-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathPeExplorer.cpp
More file actions
178 lines (147 loc) · 4.13 KB
/
Copy pathPeExplorer.cpp
File metadata and controls
178 lines (147 loc) · 4.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
#include "includes.h"
PeExplorer::~PeExplorer()
{
if (pMap != nullptr)
{
UnmapViewOfFile(pMap);
FileSize = -1;
pMap = nullptr;
}
SectionHeaderList.clear();
pDosHeader = nullptr;
pNtHeaders = nullptr;
pFileHeader = nullptr;
pOptionalHeader = nullptr;
}
// Overloaded Function to map a PE file to memory
bool PeExplorer::Explore(const char* FileName, DWORD ExtraSize)
{
printf("Mapping PE File...\n");
int retries = 0;
HANDLE FileHandle = INVALID_HANDLE_VALUE;
do
{
FileHandle = CreateFile(FileName, GENERIC_READ | GENERIC_WRITE, 0, 0, OPEN_EXISTING, FILE_ATTRIBUTE_NORMAL, 0);
if (FileHandle == INVALID_HANDLE_VALUE)
{
if (GetLastError() == ERROR_SHARING_VIOLATION)
{
++retries;
Sleep(250);
continue;
}
else
break;
}
else
break;
} while (retries < 10);
if (FileHandle == INVALID_HANDLE_VALUE)
{
PeExplorer::~PeExplorer();
printf("File Could Not Be Read. Error: 0x%X\n", GetLastError());
return false;
}
FileSize = GetFileSize(FileHandle, NULL);
FileSize += ExtraSize;
HANDLE hMap = CreateFileMapping(FileHandle, NULL, PAGE_READWRITE, 0, FileSize, NULL);
if (hMap == INVALID_HANDLE_VALUE)
{
CloseHandle(FileHandle);
printf("Could not CreateFileMapping. Error: 0x%X\n", GetLastError());
std::cin.get();
return 0;
}
pMap = MapViewOfFile(hMap, FILE_MAP_ALL_ACCESS, 0, 0, FileSize);
if (pMap == nullptr)
{
CloseHandle(FileHandle);
CloseHandle(hMap);
printf("Could not Map File. Error: 0x%X\n", GetLastError());
std::cin.get();
return 0;
}
CloseHandle(FileHandle);
CloseHandle(hMap);
if (!Explore(pMap))
{
PeExplorer::~PeExplorer();
return false;
}
return true;
}
// Overloaded Function to map a PE file to memory
bool PeExplorer::Explore(PVOID pPe)
{
printf("Reading PE File...\n");
pMap = pPe;
pDosHeader = static_cast<PIMAGE_DOS_HEADER>(pPe);
if (!VerifyDosHeader(pDosHeader->e_magic))
{
PeExplorer::~PeExplorer();
printf("Could not verify DOS header\n");
return false;
}
pNtHeaders = reinterpret_cast<PIMAGE_NT_HEADERS>((DWORD)pDosHeader + pDosHeader->e_lfanew); // pDosHeader + sizeof(DosHeader) + sizeof(DosStub) = pNtHeaders. Keep in mind that dos header + stub does not have constant size
if (!VerifyPeHeader(pNtHeaders->Signature))
{
PeExplorer::~PeExplorer();
printf("Could not verify PE header\n");
return false;
}
pFileHeader = static_cast<PIMAGE_FILE_HEADER>(&pNtHeaders->FileHeader); // Get FileHeader pointer
pOptionalHeader = static_cast<PIMAGE_OPTIONAL_HEADER>(&pNtHeaders->OptionalHeader); // Get OptionalHeader pointer
PIMAGE_SECTION_HEADER pFirstSection = reinterpret_cast<PIMAGE_SECTION_HEADER>((DWORD)pOptionalHeader + pFileHeader->SizeOfOptionalHeader); // Address of first section header = pOptionalHeader + sizeof(OptionalHeader)
// Keep in mind that OptionalHeader size is not constant use ->SizeOfOptionalHeader
for (int i = 0; i < pFileHeader->NumberOfSections; ++i)
SectionHeaderList.push_back(pFirstSection + i); // The section headers comes after each other in memory
return true;
}
PIMAGE_SECTION_HEADER PeExplorer::GetSectionByName(const char* SectionName)
{
for (auto Section : SectionHeaderList)
{
if (!memcmp(Section->Name, SectionName, strlen(SectionName)))
return Section;
}
return nullptr;
}
PIMAGE_SECTION_HEADER PeExplorer::GetSectionByCharacteristics(DWORD Characteristics)
{
for (auto Section : SectionHeaderList)
{
if (Section->Characteristics & Characteristics)
return Section;
}
return nullptr;
}
PIMAGE_SECTION_HEADER PeExplorer::GetLastSection()
{
PIMAGE_SECTION_HEADER LastSection = new IMAGE_SECTION_HEADER();
for (auto Section : SectionHeaderList)
{
if (Section->PointerToRawData > LastSection->PointerToRawData)
LastSection = Section;
}
return LastSection;
}
std::vector<PIMAGE_SECTION_HEADER> PeExplorer::GetSectionList()
{
return SectionHeaderList;
}
PIMAGE_DOS_HEADER PeExplorer::GetDosHeader()
{
return pDosHeader;
}
PIMAGE_NT_HEADERS PeExplorer::GetNtHeaders()
{
return pNtHeaders;
}
PIMAGE_FILE_HEADER PeExplorer::GetFileHeader()
{
return pFileHeader;
}
PIMAGE_OPTIONAL_HEADER PeExplorer::GetOptionalHeader()
{
return pOptionalHeader;
}