| View previous topic :: View next topic |
| Author |
Message |
hellknight99 Cheater
Reputation: 0
Joined: 27 Feb 2008 Posts: 39
|
Posted: Fri Mar 28, 2008 11:36 pm Post subject: how to save address? ( for next game ) |
|
|
so im like hacking some flash games. but the address of something keep changing. so I got the pointer made it an address now what?
It doesn't even point to the write thing o.O
( I did "What writes to this address" on the correct address)
Also what does EAX + 79 mean? for example
EAX is a bunch of numbers , like 000AB940 or something like that. What would be the offset.
|
|
| Back to top |
|
 |
Psy Grandmaster Cheater Supreme
Reputation: 1
Joined: 27 Mar 2008 Posts: 1366
|
Posted: Sat Mar 29, 2008 3:32 am Post subject: |
|
|
hellknight99, eax is the start of a structure. 79 is the offset in that case.
So that address of EAX+79 = the value you first found.
Depending on what its for...health? ammo? xp? etc... you could either choose to nop that instruction, ie. replace the bytes with 90's to make it skip that part of the code, or you could try some code-injection, of which there are numerous tutorials floating around.
Get back to me with more info and i'll try to help you out. I take it you are using Cheat engine for this? I'll walk you through.
But first, find that address again (the one which changes), find that instruction again that writes to / accesses it, and bring up the memory view window, or 'show dissassembler'. Then take a screenshot of several lines above and below that code.
Then I can see what you can do with it.
~Psych
|
|
| Back to top |
|
 |
Symbol I'm a spammer
Reputation: 0
Joined: 18 Apr 2007 Posts: 5094 Location: Israel.
|
Posted: Sat Mar 29, 2008 4:05 am Post subject: |
|
|
If this flash game is on a website (and not an executable file on yor computer) the addresses will probably always be dynamic.
EAX+17 means the value of eax is the base address of the pointer and 17 is the offset, so add 17 to eax to get the address it points to.
|
|
| Back to top |
|
 |
hellknight99 Cheater
Reputation: 0
Joined: 27 Feb 2008 Posts: 39
|
Posted: Sat Mar 29, 2008 9:33 am Post subject: |
|
|
Lets see , I hacked warcraft 3 single player for some practive.
I got the gold address and I got its pointer.
Now what? Is the pointer , suppose to tell me the gold address everytime I restart the game?
|
|
| Back to top |
|
 |
Psy Grandmaster Cheater Supreme
Reputation: 1
Joined: 27 Mar 2008 Posts: 1366
|
Posted: Sat Mar 29, 2008 11:27 am Post subject: |
|
|
Yeah. You read the value of eax+17 (<-- and example) and the write to that offset.
Search for tuts on cheat engine, dma and code-injection. You'll find what you need. Good luck
|
|
| Back to top |
|
 |
Labyrnth Moderator
Reputation: 10
Joined: 28 Nov 2006 Posts: 6300
|
Posted: Sat Mar 29, 2008 5:59 pm Post subject: |
|
|
[Psych]
You cant do a code injection on the dll controlling the flash. Trust me, been there tried that.
Depending on browser and flash version, you end up in one of these dll files with your instruction.
FireFox:
NPSWF32.dll
Internet Explorer: *Depending on version
Flash8.ocx
Flash9.ocx
Flash9d.ocx
You will crash the browser with any alteration. Flash games are allocated and wont have a good address after you close your browser mate.
This is why people are passing variables to the flash object on a form in VB making alterations to the action script.
"Not Memory"
If you want to try it, go ahead you will see what i mean. Need some help, hit me on MSN ill show you what im talking about.
|
|
| Back to top |
|
 |
Dark Byte Site Admin
Reputation: 475
Joined: 09 May 2003 Posts: 25989 Location: The netherlands
|
Posted: Sat Mar 29, 2008 7:45 pm Post subject: |
|
|
Actually, it's possible but you'll have to work a bit more high-level . Assembler only will not work
If you just do a code injection you have to write your own object parser to distinguish between objects that the code accesses.
another method is hooking into the flash activex control, you can then call the setvariable and getvariable methods and edit stuff like this
http://forum.cheatengine.org/viewtopic.php?p=1556668&highlight=#1556668 is a good example of such a usage
_________________
Tools give you results. Knowledge gives you control.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
Psy Grandmaster Cheater Supreme
Reputation: 1
Joined: 27 Mar 2008 Posts: 1366
|
Posted: Sun Mar 30, 2008 4:57 am Post subject: |
|
|
And in any case, I was responding to hellknight.... he was talking about Warcraft 3. I know about the flash .dlls, hehe
|
|
| Back to top |
|
 |
Labyrnth Moderator
Reputation: 10
Joined: 28 Nov 2006 Posts: 6300
|
Posted: Sun Mar 30, 2008 7:37 pm Post subject: |
|
|
| [Psych] wrote: | And in any case, I was responding to hellknight.... he was talking about Warcraft 3. I know about the flash .dlls, hehe  |
Agh yess i see that topic change now
DB thats like way too much work for a flash game lol!
Especially when you can just pass the variable to a flash object on a vb form like they do now.
I looked at it anyways, and it works for IE only :S.
Still some pretty good stuff to read over.
|
|
| Back to top |
|
 |
|