逆向基础:PE文件的DOS头属性说明

查看PE结构:

在 VS code 中输入#include "winnt.h" 在上面点右键转到定义打开就行了

然后搜索 IMAGE_DOS_HEADER

    typedef struct _IMAGE_DOS_HEADER {
      WORD e_magic;
      WORD e_cblp;
      WORD e_cp;
      WORD e_crlc;
      WORD e_cparhdr;
      WORD e_minalloc;
      WORD e_maxalloc;
      WORD e_ss;
      WORD e_sp;
      WORD e_csum;
      WORD e_ip;
      WORD e_cs;
      WORD e_lfarlc;
      WORD e_ovno;
      WORD e_res[4];
      WORD e_oemid;
      WORD e_oeminfo;
      WORD e_res2[10];
      LONG e_lfanew;
    } IMAGE_DOS_HEADER,*PIMAGE_DOS_HEADER;

 

猜你喜欢

转载自blog.csdn.net/lm19770429/article/details/121094472