On an NT system the loader just checks for the magic numbers at the beginning MZ / 0x4d 0x5a
and then the member e_lfanew
to get the NT header offset.
Which entries in the dos header are necessary?
-
02-06-2022 - |
Question
I am writing a PE generator, I need to know which entries in the DOS header section are necessary for execution on NT based systems.
I checked some exes on my drive and most entries in the DOS header are 0 but I am not sure if this is the norm.
Solution
Licensed under: CC-BY-SA with attribution
Not affiliated with StackOverflow