官术网_书友最值得收藏!

Binary analysis tools

Binary analysis tools are used to parse binary files and extract information about the file. An analyst would be able to identify which applications are able to read or execute the binary. File types are generally identified from their magic header bytes. These Magic Header bytes are usually located at the beginning of a file. For example, a Microsoft executable file, an EXE file, begin with the MZ header (MZ is believed to be the initials of Mark Zbikowski, a developer from Microsoft during the DOS days). Microsoft Office Word documents, on the other hand, have these first four bytes as their Magic Header: 


The hexadecimal bytes in the preceding screenshot read as DOCFILE Other information such as text string also give hints. The following screenshot shows information indicating that the program was most likely built using Window Forms:


主站蜘蛛池模板: 买车| 正镶白旗| 广安市| 宁津县| 鄂温| 济宁市| 织金县| 崇阳县| 大足县| 湘潭市| 隆尧县| 斗六市| 郓城县| 临漳县| 延津县| 南皮县| 宜丰县| 吉木萨尔县| 青河县| 隆德县| 河津市| 滦平县| 中牟县| 六枝特区| 平邑县| 康马县| 昭苏县| 普兰店市| 乌拉特后旗| 广灵县| 会东县| 罗江县| 鹤山市| 隆回县| 牙克石市| 惠水县| 黄大仙区| 特克斯县| 常山县| 柏乡县| 会东县|