1. PE Format Complete Analasys
http://hdp.null2root.org/reversing/PE_analysis_anesra.pdf
http://web.kaist.ac.kr/~taekwonv/pe_icezlion.htm
or
http://win32assembly.online.fr/
http://win32assembly.online.fr/pe-tut1.html (1. Overview Of PE File Format)
http://win32assembly.online.fr/pe-tut2.html (2. Detecting a Valid PE File)
http://win32assembly.online.fr/pe-tut3.html (3. File Header)
http://win32assembly.online.fr/pe-tut4.html (4. Optional Header)
http://win32assembly.online.fr/pe-tut6.html (5. Section Table)
http://win32assembly.online.fr/pe-tut7.html (6. Import Table)
http://win32assembly.online.fr/pe-tut7.html (7. Export Table )
Import Table
http://web.kaist.ac.kr/~taekwonv/pe_iat.htm
3. PE File Analysis - With easy explanation, With C++ Exercises
http://kkamagui.springnote.com/pages/407001
4. Peering Inside the PE: A Tour of the Win32 Portable Executable File Format (by Matt Pietrek) - 1994년
http://msdn.microsoft.com/en-us/magazine/ms809762.aspx
번역:http://blog.naver.com/gekigang/140016674843
5. An In-Depth Look into the Win32 Portable Executable File Format (by Matt Pietrek) - 2002년
An In-Depth Look into the Win32 Portable Executable File Format, Part 2
(위의 글을 Win32의 변화에 맞추어 같은 저자가 다시 쓴 글)
http://msdn.microsoft.com/en-us/magazine/bb985992.aspx
http://msdn.microsoft.com/en-us/magazine/cc301805.aspx
http://msdn.microsoft.com/en-us/magazine/cc301808.aspx
6. Physical Layout of a .NET Assembly
http://www.informit.com/articles/article.aspx?p=25350
7. PE Reference (The PE file format by LUEVELSMEYER)
http://webster.cs.ucr.edu/Page_TechDocs/pe.txt
http://win32assembly.online.fr/files/pe1.zip
8. PE File Structure Diagram
http://www.openrce.org/reference_library/files/reference/PE%20Format.pdf
9. Wikipedia
http://ko.wikipedia.org/wiki/PE_%ED%8F%AC%EB%A7%B7
* Introduction of multiple ways for PE file modification
http://web.kaist.ac.kr/~taekwonv/
Free PE Editor - Explorer Suite
http://www.ntcore.com/exsuite.php
* Visual Studio Tool (...\vc\bin folder) - dumpbin
i.e. dumpbin /header "PE FILE"
Shows File Header, Optional Header and etc.
'Hacking' 카테고리의 다른 글
Red Hat Update for Kernel (0) | 2008.12.18 |
---|---|
Microsoft Internet Explorer Data Binding Vulnerability (0) | 2008.12.18 |
Buffer Overflow (0) | 2008.12.18 |
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities (0) | 2008.12.17 |
Getting Started Reverse Engineering (0) | 2008.12.16 |