INNER CODE UNIT · C++
export_dir
stivenhacker/GhostStrike · GhostStrike.cpp:91
PIMAGE_EXPORT_DIRECTORY export_dir = (PIMAGE_EXPORT_DIRECTORY)((BYTE*)module + nt_headers->OptionalHeader.DataDirectory[IMAGE_DIRECTORY_ENTRY_EXPORT].VirtualAddress);
DWORD* functions = (DWORD*)((BYTE*)module + export_dir->AddressOfFunctions);
WORD* ordinals = (WORD*)((BYTE*)module + export_dir->AddressOfNameOrdinals);
DWORD* names = (DWORD*)((BYTE*)module + export_dir->AddressOfNames);
// Loop through the export table to find the function by its hash.
for (DWORD i = 0; i < export_dir->NumberOfNames; ++i) {
const char* func_name = (const char*)((BYTE*)module + names[i]);
if (hash_function(func_name) == function_hash) {
return (FARPROC)((BYTE*)module + functions[ordinals[i]]);
}
}
std::cerr << "Error retrieving the function address.\n";
exit(EXIT_FAILURE);
}
// Generates a cryptographically secure key of the specified length.