7684\u8282\u8868\u6307\u9488\n        \/\/\u8fd9\u91cc\u76f8\u5f53\u4e8e_IMAGE_SECTION_HEADER* sectionArr&#91;nt-&gt;FileHeader.NumberOfSections],\u58f0\u660e\u4e86\u4e00\u4e2a\u52a8\u6001\u6570\u7ec4\n        _IMAGE_SECTION_HEADER** sectionArr = (_IMAGE_SECTION_HEADER**) malloc(sizeof(_IMAGE_SECTION_HEADER*) * nt-&gt;FileHeader.NumberOfSections);\n\n        \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n        _IMAGE_SECTION_HEADER* sectionHeader;\n        \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\n        sectionHeader = (_IMAGE_SECTION_HEADER*)((UINT)nt + sizeof(_IMAGE_NT_HEADERS));\n        \/\/\u8ba1\u6570\uff0c\u7528\u6765\u8ba1\u7b97\u5757\u8868\u5730\u5740\n        int cnt = 0;\n        \/\/\u6bd4\u8f83 \u8ba1\u6570 \u548c \u5757\u8868\u7684\u4e2a\u6570\uff0c\u5373\u904d\u5386\u6240\u6709\u5757\u8868\n        while(cnt&lt; nt-&gt;FileHeader.NumberOfSections){\n            \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n            _IMAGE_SECTION_HEADER* section;\n            \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=\u7b2c\u4e00\u4e2a\u5757\u8868\u5730\u5740+\u8ba1\u6570*\u5757\u8868\u7684\u5927\u5c0f\n            section = (_IMAGE_SECTION_HEADER*)((UINT)sectionHeader + sizeof(_IMAGE_SECTION_HEADER)*cnt);\n            \/\/\u5c06\u5f97\u5230\u7684\u5757\u8868\u6307\u9488\u5b58\u5165\u6570\u7ec4\n            sectionArr&#91;cnt++] = section;\n            \/\/\u8f93\u51fa\u5757\u8868\u540d\u79f0\n            printf(\"%s\\n\", section-&gt;Name);\n        }\n\n        VaToFoa32(0x4198B0,dos, nt, sectionArr);\n        FoaToVa32(0x176B0, dos, nt, sectionArr);\n\n        break;\n    }\n\n    case IMAGE_NT_OPTIONAL_HDR64_MAGIC:\n    {\n        printf(\"64\u4f4d\u7a0b\u5e8f\\n\");\n        \/\/\u786e\u5b9a\u4e3a64\u4f4d\u7a0b\u5e8f\u540e\uff0c\u5c31\u53ef\u4ee5\u4f7f\u7528_IMAGE_NT_HEADERS64\u6765\u63a5\u6536\u6570\u636e\u4e86\n        \/\/\u521b\u5efa\u6307\u5411PE\u6587\u4ef6\u5934\u7684\u6307\u9488\n        _IMAGE_NT_HEADERS64* nt;\n        nt = (_IMAGE_NT_HEADERS64*)peId;\n        printf(\"Machine:%X\\n\", nt-&gt;FileHeader.Machine);\n        printf(\"Magic:%X\\n\", nt-&gt;OptionalHeader.Magic);\n\n        \/\/\u521b\u5efa\u4e00\u4e2a\u6307\u9488\u6570\u7ec4\uff0c\u8be5\u6307\u9488\u6570\u7ec4\u7528\u6765\u5b58\u50a8\u6240\u6709\u7684\u8282\u8868\u6307\u9488\n        \/\/\u8fd9\u91cc\u76f8\u5f53\u4e8e_IMAGE_SECTION_HEADER* sectionArr&#91;nt-&gt;FileHeader.NumberOfSections],\u58f0\u660e\u4e86\u4e00\u4e2a\u52a8\u6001\u6570\u7ec4\n        _IMAGE_SECTION_HEADER** sectionArr = (_IMAGE_SECTION_HEADER**)malloc(sizeof(_IMAGE_SECTION_HEADER*) * nt-&gt;FileHeader.NumberOfSections);\n\n        \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n        _IMAGE_SECTION_HEADER* sectionHeader;\n        \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740\uff0c\u533a\u522b\u5728\u4e8e\u8fd9\u91cc\u52a0\u4e0a\u7684\u504f\u79fb\u4e3a_IMAGE_NT_HEADERS64\n        sectionHeader = (_IMAGE_SECTION_HEADER*)((UINT)nt + sizeof(_IMAGE_NT_HEADERS64));\n        \/\/\u8ba1\u6570\uff0c\u7528\u6765\u8ba1\u7b97\u5757\u8868\u5730\u5740\n        int cnt = 0;\n        \/\/\u6bd4\u8f83 \u8ba1\u6570 \u548c \u5757\u8868\u7684\u4e2a\u6570\uff0c\u5373\u904d\u5386\u6240\u6709\u5757\u8868\n        while (cnt &lt; nt-&gt;FileHeader.NumberOfSections) {\n            \/\/\u521b\u5efa\u6307\u5411\u5757\u8868\u7684\u6307\u9488\n            _IMAGE_SECTION_HEADER* section;\n            \/\/\u8ba9\u5757\u8868\u7684\u6307\u9488\u6307\u5411\u5176\u5bf9\u5e94\u7684\u5730\u5740=\u7b2c\u4e00\u4e2a\u5757\u8868\u5730\u5740+\u8ba1\u6570*\u5757\u8868\u7684\u5927\u5c0f\n            section = (_IMAGE_SECTION_HEADER*)((UINT)sectionHeader + sizeof(_IMAGE_SECTION_HEADER) * cnt);\n            \/\/\u5c06\u5f97\u5230\u7684\u5757\u8868\u6307\u9488\u5b58\u5165\u6570\u7ec4\n            sectionArr&#91;cnt++] = section;\n            \/\/\u8f93\u51fa\u5757\u8868\u540d\u79f0\n            printf(\"%s\\n\", section-&gt;Name);\n        }\n        VaToFoa32(0x4198B0,dos, nt, sectionArr);\n        FoaToVa32(0x176B0, dos, nt, sectionArr);\n        break;\n    }\n\n    default:\n    {\n        printf(\"error!\\n\");\n        break;\n    }\n\n    }\n    return 0;\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">RVA\u548cFOA\u4e4b\u95f4\u7684\u5dee\u5f02\u5f52\u6839\u7ed3\u5e95\u5c31\u662f\u5728\u4e8e\u6587\u4ef6\u5bf9\u9f50\u548c\u5185\u5b58\u5bf9\u9f50\u7684\u5dee\u5f02\u4e0a<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u524d\u9762\u8865\u5145<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8e\u6b63\u7740\u8bfb\u548c\u5012\u7740\u8bfb<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u8ba1\u7b97\u673a\u4f7f\u7528\u5c0f\u7aef\u5e8f\u53ef\u4ee5\u52a0\u5feb\u8fd0\u884c\u901f\u5ea6\uff0c\u6240\u4ee5\u8ba1\u7b97\u673a\u7528\u4e8e\u8ba1\u7b97\uff0c\u5bfb\u5740\uff0c\u5224\u65ad\u5927\u5c0f\u7684\u6570\u636e\u90fd\u8981\u5012\u7740\u770b\uff0c\u5305\u62ec\u5730\u5740\u3001\u504f\u79fb\u91cf\u3001\u5927\u5c0f\u3001\u8ba1\u6570\u3001\u6807\u5fd7\u4f4d\u3001\u7279\u5f81\u503c\u3002\u4ece\u53f3\u5f80\u5de6\uff0c\u9ad8\u5730\u5740\u5f80\u4f4e\u5730\u5740<br>\u672c\u8eab\u7684\u5b57\u8282\u6570\u7ec4\u5f62\u5f0f\u5b58\u5728\u7684\u6570\u636e\uff0c\u8bbe\u8ba1\u7ed9\u4eba\u770b\u7684\u540d\u5b57\uff08\u6bd4\u5982text\u90a3\u4e9b\uff09\uff0c\u8981\u6b63\u7740\u8bfb<br>\u4f46\u662fmz\u548cpe\u7684\u6807\u5fd7\uff0c\u672c\u8d28\u662f\u6570\u636e\uff0c\u4f46\u88ab\u8bbe\u8ba1\u6210\u4e86\u5b57\u7b26\u4e32\u5f62\u5f0f<br>\u5728hex\u7f16\u8f91\u5668\u91cc\u6b63\u7740\u663e\u793a\uff0c\u4ee3\u7801\u91cc\u548c\u5206\u6790\u6570\u636e\u65f6\u5f97\u5012\u7740\u5199<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8e\u5bf9\u8c61\u548c\u6620\u50cf<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u8c61\u6587\u4ef6\uff0c\u5e38\u89c1\u540e\u7f00obj\uff0c\u5c31\u662f\u7f16\u8bd1c\u6216\u8005cpp\u6587\u4ef6\u65f6\u751f\u6210\u7684o\uff0c\u4e0d\u9700\u8981\u88ab\u6267\u884c\uff0c\u53ea\u662f\u534a\u6210\u54c1\uff0c\u76f4\u63a5\u4ee5coff\u6587\u4ef6\u5934\u5f00\u59cb\uff0c\u6ca1\u6709ms dos\u5934<br>\u6620\u50cf\u6587\u4ef6\uff0c\u5e38\u89c1\u540e\u7f00\uff0cexe\uff0cdll\uff0csys\uff0c\u94fe\u63a5\u5668linker\u4ea7\u7269\uff0c\u662f\u6210\u54c1\uff0c\u5c06\u591a\u4e2aobj\u6587\u4ef6\u548c\u5e93\u6587\u4ef6lib\u62fc\u88c5\u5728\u4e00\u8d77\u5f62\u6210\u6700\u7ec8\u6587\u4ef6\uff08\u6620\u50cf\u89e3\u91ca\uff0c\u7ed3\u6784\u88ab\u8bbe\u8ba1\u4e3a\u53ef\u4ee5\u76f4\u63a5\u6620\u5c04\u5230\u5185\u5b58\u4e0a\u8fd0\u884c\uff0c\u5728\u78c1\u76d8\u6837\u5b50\u548c\u52a0\u8f7d\u5230\u5185\u5b58\u4e2d\u5f88\u60f3\uff0c\u4e3a\u4e86\u517c\u5bb9\uff0c\u5fc5\u987b\u4ee5msdos\u5934\u548c\u5b58\u6839\u5f00\u59cb\uff0c\u7136\u540e\u662fpe\u7b7e\u540d\uff0c\u7136\u540e\u662fcoff\u6587\u4ef6\u5934\uff09<br>\u4e24\u8005\u5e03\u5c40\u533a\u522b<br>\u5bf9\u8c61\u6587\u4ef6<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; COFF \u6587\u4ef6\u5934 ] &lt;--- \u6587\u4ef6\u76f4\u63a5\u4ece\u8fd9\u91cc\u5f00\u59cb (\u504f\u79fb\u91cf 0)\n&#91; \u8282\u8868 ]\n&#91; \u539f\u59cb\u6570\u636e... ]<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u6620\u50cf\u6587\u4ef6<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>&#91; MS-DOS \u5934 ]\n&#91; MS-DOS \u5b58\u6839 ]\n&#91; PE \u7b7e\u540d ]\n&#91; COFF \u6587\u4ef6\u5934 ] &lt;--- \u8fd9\u91cc\u624d\u662f COFF \u5934\uff0c\u7ed3\u6784\u4e0e\u4e0a\u9762\u4e00\u6837\uff0c\u4f46\u4f4d\u7f6e\u9760\u540e\n&#91; \u53ef\u9009\u5934 (Optional Header) ] &lt;--- \u6620\u50cf\u6587\u4ef6\u7279\u6709\n&#91; \u8282\u8868 ]\n&#91; \u539f\u59cb\u6570\u636e... ]<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u5173\u4e8edos<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5934\u548c\u5b58\u6839\uff0c\u5934\u6307\u5143\u6570\u636e\uff0c\u63cf\u8ff0\u6587\u4ef6\u7684\u4f5c\u7528\uff0c\u7ed3\u6784\u5316\u6570\u636e\uff0c\u544a\u8bc9window\u7cfb\u7edf\uff08\u52a0\u8f7d\u5668\uff09\u5904\u7406\u6587\u4ef6\u7684\u65b9\u5f0f\uff0c\u63cf\u8ff0\u6587\u4ef6\u6570\u636e\u7ed3\u6784\uff0c\u5b58\u6839\uff08stub\uff09\u662f\u4e00\u6bb5\u53ef\u4ee5\u6267\u884c\u7684\u673a\u5668\u7801\uff0c\u517c\u5bb9\u6027\u5904\u7406\uff0cms ods stub\u662f\u4e00\u4e2a\u5b8c\u6574\u768416\u4f4ddos\u7a0b\u5e8f\uff0c\u5b58\u50a8\u5728pe\u6587\u4ef6\u7684\u5934\u90e8<br>dos\uff0c\u78c1\u76d8\u64cd\u4f5c\u7cfb\u7edf<br>stub\u4f5c\u7528\uff0c\u9632\u62a5\u9519\uff0c\u5c31\u662f\u6bd4\u598216\u4f4d\u7cfb\u7edf\u8bc6\u522b\u4e0d\u4e86\uff0c\u5c31\u76f4\u63a5\u901a\u8fc7stub\u7ec8\u6b62\u7a0b\u5e8f\uff0c\u4f46\u662fwindow\uff0cdos\u5934\u90a3\u91cc\u6709\u504f\u79fb\u91cf\uff0c\u5c31\u4f1a\u8df3\u8fc7\u8fd9\u4e2astub<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u4e00\u4e9b\u96f6\u788e\u6982\u5ff5<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u540d\u79f0<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u63cf\u8ff0<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5c5e\u6027\u8bc1\u4e66<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7528\u4e8e\u5c06\u53ef\u9a8c\u8bc1\u58f0\u660e\u4e0e\u6620\u50cf\u5173\u8054\u7684\u8bc1\u4e66\u3002\u8bb8\u591a\u4e0d\u540c\u7684\u53ef\u9a8c\u8bc1\u58f0\u660e\u53ef\u4ee5\u4e0e\u6587\u4ef6\u76f8\u5173\u8054\uff1b\u5176\u4e2d\u6700\u6709\u7528\u7684\u4e00\u4e2a\u58f0\u660e\u662f\u8f6f\u4ef6\u5236\u9020\u5546\u7684\u58f0\u660e\uff0c\u6b64\u58f0\u660e\u6307\u793a\u6620\u50cf\u7684\u6d88\u606f\u6458\u8981\u5e94\u8be5\u662f\u4ec0\u4e48\u3002\u6d88\u606f\u6458\u8981\u7c7b\u4f3c\u4e8e\u68c0\u9a8c\u548c\uff0c\u53ea\u662f\u5f88\u96be\u4f2a\u9020\u3002\u56e0\u6b64\uff0c\u5f88\u96be\u4fee\u6539\u6587\u4ef6\u4ee5\u4f7f\u5176\u5177\u6709\u4e0e\u539f\u59cb\u6587\u4ef6\u76f8\u540c\u7684\u6d88\u606f\u6458\u8981\u3002\u53ef\u4ee5\u4f7f\u7528\u516c\u94a5\u6216\u79c1\u94a5\u52a0\u5bc6\u65b9\u6848\u6765\u9a8c\u8bc1\u58f0\u660e\u662f\u5426\u662f\u7531\u5236\u9020\u5546\u53d1\u51fa\u7684\u3002\u672c\u6587\u6863\u63cf\u8ff0\u4e86\u6709\u5173\u5c5e\u6027\u8bc1\u4e66\u7684\u8be6\u7ec6\u4fe1\u606f\uff0c\u4f46\u4e0d\u5141\u8bb8\u5c06\u5176\u63d2\u5165\u5230\u56fe\u50cf\u6587\u4ef6\u4e2d\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u65e5\u671f\/\u65f6\u95f4\u6233<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5728 PE \u6216 COFF \u6587\u4ef6\u4e2d\u7684\u591a\u4e2a\u4f4d\u7f6e\u7528\u4e8e\u4e0d\u540c\u76ee\u7684\u7684\u6233\u8bb0\u3002\u5728\u5927\u591a\u6570\u60c5\u51b5\u4e0b\uff0c\u6bcf\u4e2a\u6233\u8bb0\u7684\u683c\u5f0f\u4e0e C \u8fd0\u884c\u65f6\u5e93\u4e2d\u7684\u65f6\u95f4\u51fd\u6570\u4f7f\u7528\u7684\u683c\u5f0f\u76f8\u540c\u3002\u6709\u5173\u5f02\u5e38\uff0c\u8bf7\u53c2\u89c1\u8c03\u8bd5\u7c7b\u578b\u4e2d IMAGE_DEBUG_TYPE_REPRO \u7684\u8bf4\u660e\u3002\u5982\u679c\u6233\u8bb0\u503c\u4e3a 0 \u6216 0xFFFFFFFF\uff0c\u5219\u5b83\u4e0d\u8868\u793a\u5b9e\u9645\u6216\u6709\u610f\u4e49\u7684\u65e5\u671f\/\u65f6\u95f4\u6233\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u6587\u4ef6\u6307\u9488<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u94fe\u63a5\u5668\uff08\u5bf9\u4e8e\u76ee\u6807\u6587\u4ef6\uff09\u6216\u52a0\u8f7d\u5668\uff08\u5bf9\u4e8e\u6620\u50cf\u6587\u4ef6\uff09\u5904\u7406\u4e4b\u524d\u6587\u4ef6\u672c\u8eab\u4e2d\u9879\u7684\u4f4d\u7f6e\u3002\u6362\u53e5\u8bdd\u8bf4\uff0c\u8fd9\u662f\u5b58\u50a8\u5728\u78c1\u76d8\u4e0a\u7684\u6587\u4ef6\u5185\u7684\u4f4d\u7f6e\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u94fe\u63a5\u5668<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u968f Microsoft Visual Studio \u4e00\u8d77\u63d0\u4f9b\u7684\u94fe\u63a5\u5668\u5f15\u7528\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5bf9\u8c61\u6587\u4ef6<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4f5c\u4e3a\u94fe\u63a5\u5668\u8f93\u5165\u63d0\u4f9b\u7684\u6587\u4ef6\u3002\u94fe\u63a5\u5668\u751f\u6210\u4e00\u4e2a\u6620\u50cf\u6587\u4ef6\uff0c\u800c\u6b64\u6620\u50cf\u6587\u4ef6\u53c8\u7528\u4f5c\u52a0\u8f7d\u5668\u7684\u8f93\u5165\u3002\u672f\u8bed\u201c\u76ee\u6807\u6587\u4ef6\u201d\u5e76\u4e0d\u4e00\u5b9a\u610f\u5473\u7740\u4e0e\u9762\u5411\u5bf9\u8c61\u7684\u7f16\u7a0b\u6709\u4efb\u4f55\u8054\u7cfb\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5df2\u4fdd\u7559\uff0c\u5fc5\u987b\u4e3a 0<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5b57\u6bb5\u7684\u63cf\u8ff0\uff0c\u6307\u793a\u8be5\u5b57\u6bb5\u7684\u503c\u5bf9\u4e8e\u751f\u6210\u5668\u6765\u8bf4\u5fc5\u987b\u4e3a\u96f6\uff0c\u800c\u4f7f\u7528\u8005\u5fc5\u987b\u5ffd\u7565\u8be5\u5b57\u6bb5\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u76f8\u5bf9\u865a\u62df\u5730\u5740 (RVA)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5728\u6620\u50cf\u6587\u4ef6\u4e2d\uff0c\u8fd9\u662f\u9879\u76ee\u52a0\u8f7d\u5230\u5185\u5b58\u5e76\u4ece\u4e2d\u51cf\u53bb\u6620\u50cf\u6587\u4ef6\u57fa\u5730\u5740\u540e\u7684\u5730\u5740\u3002\u9879\u76ee\u7684 RVA \u51e0\u4e4e\u603b\u662f\u4e0e\u5176\u5728\u78c1\u76d8\u4e0a\u6587\u4ef6\u4e2d\u7684\u4f4d\u7f6e\uff08\u6587\u4ef6\u6307\u9488\uff09\u4e0d\u540c\u3002<br>\u5728\u76ee\u6807\u6587\u4ef6\u4e2d\uff0cRVA \u7684\u610f\u4e49\u4e0d\u5927\uff0c\u56e0\u4e3a\u672a\u5206\u914d\u5185\u5b58\u4f4d\u7f6e\u3002\u5728\u8fd9\u79cd\u60c5\u51b5\u4e0b\uff0cRVA \u5c06\u662f\u4e00\u4e2a\u6bb5\u5185\u7684\u5730\u5740\uff08\u6b64\u8868\u540e\u9762\u5c06\u8fdb\u884c\u63cf\u8ff0\uff09\uff0c\u7a0d\u540e\u5728\u94fe\u63a5\u671f\u95f4\u4f1a\u5bf9\u6b64\u5730\u5740\u5e94\u7528\u91cd\u5b9a\u4f4d\u3002\u4e3a\u7b80\u5355\u8d77\u89c1\uff0c\u7f16\u8bd1\u5668\u5e94\u53ea\u5c06\u6bcf\u4e2a\u90e8\u5206\u4e2d\u7684\u7b2c\u4e00\u4e2a RVA \u8bbe\u7f6e\u4e3a\u96f6\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u90e8\u5206<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">PE \u6216 COFF \u6587\u4ef6\u4e2d\u4ee3\u7801\u6216\u6570\u636e\u7684\u57fa\u672c\u5355\u4f4d\u3002\u4f8b\u5982\uff0c\u76ee\u6807\u6587\u4ef6\u4e2d\u7684\u6240\u6709\u4ee3\u7801\u90fd\u53ef\u4ee5\u7ec4\u5408\u5728\u5355\u4e2a\u90e8\u5206\u4e2d\uff0c\u6216\u8005\uff08\u53d6\u51b3\u4e8e\u7f16\u8bd1\u5668\u884c\u4e3a\uff09\u6bcf\u4e2a\u51fd\u6570\u90fd\u53ef\u4ee5\u5360\u7528\u81ea\u5df1\u7684\u90e8\u5206\u3002\u90e8\u5206\u8d8a\u591a\uff0c\u6587\u4ef6\u5f00\u9500\u5c31\u8d8a\u5927\uff0c\u4f46\u94fe\u63a5\u5668\u80fd\u591f\u66f4\u6709\u9009\u62e9\u6027\u5730\u94fe\u63a5\u4ee3\u7801\u3002\u4e00\u4e2a\u90e8\u5206\u7c7b\u4f3c\u4e8e Intel 8086 \u4f53\u7cfb\u7ed3\u6784\u4e2d\u7684\u6bb5\u3002\u4e00\u4e2a\u90e8\u5206\u4e2d\u7684\u6240\u6709\u539f\u59cb\u6570\u636e\u90fd\u5fc5\u987b\u8fde\u7eed\u52a0\u8f7d\u3002\u6b64\u5916\uff0c\u6620\u50cf\u6587\u4ef6\u53ef\u4ee5\u5305\u542b\u591a\u4e2a\u5177\u6709\u7279\u6b8a\u7528\u9014\u7684\u90e8\u5206\uff0c\u4f8b\u5982 .tls \u6216 .reloc \u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u865a\u62df\u5730\u5740 (VA)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4e0e RVA \u76f8\u540c\uff0c\u53ea\u4e0d\u8fc7\u4e0d\u51cf\u53bb\u6620\u50cf\u6587\u4ef6\u7684\u57fa\u5740\u3002\u8be5\u5730\u5740\u79f0\u4e3a VA\uff0c\u56e0\u4e3a Windows \u4f1a\u4e3a\u6bcf\u4e2a\u8fdb\u7a0b\u521b\u5efa\u4e00\u4e2a\u72ec\u7acb\u4e8e\u7269\u7406\u5185\u5b58\u7684\u4e0d\u540c VA \u7a7a\u95f4\u3002\u5bf9\u4e8e\u51e0\u4e4e\u6240\u6709\u76ee\u7684\uff0cVA \u5e94\u53ea\u88ab\u89c6\u4e3a\u4e00\u4e2a\u5730\u5740\u3002VA \u4e0d\u5982 RVA \u90a3\u4e48\u53ef\u9884\u6d4b\uff0c\u56e0\u4e3a\u52a0\u8f7d\u5668\u53ef\u80fd\u4e0d\u4f1a\u5728\u5176\u9996\u9009\u4f4d\u7f6e\u52a0\u8f7d\u6620\u50cf\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u82f1\u6587\u672f\u8bed<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u4e2d\u6587\u672f\u8bed<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u63cf\u8ff0<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Virtual Address (VA)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u865a\u62df\u5730\u5740<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8fdb\u7a0b\u865a\u62df\u5185\u5b58\u7a7a\u95f4\u4e2d\u7684\u7edd\u5bf9\u5730\u5740\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Relative Virtual Address (RVA)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u76f8\u5bf9\u865a\u62df\u5730\u5740<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5185\u5b58\u5730\u5740\u76f8\u5bf9\u4e8e\u6a21\u5757\u57fa\u5740\u7684\u504f\u79fb\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>File Pointer<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u6307\u9488<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u5728\u78c1\u76d8\u4e0a\u7684\u7269\u7406\u504f\u79fb\u4f4d\u7f6e\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Section<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8282 \/ \u6bb5<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4ee3\u7801\u6216\u6570\u636e\u7684\u903b\u8f91\u5206\u7ec4\uff0c\u5177\u6709\u76f8\u540c\u7684\u5185\u5b58\u5c5e\u6027\uff08\u5982\u53ea\u8bfb\u3001\u53ef\u6267\u884c\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Data Directory<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u76ee\u5f55<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4f4d\u4e8e\u53ef\u9009\u5934\u672b\u5c3e\u7684\u6570\u7ec4\uff0c\u6307\u5411\u5404\u79cd\u8868\uff08\u5bfc\u5165\u3001\u5bfc\u51fa\u3001\u8d44\u6e90\u7b49\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Thunk<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8f6c\u6362\u5c42 \/ \u6869\u4ee3\u7801<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8fd9\u91cc\u901a\u5e38\u6307\u5bfc\u5165\u5730\u5740\u8868 (IAT) \u4e2d\u7684\u9879\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h1 class=\"wp-block-heading\">ELF<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">\u6bd4\u8d77PE\uff0cELF\u5206\u4e86section\u7ed9\u7f16\u8bd1\u5668\u548csegment\u7ed9\u52a0\u8f7d\u5668\uff0c\u5904\u7406\u5916\u90e8\u51fd\u6570\u7684\u65f6\u5019\u8c03\u7528\u4e86GOT\/PLT\uff08\u5ef6\u8fdf\u7ed1\u5b9a\uff09\uff0cPE\u5219\u7528\u7684IAT<br>elf\u683c\u5f0f\u7531system v\u6807\u51c6\u5b9a\u4e49\uff0c\u8bbe\u8ba1\u66f4\u7075\u6d3b\uff0c\u652f\u6301\u53ef\u6267\u884c\u6587\u4ef6\uff0c\u5171\u4eab\u5e93\uff0c\u76ee\u6807\u6587\u4ef6\u7b49\u591a\u79cd\u7c7b\u578b<br>\u5e38\u89c1\u540e\u7f00<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u65e0\u540e\u7f00\u6216.bin\uff0c\u53ef\u6267\u884c\u6587\u4ef6\u5982\/bin\/ls\u3001\/usr\/bin\/python3\uff0c\u901a\u5e38\u65e0\u540e\u7f00<\/li>\n\n\n\n<li>.so\uff0c\u5171\u4eab\u5bf9\u8c61\uff0c\u7c7b\u4f3cwindows\u7684dll\uff0c\u63d0\u4f9b\u52a8\u6001\u94fe\u63a5\u529f\u80fd<\/li>\n\n\n\n<li>.a,\u9759\u6001\u94fe\u63a5\u5e93\uff0c\u5305\u542b\u591a\u4e2a\u76ee\u6807\u6587\u4ef6\u5f52\u6863\uff0c\u7f16\u8bd1\u65f6\u4f1a\u88ab\u5b8c\u6574\u5d4c\u5165\u53ef\u6267\u884c\u6587\u4ef6<\/li>\n\n\n\n<li>.o,\u76ee\u6807\u6587\u4ef6\uff0c\u7f16\u8bd1\u5668\u8f93\u51fa\u7684\u4e2d\u95f4\u6587\u4ef6\uff0c\u8981\u94fe\u63a5\u5668\u5904\u7406\u540e\u751f\u6210\u53ef\u6267\u884c\u6587\u4ef6<\/li>\n\n\n\n<li>.ko\uff0c\u5185\u6838\u6a21\u5757\uff0clinux\u5185\u6838\u7684\u9a71\u52a8\u7a0b\u5e8f\uff0c\u8fd0\u884c\u4e8e\u5185\u6838\u7a7a\u95f4\uff0c\u76f8\u5f53\u4e8ewindow\u91cc\u9762\u7684.sys\uff08\u9a71\u52a8\u7a0b\u5e8f\uff09\uff0c\u8fd0\u884c\u5728ring 0(\u6700\u9ad8\u6743\u9650)\uff0c\u6bd4\u8d77\u666e\u901aelf\uff0cko\u9a71\u52a8\u6ca1\u6709main\uff0c\u53ea\u6709module_init()\uff08\u63d2\u5165\u6a21\u5757\u65f6\u6267\u884c\uff09\u548c\u5bf9\u5e94\u7684exit\uff0c\u4f1a\u770b\u5230\u5927\u91cf\u91cd\u5b9a\u4f4d\u8868\uff0c\u56e0\u4e3a\u8981\u88ab\u201c\u94fe\u63a5\u201d\u8fdb\u5185\u6838<\/li>\n\n\n\n<li>.mod\uff0c\u90e8\u5206\u7cfb\u7edf\u7684\u6a21\u5757\u6587\u4ef6\uff0c\u5982\u65e9\u671funix\u529f\u80fd\u7c7b\u4f3cko\uff0c\u5305\u542b\u4e86\u6a21\u5757\u7684\u7248\u672c\u4fe1\u606f\uff08Version Magic\uff09\u548c\u7b26\u53f7\u4f9d\u8d56\u5173\u7cfb\u3002<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">\u7ed3\u6784<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">\u533a\u57df\u4f4d\u7f6e<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u7ec4\u4ef6\u540d\u79f0 (\u4e2d\u6587)<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u82f1\u6587\u5bf9\u5e94<\/th><th class=\"has-text-align-left\" data-align=\"left\">\u8bf4\u660e<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u9876\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>ELF \u6587\u4ef6\u5934<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">ELF Header<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6587\u4ef6\u7684\u603b\u7d22\u5f15\uff0c\u5305\u542b\u9b54\u6570\u3001\u7248\u672c\u7b49\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e0a\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u7a0b\u5e8f\u5934\u90e8\u8868<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Program Header Table<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u63cf\u8ff0\u6bb5\uff08Segment\uff09\u4fe1\u606f\uff0c\u7528\u4e8e\u6267\u884c\u89c6\u56fe\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.text<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Code Section<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u4ee3\u7801\u8282\uff08\u6307\u4ee4\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.data<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Data Section<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u6570\u636e\u8282\uff08\u5df2\u521d\u59cb\u5316\u5168\u5c40\u53d8\u91cf\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.bss<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">BSS Section<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u672a\u521d\u59cb\u5316\u6570\u636e\u8282\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.symtab<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Symbol Table<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u7b26\u53f7\u8868\uff08\u51fd\u6570\u540d\u3001\u53d8\u91cf\u540d\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.debug<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Debug Info<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u8c03\u8bd5\u4fe1\u606f\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>.line<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Line Number Table<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u884c\u53f7\u8868\uff08\u6e90\u7801\u884c\u53f7\u5bf9\u5e94\uff09\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u4e2d\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u2026<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Others<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u5176\u4ed6\u5404\u7c7b\u8282\u3002<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u5e95\u90e8<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>\u8282\u533a\u5934\u90e8\u8868<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Section Header Table<\/td><td class=\"has-text-align-left\" data-align=\"left\">\u63cf\u8ff0\u8282\uff08Section\uff09\u4fe1\u606f\uff0c\u94fe\u63a5\u89c6\u56fe\u7684\u6838\u5fc3\uff0c\u8bb0\u5f55\u4e86\u4e0a\u9762\u6240\u6709\u8282\u7684\u4f4d\u7f6e\u3002<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">ELF\u5934\u90e8<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u6587\u4ef6\u8d77\u59cb\u4f4d\u7f6e\uff0c\u56fa\u5b9a\u5927\u5c0f\uff0832\u4f4d\u4e3a52\u5b57\u8282\uff0c64\u4f4d\u4f4d64\u5b57\u8282\uff09<br>\u7ed3\u6784\u4f53<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#define EI_NIDENT 16\ntypedef struct {\n    unsigned char e_ident&#91;EI_NIDENT];  \/\/ ELF\u6807\u8bc6\u7b26\n    Elf32_Half    e_type;             \/\/ \u6587\u4ef6\u7c7b\u578b\n    Elf32_Half    e_machine;          \/\/ \u76ee\u6807\u67b6\u6784\n    Elf32_Word    e_version;          \/\/ ELF\u7248\u672c\n    Elf32_Addr    e_entry;            \/\/ \u7a0b\u5e8f\u5165\u53e3\u70b9\n    Elf32_Off     e_phoff;            \/\/ \u7a0b\u5e8f\u5934\u8868\u504f\u79fb\n    Elf32_Off     e_shoff;            \/\/ \u8282\u5934\u8868\u504f\u79fb\n    Elf32_Word    e_flags;            \/\/ \u5904\u7406\u5668\u7279\u5b9a\u6807\u5fd7\n    Elf32_Half    e_ehsize;           \/\/ ELF\u5934\u90e8\u5927\u5c0f\n    Elf32_Half    e_phentsize;        \/\/ \u7a0b\u5e8f\u5934\u8868\u9879\u5927\u5c0f\n    Elf32_Half    e_phnum;            \/\/ \u7a0b\u5e8f\u5934\u8868\u9879\u6570\u91cf\n    Elf32_Half    e_shentsize;        \/\/ \u8282\u5934\u8868\u9879\u5927\u5c0f\n    Elf32_Half    e_shnum;            \/\/ \u8282\u5934\u8868\u9879\u6570\u91cf\n    Elf32_Half    e_shstrndx;         \/\/ \u8282\u540d\u79f0\u5b57\u7b26\u4e32\u8868\u7d22\u5f15\n} Elf32_Ehdr;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">\u5176\u4e2d\uff0ce_ident\u5b57\u6bb5\u7684\u524d4\u4e2a\u5b57\u8282\u56fa\u5b9a\u4e3a0x7f\u3001&#8217;E&#8217;\u3001&#8217;L&#8217;\u3001&#8217;F&#8217;\uff0c\u8fd9\u662fELF\u6587\u4ef6\u7684\u9b54\u6570\u6807\u8bc6\u3002<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u7a0b\u5e8f\u5934\u8868\uff08Program Header Table\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u63cf\u8ff0\u6bb5\uff08segment\uff09\u4fe1\u606f\uff0c\u7528\u4e8e\u7a0b\u5e8f\u52a0\u8f7d\u548c\u6267\u884c<br>\u7ed3\u6784\u4f53<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct {\n    Elf32_Word p_type;    \/\/ \u6bb5\u7c7b\u578b\n    Elf32_Off  p_offset;  \/\/ \u6bb5\u5728\u6587\u4ef6\u4e2d\u7684\u504f\u79fb\n    Elf32_Addr p_vaddr;   \/\/ \u6bb5\u5728\u5185\u5b58\u4e2d\u7684\u865a\u62df\u5730\u5740\n    Elf32_Addr p_paddr;   \/\/ \u7269\u7406\u5730\u5740(\u901a\u5e38\u4e0e\u865a\u62df\u5730\u5740\u76f8\u540c)\n    Elf32_Word p_filesz;  \/\/ \u6bb5\u5728\u6587\u4ef6\u4e2d\u7684\u5927\u5c0f\n    Elf32_Word p_memsz;   \/\/ \u6bb5\u5728\u5185\u5b58\u4e2d\u7684\u5927\u5c0f\n    Elf32_Word p_flags;   \/\/ \u6bb5\u6807\u5fd7(\u8bfb\/\u5199\/\u6267\u884c)\n    Elf32_Word p_align;   \/\/ \u6bb5\u5bf9\u9f50\u65b9\u5f0f\n} Elf32_Phdr;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u8282\u5934\u8868\uff08Section Header Table\uff09<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u63cf\u8ff0\u8282\u7684\u4fe1\u606f\uff08section\uff09\uff0c\u4e3b\u8981\u7528\u4e8e\u94fe\u63a5\u548c\u8c03\u8bd5<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>typedef struct {\n    Elf32_Word sh_name;      \/\/ \u8282\u540d\u79f0(\u5b57\u7b26\u4e32\u8868\u7d22\u5f15)\n    Elf32_Word sh_type;      \/\/ \u8282\u7c7b\u578b\n    Elf32_Word sh_flags;     \/\/ \u8282\u6807\u5fd7\n    Elf32_Addr sh_addr;      \/\/ \u8282\u5728\u5185\u5b58\u4e2d\u7684\u5730\u5740\n    Elf32_Off  sh_offset;    \/\/ \u8282\u5728\u6587\u4ef6\u4e2d\u7684\u504f\u79fb\n    Elf32_Word sh_size;      \/\/ \u8282\u5927\u5c0f\n    Elf32_Word sh_link;      \/\/ \u94fe\u63a5\u5230\u5176\u4ed6\u8282\u7684\u7d22\u5f15\n    Elf32_Word sh_info;      \/\/ \u9644\u52a0\u4fe1\u606f\n    Elf32_Word sh_addralign; \/\/ \u8282\u5bf9\u9f50\u65b9\u5f0f\n    Elf32_Word sh_entsize;   \/\/ \u6761\u76ee\u5927\u5c0f(\u5982\u679c\u6709)\n} Elf32_Shdr;<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">\u8282<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u8282\u5b58\u50a8\u5b9e\u9645\u5185\u5bb9\uff0c\u5e38\u89c1\u8282\u6709\uff1a<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>.text\uff1a\u53ef\u6267\u884c\u4ee3\u7801<\/li>\n\n\n\n<li>.data\uff1a\u5df2\u521d\u59cb\u5316\u7684\u5168\u5c40\u53d8\u91cf<\/li>\n\n\n\n<li>.bss\uff1a\u672a\u521d\u59cb\u5316\u7684\u5168\u5c40\u53d8\u91cf(\u4e0d\u5360\u7528\u6587\u4ef6\u7a7a\u95f4)<\/li>\n\n\n\n<li>.rodata\uff1a\u53ea\u8bfb\u6570\u636e<\/li>\n\n\n\n<li>.symtab\uff1a\u7b26\u53f7\u8868<\/li>\n\n\n\n<li>.strtab\uff1a\u5b57\u7b26\u4e32\u8868<\/li>\n\n\n\n<li>.rel.*\uff1a\u91cd\u5b9a\u4f4d\u4fe1\u606f<\/li>\n\n\n\n<li>.dynamic\uff1a\u52a8\u6001\u94fe\u63a5\u4fe1\u606f<\/li>\n\n\n\n<li>.interp\uff1a\u7a0b\u5e8f\u89e3\u91ca\u5668\u8def\u5f84(\u5982\/lib\/ld-linux.so.2\uff09<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">ELF\u6587\u4ef6\u7684\u4e24\u79cd\u89c6\u56fe<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">\u94fe\u63a5\u89c6\u56fe<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u5e94\u8282\u5934\u8868\uff0c\u5c06\u6587\u4ef6\u6309\u529f\u80fd\u5212\u5206\u4e3a\u591a\u4e2a\u8282\uff0c\u4e3b\u8981\u7528\u4e8e\u9759\u6001\u94fe\u63a5\u8fc7\u7a0b\uff0c\u7279\u70b9\u662f\u7c92\u5ea6\u7ec6\uff08\u5c31\u662f\u5206\u7c7b\u7ec6\uff09\uff0c\u4fbf\u4e8e\u7f16\u8bd1\u5668\u751f\u6210\u548c\u94fe\u63a5\u5668\u5904\u7406\uff0c\u5b9e\u9645\u6267\u884c\u4e2d\uff0c\u94fe\u63a5\u5668\u4f1a\u5c06\u591a\u4e2a\u8282\u5408\u5e76\u6210\u6bb5\u63d0\u9ad8\u7a7a\u95f4\u5229\u7528\u7387<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\u6267\u884c\u89c6\u56fe<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u5bf9\u5e94\u7a0b\u5e8f\u5934\u8868\uff0c\u63cf\u8ff0\u4e86\u600e\u4e48\u5c06\u6587\u4ef6\u5185\u5bb9\u6620\u5c04\u5230\u8fdb\u7a0b\u7684\u865a\u62df\u5730\u5740\u7a7a\u95f4\uff0c\u5173\u6ce8\u6bb5<br>\u6309\u7167\u6743\u9650\u5408\u5e76\uff0c\u6bd4\u5982text\u548crodata\u90fd\u53ea\u8bfb\uff0cdata\u548cbss\u90fd\u53ef\u8bfb\u53ef\u5199<br>\u5e38\u89c1\u6bb5\u7c7b\u578b<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>PT_LOAD,\u901a\u5e38\u4e00\u4e2a\u7a0b\u5e8f\u81f3\u5c11\u4e24\u4e2aptload\u6bb5\uff0c\u4e00\u4e2a\u53ea\u8bfb\uff0c\u4e00\u4e2a\u8bfb\u5199<\/li>\n\n\n\n<li>PT_DYNAMIC\uff0c\u52a8\u6001\u94fe\u63a5\u6bb5\uff0c\u5bf9\u5e94\u8282.dynamic,\u63cf\u8ff0\u9700\u8981\u54ea\u4e2aso\u5e93\uff08DT_NEEDED\uff09\uff0c\u7b26\u53f7\u8868\uff0c\u91cd\u5b9a\u4f4d\u8868\uff0c\u521d\u59cb\u5316\u51fd\u6570\uff0c\u8c03\u7528\u5916\u90e8\u5e93\u51fd\u6570<\/li>\n\n\n\n<li>PT_INTERP\uff0c\u89e3\u91ca\u5668\u8def\u5f84\uff0c\u5bf9\u5e94\u8282.interp\uff0c\u901a\u5e38\u662f\u5b57\u7b26\u4e32\uff0c\u8def\u5f84\u6307\u5411\u52a8\u6001\u94fe\u63a5\u5668\uff0c\u8fd0\u884c\u524d\u51c6\u5907<\/li>\n\n\n\n<li>PT_NOTE\uff0c\u5bf9\u5e94\u8282.note.ABU-tag\u7b49\uff0c\u8f85\u52a9\u8bf4\u660e<\/li>\n\n\n\n<li>PT_TLS\uff0c\u7ebf\u7a0b\u5c40\u90e8\u5b58\u50a8\uff0c\u5bf9\u5e94\u8282\uff0c.tdata,.tbss\uff0c\u544a\u8bc9\u7cfb\u7edf\u5982\u4f55\u4e3a\u6bcf\u4e2a\u7ebf\u7a0b\u521d\u59cb\u5316\u53d8\u91cf<\/li>\n\n\n\n<li>PT_GNU_STACK\uff0c\u6808\u63a7\u5236\uff0c\u865a\u62df\u6bb5\uff0c\u544a\u8bc9\u6808\u662f\u5426\u53ef\u6267\u884c<br>PT\uff0c\u7ed9\u64cd\u4f5c\u7cfb\u7edf\u5185\u6838\u770b\uff0c\u51b3\u5b9a\u6bb5\u5c5e\u6027\uff0cDT\uff0c\u7ed9\u52a8\u6001\u94fe\u63a5\u5668\u770b\uff0c\u51b3\u5b9a\u52a8\u6001\u94fe\u63a5\u7ec6\u8282<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">\u9759\u6001\u94fe\u63a5<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u9759\u6001\u94fe\u63a5\u8fc7\u7a0b<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u5728\u7f16\u8bd1\u65f6\u5c06\u5e93\u4ee3\u7801\u76f4\u63a5\u590d\u5236\u5230\u6700\u7ec8\u53ef\u6267\u884c\u6587\u4ef6\u7684\u94fe\u63a5\u65b9\u5f0f\uff0c\u8fc7\u7a0b\u5982<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u7f16\u8bd1\u5668\u751f\u6210\u76ee\u6807\u6587\u4ef6.o<\/li>\n\n\n\n<li>\u94fe\u63a5\u5668\u626b\u63cf\u6240\u6709\u76ee\u6807\u6587\u4ef6\u548c\u9759\u6001\u5e93.a<\/li>\n\n\n\n<li>\u89e3\u6790\u6240\u6709\u7b26\u53f7\u5f15\u7528<\/li>\n\n\n\n<li>\u5c06\u4f7f\u7528\u7684\u5e93\u4ee3\u7801\u590d\u5236\u5230\u53ef\u6267\u884c\u6587\u4ef6<\/li>\n\n\n\n<li>\u751f\u6210\u5b8c\u5168\u72ec\u7acb\u7684\u53ef\u6267\u884c\u6587\u4ef6<br>\u7279\u70b9\uff1a\u5730\u5740\u9884\u786e\u5b9a\uff0c\u94fe\u63a5\u9636\u6bb5\u4e3a\u6240\u6709\u7b26\u53f7\u5206\u914d\u6700\u7ec8\u865a\u62df\u5730\u5740<\/li>\n<\/ol>\n\n\n\n<h4 class=\"wp-block-heading\">\u9759\u6001\u52a0\u8f7d\u8fc7\u7a0b<\/h4>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u89e3\u6790elf\u6587\u4ef6\u5934\u90e8\uff0c\u9a8c\u8bc1\u6587\u4ef6\u683c\u5f0f<\/li>\n\n\n\n<li>\u6839\u636e\u7a0b\u5e8f\u5934\u8868\u5c06\u5404\u6bb5\u6620\u5c04\u5230\u94fe\u63a5\u65f6\u786e\u5b9a\u7684\u56fa\u5b9a\u865a\u62df\u5730\u5740<\/li>\n\n\n\n<li>\u5efa\u7acb\u5185\u5b58\u7ba1\u7406\u7ed3\u6784(mm_struct)\u7ba1\u7406\u865a\u62df\u5185\u5b58\u533a\u57df\uff08VMA)<\/li>\n\n\n\n<li>\u521d\u59cb\u5316\u9875\u8868\u6620\u5c04<\/li>\n\n\n\n<li>cpu\u76f4\u63a5\u4eceelf\u5934\u90e8\u7684e_entry\u83b7\u53d6\u5165\u53e3\u5730\u5740\u5f00\u59cb\u6267\u884c<br>\u6240\u6709\u5185\u5b58\u8bbf\u95ee\u90fd\u4f7f\u7528\u7edd\u5bf9\u5730\u5740\uff0c\u901a\u8fc7MMU\u786c\u4ef6\u5c06\u94fe\u63a5\u65f6\u786e\u5b9a\u7684\u865a\u62df\u5730\u5740\u8f6c\u6362\u4e3a\u7269\u7406\u5730\u5740\u3002\u6574\u4e2a\u8fc7\u7a0b\u5b8c\u5168\u590d\u7528\u94fe\u63a5\u9636\u6bb5\u786e\u5b9a\u7684\u5730\u5740\u5e03\u5c40\uff0c\u65e0\u9700\u8fd0\u884c\u65f6\u91cd\u5b9a\u4f4d\u3002<br>\u7279\u70b9\uff1a\u7a0b\u5e8f\u81ea\u5305\u542b\uff0c\u4f46\u53ef\u6267\u884c\u6587\u4ef6\u4f53\u79ef\u5927<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u52a8\u6001\u94fe\u63a5<\/h3>\n\n\n\n<h4 class=\"wp-block-heading\">\u52a8\u6001\u94fe\u63a5\u8fc7\u7a0b<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">\u7a0b\u5e8f\u8fd0\u884c\u65f6\u624d\u52a0\u8f7d\u94fe\u63a5\u548c\u94fe\u63a5\u6240\u9700\u5e93<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u7f16\u8bd1\u5668\u751f\u6210.o<\/li>\n\n\n\n<li>\u94fe\u63a5\u5668\u8bb0\u5f55\u52a8\u6001\u5e93.so\u4ee5\u6765\u4fe1\u606f<\/li>\n\n\n\n<li>\u751f\u6210\u5305\u542b\u4e3a\u89e3\u6790\u7b26\u53f7\u7684\u53ef\u6267\u884c\u6587\u4ef6<\/li>\n\n\n\n<li>\u7a0b\u5e8f\u8fd0\u884c\u65f6\uff0c\u52a8\u6001\u94fe\u63a5\u5668\uff08ld.so\uff09\n<ol class=\"wp-block-list\">\n<li>\u67e5\u627e\u5e76\u52a0\u8f7d\u6240\u9700\u5171\u4eab\u5e93<\/li>\n\n\n\n<li>\u89e3\u6790\u7b26\u53f7\u5f15\u7528<\/li>\n\n\n\n<li>\u6267\u884c\u91cd\u5b9a\u4f4d\u64cd\u4f5c<br>\u7279\u70b9\uff1a\u5730\u5740\u5ef6\u8fdf\u786e\u5b9a\uff0c\u5b9e\u9645\u5730\u5740\u5728\u8fd0\u884c\u65f6\u624d\u89e3\u6790<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">\u52a8\u6001\u52a0\u8f7d\u8fc7\u7a0b<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>\u5185\u6838\u6620\u5c04\u4e3b\u7a0b\u5e8f\u7684\u6bb5\u5230\u5185\u5b58<\/li>\n\n\n\n<li>\u52a0\u8f7d\u52a8\u6001\u94fe\u63a5\u5668\uff08ld.so\uff09<\/li>\n\n\n\n<li>\u52a8\u6001\u94fe\u63a5\u5668\u6309\u9700\u52a0\u8f7d\u4f9d\u8d56\u7684\u5171\u4eab\u5e93<\/li>\n\n\n\n<li>\u901a\u8fc7GOT\u548cPLT\u673a\u5236\u5b8c\u6210\u7b26\u53f7\u89e3\u6790\u548c\u5730\u5740\u91cd\u5b9a\u4f4d<\/li>\n\n\n\n<li>\u6240\u6709\u5e93\u4ee3\u7801\u91c7\u7528\u4f4d\u7f6e\u65e0\u5173\u4ee3\u7801\uff08PLC\uff09\u6280\u672f\uff0c\u652f\u6301\u591a\u8fdb\u7a0b\u5171\u4eab<\/li>\n\n\n\n<li>\u652f\u6301ASLR\uff08\u5730\u5740\u7a7a\u95f4\u5e03\u5c40\u968f\u673a\u5316\uff09<br>\u7279\u70b9\uff1a\u8282\u7701\u5185\u5b58\uff0c\u4f9d\u8d56\u7ba1\u7406\u590d\u6742<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.52pojie.cn\/thread-1403011-1-1.html\">\u6587\u7ae0\uff0c\u7b14\u8bb0<\/a><br><a href=\"https:\/\/bbs.kanxue.com\/thread-277677.htm\">\u6587\u7ae0\uff0c\u8be6\u7ec6\u8bb2\u89e3\uff0c\u592a\u5f3a\u4e86<\/a><br><a href=\"https:\/\/learn.microsoft.com\/zh-cn\/windows\/win32\/debug\/pe-format?redirectedfrom=MSDN\">\u6587\u7ae0<\/a><br><a href=\"https:\/\/blog.csdn.net\/fengbingchun\/article\/details\/89388105\">\u6587\u7ae0<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PE \u5e38\u89c1\u540e\u7f00 PE\u6587\u4ef6\u7684\u4e24\u79cd\u72b6\u6001 pe\u6587\u4ef6\u5206\u4e3a\u8fd0\u884c\u6001\u548c\u975e\u8fd0\u884c\u6001 \u6587\u4ef6\u7ed3\u6784 \u57fa\u4e8ecoff\uff08Common Obj [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":61,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-learn"],"_links":{"self":[{"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/posts\/16","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/comments?post=16"}],"version-history":[{"count":2,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/posts\/16\/revisions"}],"predecessor-version":[{"id":63,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/posts\/16\/revisions\/63"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/media\/61"}],"wp:attachment":[{"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/media?parent=16"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/categories?post=16"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/8.210.123.186\/index.php\/wp-json\/wp\/v2\/tags?post=16"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}