0:001> dt ntdll!*IMAGE_*
ntdll!_IMAGE_NT_HEADERS
ntdll!_IMAGE_DOS_HEADER
ntdll!_IMAGE_FILE_HEADER
ntdll!_IMAGE_OPTIONAL_HEADER
ntdll!_IMAGE_DATA_DIRECTORY
0:001> dt MyApp*!*IMAGE_*
MyApp!PIMAGE_DEBUG_DIRECTORY
MyApp!PIMAGE_RESOURCE_DIRECTORY_ENTRY
MyApp!PIMAGE_TLS_CALLBACK
MyApp!PIMAGE_FUNCTION_ENTRY
MyApp!PIMAGE_EXPORT_DIRECTORY
MyApp!IMAGE_ARCHITECTURE_HEADER
MyApp!PIMAGE_AUX_SYMBOL
MyApp!IMAGE_ALPHA_RUNTIME_FUNCTION_ENTRY
MyApp!PIMAGE_RESOURCE_DIR_STRING_U
MyApp!PIMAGE_THUNK_DATA
MyApp!PIMAGE_RUNTIME_FUNCTION_ENTRY
MyApp!IMAGE_ROM_HEADERS
MyApp!PIMAGE_TLS_DIRECTORY64
MyApp!PIMAGE_SYMBOL
MyApp!_PIMAGE_RUNTIME_FUNCTION_ENTRY
MyApp!IMAGE_TLS_DIRECTORY32
MyApp!PIMAGE_BASE_RELOCATION
MyApp!IMAGE_FILE_HEADER
MyApp!IMAGE_DOS_HEADER
MyApp!PIMAGE_ARCHITECTURE_ENTRY
MyApp!PIMAGE_DOS_HEADER
MyApp!IMAGE_RUNTIME_FUNCTION_ENTRY
MyApp!IMAGE_FUNCTION_ENTRY
MyApp!PIMAGE_THUNK_
windbg dt命令显示PE相关数据结构
最新推荐文章于 2024-11-02 08:13:51 发布
本文深入探讨了PE(可移植执行)文件格式的内部结构,详细介绍了ntdll和MyApp模块中包含的各种数据结构,如_IMAGE_NT_HEADERS、_IMAGE_DOS_HEADER、_IMAGE_FILE_HEADER等,这些结构对于理解Windows操作系统下的程序加载和执行至关重要。

最低0.47元/天 解锁文章
2万+

被折叠的 条评论
为什么被折叠?



