On Wed Apr 24 15:30:39 2024 +0000, eric pouech wrote:
right, but this means that you never include in the hash what's after the content of the security directory? (and another nitpick, not sure it does matter so much for real images, but it should be checked against nth->OptionalHeader.NumberOfRvaAndSizes that security header in present)
The signature is specified to come last. I added a check for NumberOfRvaAndSizes.