-
?? sizeof
exp: get the _teb structure size?? sizeof(ntdll!_teb)
-
- Need to check
_IMAGE_DOS_HEADER
>_IMAGE_NT_HEADERS
>_IMAGE_OPTIONAL_HEADER
>DllCharacteristics
For example we want check sample.exe :lm m sample.exe
> in result selectstart
. for example it's1000000
.Sodt ntdll!_IMAGE_DOS_HEADER 100000
. In result selecte_lfanew
value. But use?
command to convert hexadecimal. For example? 0n120
. result is78
. now use this command :dt ntdll!_IMAGE_NT_HEADERS 0x00100000+0x78
. in the result selectOptionalHeader
filed for example it is18
. Now use this command :dt ntdll!_IMAGE_OPTIONAL_HEADER 0x00100000+0x78+0x18
Now we haveDllCharacteristics
value. For parse is use this link
- Need to check