Skip to content

v0.3.0: Phase 3 - Section Listing

Latest

Choose a tag to compare

@AngBan2x AngBan2x released this 02 May 22:14

Phase 3 is now complete for both ELF and PE binaries!

New things and changes

  • Added section listing. Sections are now stored within a list of dictionaries, where each dictionary contains information of the section
  • PE: Generalized flag extraction. Made a generic function that given the characteristics value (or any hex value) and its corresponding dictionary (stored in the constants module), it returns a dictionary with the corresponding flags within the caracteristics value.
  • Added constants for the section flags (types, characteristics, etc.)

Truncated example outputs

ELF: /bin/ls - Header and first 4 sections

File path: /bin/ls
Filetype: ELF
Header :
	e_ident (Identification) :
		Magic number : 0x7fELF
		Class (architecture) : 64-bit
		Data encoding : Two's complement, Little Endian
		Version : 2
		OS/ABI target : UNIX System V ABI
		ABI version : 0
	e_type (Object file type) : DYN (Shared object)
	e_machine (Required architecture) : AMD x86-64
	e_version (File version) : 1
	e_entry (Point of entry) : 0x104af0
	e_phoff (Program Header Table offset) : 64
	e_shoff (Section Header Table offset) : 10830008
	e_flags (Processor Specific Flags) : 0
	e_ehsize (Header size) : 64
	e_phentsize (Program Header Table entry size) : 56
	e_phnum (Program Header Table entries) : 15
	e_shentsize (Section Header Table entry size) : 64
	e_shnum (Section Header Table entries) : 34
	e_shstrndx (Section Header String Table Index) : 33
Sections :
	[0]
	Name : None
	Type : Null
	Flags :
		0 : None
	Address : 0x0
	Offset : 0
	Size : 0
	Link : 0
	Info : 0
	Address alignment : 0
	Entry size : 0
 
	[1]
	Name : .note.gnu.property
	Type : Notes
	Flags :
		0x2 : Occupies memory during execution
	Address : 0x388
	Offset : 904
	Size : 32
	Link : 0
	Info : 0
	Address alignment : 8
	Entry size : 0
 
	[2]
	Name : .note.gnu.build-id
	Type : Notes
	Flags :
		0x2 : Occupies memory during execution
	Address : 0x3a8
	Offset : 936
	Size : 36
	Link : 0
	Info : 0
	Address alignment : 4
	Entry size : 0
 
	[3]
	Name : .interp
	Type : Program information
	Flags :
		0x2 : Occupies memory during execution
	Address : 0x3cc
	Offset : 972
	Size : 28
	Link : 0
	Info : 0
	Address alignment : 1
	Entry size : 0

PE: cmd.exe - Headers and first four sections

File path: /mnt/c/Windows/system32/cmd.exe
Filetype: PE
Magic number 0x20b
Current file position: 296
File position after seeking to st_off: 512
PE Header :
	COFF Offset : 248
	Signature : b'PE\x00\x00'
	File Header :
		Machine : x64
		NumberOfSections : 8
		TimeDateStamp : 2091-09-06 23:01:06+00:00
		PointerToSymbolTable : 0
		NumberOfSymbols : 0
		SizeOfOptionalHeader (bytes) : 240
		Characteristics :
			0x2 : Executable file
			0x20 : Can handle >2GB addresses
	Optional Header :
		Standard Fields :
			Magic : PE32+
			MajorLinkerVersion : 14
			MinorLinkerVersion : 38
			SizeOfCode : 233472
			SizeOfInitializedData : 217088
			SizeOfUnitizializedData : 0
			AddressOfEntryPoint : 162592
			BaseOfCode (address) : 4096
Sections :
	[0]
	Name : .text
	VirtualSize : 0x37db6
	VirtualAddress : 0x1000
	SizeOfRawData : 0x38000
	PointerToRawData : 0x1000
	PointerToRelocations : 0x0
	PointerToLinenumbers : 0x0
	NumberOfRelocations : 0x0
	NumberOfLinenumbers : 0x0
	Characteristics :
		0x0 : Reserved for future use
		0x20 : Contains executable code
		0x20000000 : Can be executed as code
		0x40000000 : Can be read
 
	[1]
	Name : fothk
	VirtualSize : 0x1000
	VirtualAddress : 0x39000
	SizeOfRawData : 0x1000
	PointerToRawData : 0x39000
	PointerToRelocations : 0x0
	PointerToLinenumbers : 0x0
	NumberOfRelocations : 0x0
	NumberOfLinenumbers : 0x0
	Characteristics :
		0x0 : Reserved for future use
		0x20 : Contains executable code
		0x20000000 : Can be executed as code
		0x40000000 : Can be read
 
	[2]
	Name : .rdata
	VirtualSize : 0x9b38
	VirtualAddress : 0x3a000
	SizeOfRawData : 0xa000
	PointerToRawData : 0x3a000
	PointerToRelocations : 0x0
	PointerToLinenumbers : 0x0
	NumberOfRelocations : 0x0
	NumberOfLinenumbers : 0x0
	Characteristics :
		0x0 : Reserved for future use
		0x40 : Contains initialized data
		0x40000000 : Can be read
 
	[3]
	Name : .data
	VirtualSize : 0x1c1a0
	VirtualAddress : 0x44000
	SizeOfRawData : 0x1000
	PointerToRawData : 0x44000
	PointerToRelocations : 0x0
	PointerToLinenumbers : 0x0
	NumberOfRelocations : 0x0
	NumberOfLinenumbers : 0x0
	Characteristics :
		0x0 : Reserved for future use
		0x40 : Contains initialized data
		0x40000000 : Can be read
		0x80000000 : Can be written to