官术网_书友最值得收藏!

Binary analysis tools

Binary analysis tools are used to parse binary files and extract information about the file. An analyst would be able to identify which applications are able to read or execute the binary. File types are generally identified from their magic header bytes. These Magic Header bytes are usually located at the beginning of a file. For example, a Microsoft executable file, an EXE file, begin with the MZ header (MZ is believed to be the initials of Mark Zbikowski, a developer from Microsoft during the DOS days). Microsoft Office Word documents, on the other hand, have these first four bytes as their Magic Header: 


The hexadecimal bytes in the preceding screenshot read as DOCFILE Other information such as text string also give hints. The following screenshot shows information indicating that the program was most likely built using Window Forms:


主站蜘蛛池模板: 天全县| 沂水县| 江口县| 涟源市| 无为县| 民乐县| 电白县| 集安市| 广元市| 垣曲县| 南溪县| 连云港市| 楚雄市| 库伦旗| 句容市| 洛宁县| 上栗县| 晴隆县| 巫溪县| 长泰县| 肃北| 若羌县| 绵阳市| 同德县| 涟源市| 米脂县| 古田县| 房产| 怀远县| 馆陶县| 沂源县| 玉溪市| 夏津县| 武清区| 商水县| 阳曲县| 乌鲁木齐县| 株洲市| 万宁市| 武定县| 原阳县|