View Single Post
  #7  
Old 12-14-2004, 15:56
zaratustra
 
Posts: n/a
Quote:
Originally Posted by Michel
Do you think it's really necessary ?
Look that 65CA != 8000 - 1000 (sec .text)



Notepad has an 'irregular' PE Header format. I will explain it later.
Please have a look at another exe, you should note that my assertion
about the virtual size is correct. ( You can obtain the same result
with the option rebuild pe in lordpe applied to notepad).
YOU WILL OBTAIN AN ERROR IF THE VSIZE OF YOUR ADDED SECTION IS 0.
Also when you add a new section you should specify the Raw offset in the file
where your data reside. In your case, you should also add some datas at the end of file. You can do it with winhex or some other program. Or with lordpe
for example loading the section directly from disk. It is the way I prefer.
Save your datas to disk and load a new section from disk with lordpe.
Fix the vsize of the previous last section to fit the new allotted section and try...
Please try also with a program different from notepad, or post the
data of your new section I can try it on my own.
Cheers.
Z.

Last edited by zaratustra; 12-14-2004 at 16:09.
Reply With Quote