I'm learning PE files structure, but I'm confused about the concept of Address of Entry Point and Original Entry Point. I know Address of Entry Point can be calculated according to Image_Optional_Header, Does Original Entry Point do? And the code between Address of Entry Point and Original Entry Point do what?
What's the differences between Address of Entry Point and Original Entry Point?
3.3k Views Asked by Hu Zhenwu At
1
There are 1 best solutions below
Related Questions in PORTABLE-EXECUTABLE
- Determine physical file address of directory RVA in PE file
- What is the relationship between sections and data directories in a PE file?
- I am confusing some assembly code about enable PE within boot/setup.s file in Linux 0.11
- Is it true that PE files map directly into memory?
- What Does Windows Do Before Main() is Called?
- Call "main" function programmatically in Windows
- Memory Address files
- Determining if the running executable has IMAGE_FILE_LARGE_ADDRESS_AWARE?
- Identification of PE section characteristic
- Is kernel32.dll always loaded below 0x80000000 (x64) ?
- How can I find the public key of any PE file?
- PE format, what is the use for IAT Directory
- How to insert/remove some garbage instructions into ELF/PE file without changing its functionality?
- How does the linker determine at which line a symbol is called?
- How can I use pe.entry_point to write YARA rules?
Related Questions in ENTRY-POINT
- Different storyboard's entry points depending on a parameter
- Call "main" function programmatically in Windows
- python pip install wheel with custom entry points
- Using static void Main() method from base class as a program's entry point
- UML behavioral state diagram: entry and exit point ownership implications for orthogonal states
- What's the differences between Address of Entry Point and Original Entry Point?
- Is the entry point for the same for a C++ app as it is for a C app?
- Android equivalent of: void main() / Sub Main?
- Why does a Java program require a "main()" method?
- Can i set entry point at code in PE headers?
- location of python application entry point files in the repository
- How to change the entry point of a Ios App?
- MERN : Multiple independent react apps without involving to web pack details
- Reading PE files EntryPointAdress using c#
- Is the variable elf_entry in the kernel function load_elf_binary the entry point i get with readelf -h
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
The Original Entry Point is a concept typically referred to in reverse engineering for an executable that has been modified by some means such as being compressed (or encrypted) by a packer or infected with malware. Prior to modification, the entry-point of an executable IS the original entry point (OEP). When an executable has been modified, such as to include a stub of code that runs prior to the original code, the entry-point of the executable is changed to point to the new code. The stub then references the old entry-point when it is done. So once the stub runs, it will transfer control to the address of the original entry point so the modified program still works (or appears) to work as normal.