-
Hello. Did you planning for future add object format’s for osx and win64 (intel)? With respect for tinycc: he didn’t generate macos executable. Portable c compiler also not supported this platform. Bu…
-
Hello,
After the recent changes of #1790 and #2197 by @BrentHoltsclaw, I run a regression test on some UEFI image samples with known results based on earlier Chipsec versions.
In some cases/samp…
-
I've tried running `steg86 profile` against several EXEs and DLLs, both PE32 and PE32+, and every time, it has produced an error like this:
```
Fatal: encountered an invalid instruction at text of…
-
I got a PE32+ binary with baddr = 0x0 which is not "messed up".
I see no reason to set this to 0x10000
```
rz-bin -H myfile
paddr name vaddr commen…
-
I'm trying your library but unfortunately it doesn't work for 64bit executables.
I'm testing it directly on Visual Studio cl.exe available for different platforms. But any amd64 executable doesn't …
-
I did a search for the bytes that ImageVerificationHandler uses but it does not exist within the file. I tried extracting some other PE32 image sections from the bios but I cant find ImageVerification…
-
right now, the W64 installer is a 32bit application (`PE32`).
i wonder why it is not a 64bit application `PE32+`?
it should be as simple as adding something like:
```nsis
!if ${ARCHI} == "64"
…
-
-
#57
.idata section at RVA 0x1B4000, raw data at 0x124200
Entry for kernel32:
Ordinal table at RVA 1B43C4 (3C4 within section)
Import address table at RVA D21C0 - outside of .idata secti…
sevaa updated
1 month ago
-
If a UEFI PE32 module is built position-independent, Ghidra loads it at 0x10000. When it searches for global assignments, it finds the `SystemTable->BootServices`, which in almost every case is somewh…
zznop updated
3 years ago