Cross-platform Support for Windows Memory Dumps

オープン
#653 コメント 3 件 リアクション 1 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
25/100
issue の種類
機能追加
明瞭さ
説明が足りない
活発さ
停滞
技術スタック
cpp

調査の方向性

Reproduce the reported behavior by opening a Windows memory dump of a PE file and comparing the hex view's "Raw" and "PE" options. Start from the disassembler's PE recognition and memory-dump handling paths; done means the dump is identified as PE and functions are shown instead of an unchanged raw view.

索引モデルが issue の本文から書いたものです。

説明

Component: Core Effort: Medium File Format: PE Impact: Low

Hi there,

I want to disassemble a memory dump of a PE file. Upon startup binary ninja goes into a hex view without identifying any functions. I guess the disassembler knows that this is a PE file, because in the bottom-right corner it shows me two options "Raw" and "PE". However, switching to PE doesn't change anything ("Raw" remains as the selected option).

主要言語
C++
スター
1.3k
フォーク
298
平均マージ
5日 5時間
マージ済み PR(30日)
19

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

Vector35/binaryninja-api のほかの issue

Vector35/binaryninja-api の issue をすべて見る

似ている issue

C++ の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。