Skip to content

Support for detecting trailing non-LNK data #49

@wxsBSD

Description

@wxsBSD

Some LNK files have data appended to the end. It would be useful if liblnk could detect that there is data at the end of the file and represent it as an offset value so it can be easily carved out. a8fac75d06cf1d4e30f9b118a962a24413d046dec622bd17dd594250252543e9 is one example of a LNK with a PE appended to the end of it. While easy to find the PE I have other examples with encrypted/compressed data on the end that are not easily recognizable.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions