๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋ฆฌ๋ฒ„์‹ฑ

๋ฆฌ๋ฒ„์‹ฑ - ๋ฆฌ๋ฒ„์Šค ์ฝ”์–ด(ReverseCore)

by Janger 2022. 9. 16.
728x90
๋ฐ˜์‘ํ˜•

https://reversecore.com/18?category=216978 

 

PE(Portable Executable) File Format (1) - PE Header

Introduction Windows ์šด์˜์ฒด์ œ์˜ PE(Portable Executable) File Format ์— ๋Œ€ํ•ด์„œ ์•„์ฃผ ์ƒ์„ธํžˆ ๊ณต๋ถ€ํ•ด ๋ณด๋„๋ก ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. PE format ์„ ๊ณต๋ถ€ํ•˜๋ฉด์„œ Windows ์šด์˜์ฒด์ œ์˜ ๊ฐ€์žฅ ํ•ต์‹ฌ์ ์ธ ๋ถ€๋ถ„์ธ Process, Memory, D..

reversecore.com

 

๋ฆฌ๋ฒ„์‹ฑ ํ•ต์‹ฌ ์›๋ฆฌ ์ €์ž๋ถ„์ด ์šด์˜ํ•˜์‹œ๋Š” ๋ธ”๋กœ๊ทธ์ธ๋ฐ ์šด์˜์ฒด์ œ์˜ ๊ตฌ์กฐ ์›๋ฆฌ(PE)์™€ DLL Injection, API Hooking๊ณผ ๊ฐ™์€ ์ž์„ธํ•œ ํ•ดํ‚น ๊ธฐ๋ฒ•์˜ ์›๋ฆฌ๋„ ์ž˜ ์„ค๋ช…์ด ๋˜์–ด์žˆ๋‹ค. 

728x90
๋ฐ˜์‘ํ˜•