PE File section relocation and stack cookies -> Error











up vote
0
down vote

favorite












i'm trying to increase the size of a pe section which is located after the .text section. I want to increase the size of .rdata by 0x1000 to go from this layout



layout before



to that layout



layout after



by adding 0x1000 as an offset k to the section size.



What am i doing to achieve this:




  • Adding extra size/offset (k) to the "VirtualSize" property of the pe file

  • Adding the offset k to all "VirtualAddress" properties of all following sections

  • Adding the offset k to the "SizeOfImage" property of the pe header

  • Adding k to all data directory adresses greater or equal 0x5000


What's the problem:
I can start the pe file without the windows loader complaining. Still the new exe crashes because of a call to "_security_init_cookie". If however i use a debugger to patch out the stack cookie calls and jump directly to the real main the programm start's normally.



My question:
How can i fix this error concerning the stack cookies? Where are the adresses in the pe file i need to patch to do so?



I'm aware i'd normally need to patch the reloc table too. In this case i have checked that there are no entries for the sections i want to relocate.










share|improve this question
























  • Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
    – Margaret Bloom
    Nov 11 at 15:46






  • 3




    The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
    – Ross Ridge
    Nov 11 at 17:33










  • @RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
    – Stephen Ahmad
    Nov 16 at 15:01










  • Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
    – Stephen Ahmad
    Nov 16 at 15:02















up vote
0
down vote

favorite












i'm trying to increase the size of a pe section which is located after the .text section. I want to increase the size of .rdata by 0x1000 to go from this layout



layout before



to that layout



layout after



by adding 0x1000 as an offset k to the section size.



What am i doing to achieve this:




  • Adding extra size/offset (k) to the "VirtualSize" property of the pe file

  • Adding the offset k to all "VirtualAddress" properties of all following sections

  • Adding the offset k to the "SizeOfImage" property of the pe header

  • Adding k to all data directory adresses greater or equal 0x5000


What's the problem:
I can start the pe file without the windows loader complaining. Still the new exe crashes because of a call to "_security_init_cookie". If however i use a debugger to patch out the stack cookie calls and jump directly to the real main the programm start's normally.



My question:
How can i fix this error concerning the stack cookies? Where are the adresses in the pe file i need to patch to do so?



I'm aware i'd normally need to patch the reloc table too. In this case i have checked that there are no entries for the sections i want to relocate.










share|improve this question
























  • Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
    – Margaret Bloom
    Nov 11 at 15:46






  • 3




    The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
    – Ross Ridge
    Nov 11 at 17:33










  • @RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
    – Stephen Ahmad
    Nov 16 at 15:01










  • Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
    – Stephen Ahmad
    Nov 16 at 15:02













up vote
0
down vote

favorite









up vote
0
down vote

favorite











i'm trying to increase the size of a pe section which is located after the .text section. I want to increase the size of .rdata by 0x1000 to go from this layout



layout before



to that layout



layout after



by adding 0x1000 as an offset k to the section size.



What am i doing to achieve this:




  • Adding extra size/offset (k) to the "VirtualSize" property of the pe file

  • Adding the offset k to all "VirtualAddress" properties of all following sections

  • Adding the offset k to the "SizeOfImage" property of the pe header

  • Adding k to all data directory adresses greater or equal 0x5000


What's the problem:
I can start the pe file without the windows loader complaining. Still the new exe crashes because of a call to "_security_init_cookie". If however i use a debugger to patch out the stack cookie calls and jump directly to the real main the programm start's normally.



My question:
How can i fix this error concerning the stack cookies? Where are the adresses in the pe file i need to patch to do so?



I'm aware i'd normally need to patch the reloc table too. In this case i have checked that there are no entries for the sections i want to relocate.










share|improve this question















i'm trying to increase the size of a pe section which is located after the .text section. I want to increase the size of .rdata by 0x1000 to go from this layout



layout before



to that layout



layout after



by adding 0x1000 as an offset k to the section size.



What am i doing to achieve this:




  • Adding extra size/offset (k) to the "VirtualSize" property of the pe file

  • Adding the offset k to all "VirtualAddress" properties of all following sections

  • Adding the offset k to the "SizeOfImage" property of the pe header

  • Adding k to all data directory adresses greater or equal 0x5000


What's the problem:
I can start the pe file without the windows loader complaining. Still the new exe crashes because of a call to "_security_init_cookie". If however i use a debugger to patch out the stack cookie calls and jump directly to the real main the programm start's normally.



My question:
How can i fix this error concerning the stack cookies? Where are the adresses in the pe file i need to patch to do so?



I'm aware i'd normally need to patch the reloc table too. In this case i have checked that there are no entries for the sections i want to relocate.







windows assembly memory






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited Nov 12 at 8:58









xmojmr

7,04842240




7,04842240










asked Nov 11 at 15:13









Stephen Ahmad

85




85












  • Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
    – Margaret Bloom
    Nov 11 at 15:46






  • 3




    The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
    – Ross Ridge
    Nov 11 at 17:33










  • @RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
    – Stephen Ahmad
    Nov 16 at 15:01










  • Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
    – Stephen Ahmad
    Nov 16 at 15:02


















  • Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
    – Margaret Bloom
    Nov 11 at 15:46






  • 3




    The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
    – Ross Ridge
    Nov 11 at 17:33










  • @RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
    – Stephen Ahmad
    Nov 16 at 15:01










  • Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
    – Stephen Ahmad
    Nov 16 at 15:02
















Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
– Margaret Bloom
Nov 11 at 15:46




Maybe you also need to patch the relocations? To be sure: you don't also want to increase the size of .rodata in the file, do you?
– Margaret Bloom
Nov 11 at 15:46




3




3




The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
– Ross Ridge
Nov 11 at 17:33




The PECOFF format doesn't support moving sections relative to other sections like this. You can append a section at the end, but you can't insert or expand a section in the middle. If the executable isn't relocatable then all addresses are fixed and all sections need to be loaded at their specified addresses. If the executable is relocatable then entire executable image needs relocated as a single block, so that the distance between any two locations never changes.
– Ross Ridge
Nov 11 at 17:33












@RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
– Stephen Ahmad
Nov 16 at 15:01




@RossRidge I'm aware of this fact. I just thought that since it's after the code section and there are no relocations for the following sections it should work.
– Stephen Ahmad
Nov 16 at 15:01












Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
– Stephen Ahmad
Nov 16 at 15:02




Could i iterate through the code section fixing all references? I mean effectively i don't need to fix jumps since it's after the code section. I'd need analyze the code section for mov other reference commands check their adresses and fix them.
– Stephen Ahmad
Nov 16 at 15:02

















active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53250099%2fpe-file-section-relocation-and-stack-cookies-error%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown






























active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.





Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


Please pay close attention to the following guidance:


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53250099%2fpe-file-section-relocation-and-stack-cookies-error%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Full-time equivalent

さくらももこ

13 indicted, 8 arrested in Calif. drug cartel investigation