Extract .exe Resources with dd: Difference between revisions

From Leo's Notes
This page was last edited on 1 September 2019, at 02:31.
m reformat
m formatting
Line 4: Line 4:


{{highlight|lang=bash|code=
{{highlight|lang=bash|code=
<nowiki>
Location=0
Location=0


Line 20: Line 21:
# You could assume it goes until the end of the binary and extract
# You could assume it goes until the end of the binary and extract
# the segment from $Location to `du -b SIMTOWER.EXE`.
# the segment from $Location to `du -b SIMTOWER.EXE`.
</nowiki>
}}
}}


[[Category:Linux]]{{Navbox Linux}}
[[Category:Linux]]{{Navbox Linux}}
[[Category:Stub]]

Revision as of 02:31, 1 September 2019

One method of extracting resources from a binary file is to first locate the start of each resource segment by its file header and then extract it out until the next file header.

For example, to get all audio resources (a .wav file with a file header of 'RIFF'), get all the offsets where the string 'RIFF' starts and extract the data from there until the next header:

Location=0

strings -a -t d SIMTOWER.EXE | grep -i RIFF | awk '{print $1}' | while read i ; do
	if [ $Location -eq 0 ] ; then
		Location=$i
		continue
	fi

	Length=$(($i-$Location))
	dd if=SIMTOWER.EXE of=$Location bs=1 count=$Length skip=$Location
	Location=$i
done

# The last record will need to be extracted manually.
# You could assume it goes until the end of the binary and extract
# the segment from $Location to `du -b SIMTOWER.EXE`.