当前位置: 首页>>代码示例>>Python>>正文


Python PE.peFromFileName方法代码示例

本文整理汇总了Python中PE.peFromFileName方法的典型用法代码示例。如果您正苦于以下问题:Python PE.peFromFileName方法的具体用法?Python PE.peFromFileName怎么用?Python PE.peFromFileName使用的例子?那么恭喜您, 这里精选的方法代码示例或许可以为您提供帮助。您也可以进一步了解该方法所在PE的用法示例。


在下文中一共展示了PE.peFromFileName方法的7个代码示例,这些例子默认根据受欢迎程度排序。您可以为喜欢或者感觉有用的代码点赞,您的评价将有助于系统推荐出更棒的Python代码示例。

示例1: test_export_by_ordinal_base_45

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
 def test_export_by_ordinal_base_45(self):
     file_path = helpers.getTestPath('windows', 'i386', 'export_by_ordinal_base_45.dll')
     pe = PE.peFromFileName(file_path)
     export_list = pe.getExports()
     self.assertEquals(len(export_list), 2, "expecting 2 exported functions")
     self.assertEquals(export_list[0][1], 45, "exported function with ordinal 45 not found")
     self.assertEquals(export_list[1][1], 55, "exported function with ordinal 55 not found")
开发者ID:BwRy,项目名称:vivisect,代码行数:9,代码来源:testpe.py

示例2: deAslr

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
def deAslr(trace, va):
    '''
    Given an address in an ASLR'd library, rebase
    it back to the address as it would be if the
    given PE were at it's suggested address...
    '''

    if vtrace.remote:
        raise Exception('deAslr only works for local debuggers!')

    map = trace.getMemoryMap(va)
    if map == None:
        return va

    mapva, mapsize, mapperm, mapfname = map
    if not mapfname:
        return va

    normname = trace.normFileName(mapfname)
    sym = trace.getSymByName(normname)
    if sym == None:
        return va

    membase = long(sym)

    pe = PE.peFromFileName(mapfname)
    filebase = pe.IMAGE_NT_HEADERS.OptionalHeader.ImageBase

    rva = va - membase

    return filebase + rva
开发者ID:Anstep,项目名称:pyew,代码行数:33,代码来源:win32aslr.py

示例3: main

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
def main():
    parser = optparse.OptionParser()
    parser.add_option('--version', dest='version', default=False, action='store_true')
    parser.add_option('--resources', dest='resources', default=False, action='store_true')

    opts, argv = parser.parse_args()

    for fname in argv:

        print('Parsing: %s' % fname)

        vsver = None
        expname = None

        pe = PE.peFromFileName(fname)

        if opts.resources:
            print('Type Nameid - rva size sample')
            for rtype, nameid, (rva, size, codepage) in pe.getResources():
                hexstr = pe.readAtRva(rva, max(size, 8)).encode('hex')
                print(('0x%.4x 0x%.4x - 0x%.8x 0x%.8x %s' % (rtype, nameid, rva, size, hexstr)))

        if opts.version:
            vs = pe.getVS_VERSIONINFO()
            if vs is None:
                print('No VS_VERSIONINFO found!')

            else:
                keys = vs.getVersionKeys()
                keys.sort()
                for k in keys:
                    val = vs.getVersionValue(k)
                    print('%s: %r' % (k, val))

        code.interact(local=locals())
开发者ID:bat-serjo,项目名称:vivisect,代码行数:37,代码来源:petool.py

示例4: test_export_by_name

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
 def test_export_by_name(self):
     file_path = helpers.getTestPath('windows', 'i386', 'export_by_name.dll')
     pe = PE.peFromFileName(file_path)
     export_list = pe.getExports()
     self.assertEquals(len(export_list), 2, "expecting 2 exported functions")
     self.assertEquals(export_list[0][1], 0, "exported function with ordinal 0 not found")
     self.assertEquals(export_list[0][2], "Func1", "exported function with name 'Func1' not found")
     self.assertEquals(export_list[1][1], 1, "exported function with ordinal 1 not found")
     self.assertEquals(export_list[1][2], "Func2", "exported function with name 'Func2' not found")
开发者ID:BwRy,项目名称:vivisect,代码行数:11,代码来源:testpe.py

示例5: test_pe_vsersion

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
 def test_pe_vsersion(self):
     fpath = os.path.join('test_pe','bins','wwaninst.dll')
     pe = PE.peFromFileName(fpath)
     vs = pe.getVS_VERSIONINFO()
     self.assertIsNotNone(vs)
     keys = vs.getVersionKeys()
     self.assertEqual(len(keys), len(vs_version))
     for key in vs.getVersionKeys():
         self.assertEqual(vs_version.get(key), vs.getVersionValue(key))
开发者ID:BwRy,项目名称:vivisect,代码行数:11,代码来源:test_version.py

示例6: getOEP

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
def getOEP(trace, filepath):
    base = None

    libs = trace.getMeta("LibraryPaths")
    for k, v in libs.iteritems():
        if filepath in v:
            base = k
    
    if base is None:
        p = PE.peFromFileName(filepath)
        base = p.IMAGE_NT_HEADERS.OptionalHeader.ImageBase
    else:
        p = PE.peFromMemoryObject(trace, base)

    ep = p.IMAGE_NT_HEADERS.OptionalHeader.AddressOfEntryPoint
    oep = base + ep
    return oep
开发者ID:hoangcuongflp,项目名称:vtrace_scripts,代码行数:19,代码来源:simpleAPI.py

示例7:

# 需要导入模块: import PE [as 别名]
# 或者: from PE import peFromFileName [as 别名]
'''
For now, all this does is rename files to their exportname and version info.
(more to come is likely)
'''

if __name__ == "__main__":

    for fname in sys.argv[1:]:

        print 'Parsing: %s' % fname

        vsver = None
        expname = None

        pe = PE.peFromFileName(fname)

        expname = pe.getExportName()

        dirname = os.path.dirname(fname)

        vs = pe.getVS_VERSIONINFO()
        if vs == None:
            print 'No VS_VERSIONINFO found!'

        else:
            keys = vs.getVersionKeys()
            keys.sort()
            for k in keys:
                val = vs.getVersionValue(k)
                print '%s: %s' % (k, val)
开发者ID:Fitblip,项目名称:SocketSniff,代码行数:32,代码来源:petool.py


注:本文中的PE.peFromFileName方法示例由纯净天空整理自Github/MSDocs等开源代码及文档管理平台,相关代码片段筛选自各路编程大神贡献的开源项目,源码版权归原作者所有,传播和使用请参考对应项目的License;未经允许,请勿转载。