Cross-platform Support for Windows Memory Dumps

Đang mở
#653 3 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Đình trệ
Công nghệ
cpp
Lĩnh vực
reverse-engineering

Hướng nghiên cứu

Reproduce the reported behavior by opening a Windows memory dump of a PE file and comparing the hex view's "Raw" and "PE" options. Start from the disassembler's PE recognition and memory-dump handling paths; done means the dump is identified as PE and functions are shown instead of an unchanged raw view.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

Component: Core Effort: Medium File Format: PE Impact: Low

Hi there,

I want to disassemble a memory dump of a PE file. Upon startup binary ninja goes into a hex view without identifying any functions. I guess the disassembler knows that this is a PE file, because in the bottom-right corner it shows me two options "Raw" and "PE". However, switching to PE doesn't change anything ("Raw" remains as the selected option).

Ngôn ngữ chính
C++
Star
1.3k
Fork
298
Merge trung bình
5 ngày 5 giờ
Pull request đã merge (30 ngày)
19

Hướng dẫn đóng góp

Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của Vector35/binaryninja-api

Tất cả issue của Vector35/binaryninja-api

Issue tương tự

Thêm issue về C++

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.