Exploring the Portable Executable format
Upcoming SlideShare
Loading in...5
×

Like this? Share it with your network

Share

Exploring the Portable Executable format

  • 1,339 views
Uploaded on

a 44CON 2013 workshop

a 44CON 2013 workshop

More in: Business , Technology
  • Full Name Full Name Comment goes here.
    Are you sure you want to
    Your message goes here
    Be the first to comment
No Downloads

Views

Total Views
1,339
On Slideshare
1,314
From Embeds
25
Number of Embeds
4

Actions

Shares
Downloads
23
Comments
0
Likes
1

Embeds 25

https://twitter.com 20
http://www.linkedin.com 2
https://www.linkedin.com 2
https://web.tweetdeck.com 1

Report content

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate.

Cancel
    No notes for slide

Transcript

  • 1. Exploring the Portable Executable format London, England Ange Albertini 2013/09/13
  • 2. Workshop package (PoCs+docs) http://www.xchg.info/corkami/workshop.zip Recommended PE viewer: http://icerbero.com/peinsider
  • 3. a handmade PE simple.exe a first real example working minimal
  • 4. detailed walkthrough
  • 5. DOS header unused in PE mode
  • 6. PE header PE signature
  • 7. Optional Header NOT optional in executables
  • 8. DataDirectories end of OptionalHeader 16 (max) * [RVA, Size] each entry interpreted differently
  • 9. Sections memory mapping
  • 10. Imports standard loader mechanism NOT required load DLL, locate APIs
  • 11. compiled PE compiled.exe closer to reality extra non-critical structure
  • 12. DLL exports relocations
  • 13. driver subsystem, checksum low alignments mapping different imports
  • 14. resources structure version, manifest/icon, APIs
  • 15. Thread Local Storage callback list before EntryPoint & after ExitProcess
  • 16. .Net different and integrated binary 2nd loader
  • 17. what about 64b? very few changes ● 2 magic constants ● a few elements become QWord ○ ImageBase, Imports thunks, callbacks ● Exceptions have their own DataDirectory ○ no need for LoadConfig (SafeSEH)
  • 18. and ARM ● a different magic constant ● still 16b DOS Stub ! ● nothing special, PE wise ○ the beauty of ‘Portability’
  • 19. trivial