Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Can anyone help me find my OFFSET and HEX?

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking
View previous topic :: View next topic  
Author Message
Droppinacid
How do I cheat?
Reputation: 0

Joined: 03 Aug 2012
Posts: 9

PostPosted: Sun Aug 12, 2012 1:10 pm    Post subject: Can anyone help me find my OFFSET and HEX? Reply with quote

So i kinda figured out this pointer thing, but i ran into something weird.

Can anyone tell me what is my offset and what is my hex?
(I uploaded a picture)

Appreciate it,
-Dennis



ss__2012-08-11_at_04.21.58_-2_838-2.png
 Description:
 Filesize:  17.68 KB
 Viewed:  4181 Time(s)

ss__2012-08-11_at_04.21.58_-2_838-2.png


Back to top
View user's profile Send private message
Pingo
Grandmaster Cheater
Reputation: 8

Joined: 12 Jul 2007
Posts: 571

PostPosted: Sun Aug 12, 2012 4:06 pm    Post subject: Reply with quote

looks like the offset is just 0
_________________
Back to top
View user's profile Send private message
Gaz
Cheater
Reputation: 0

Joined: 08 Aug 2012
Posts: 40

PostPosted: Sun Aug 12, 2012 4:53 pm    Post subject: Reply with quote

offset 0
hex is 6911BD4
Back to top
View user's profile Send private message
Droppinacid
How do I cheat?
Reputation: 0

Joined: 03 Aug 2012
Posts: 9

PostPosted: Sun Aug 12, 2012 7:47 pm    Post subject: Reply with quote

yea thats what i thought, just kinda weird, when i put the hex in and press scan, nothing comes up.

Im gonna keep trying

Thanks for you're responses
-Dennis
Back to top
View user's profile Send private message
n0 m3rcY
Cheater
Reputation: 0

Joined: 18 Jun 2012
Posts: 42

PostPosted: Mon Aug 13, 2012 1:08 am    Post subject: Reply with quote

What that's doing is calling what's in player.dll (most likely) setting eax to that value. the brackets [] around eax mean that the instruction is accessing the eax as a pointer, and is assigning edi to the pointer eax holds.

It's probably DMA, so what you could do is replace the call command with a jmp to your codecave, call it, and then mov eax to some location within the program that is empty, then read that address. Ie:

Code:

001A dec edi
001B jmp 002E
001C nop
001D nop
001E mov [eax], edi
...
MyCave:
002E call player.dll+51B0
002F mov dword ptr ds:[00400000], eax ; your mem location
003A jmp 1C


Last edited by n0 m3rcY on Mon Aug 13, 2012 4:29 pm; edited 2 times in total
Back to top
View user's profile Send private message
Droppinacid
How do I cheat?
Reputation: 0

Joined: 03 Aug 2012
Posts: 9

PostPosted: Mon Aug 13, 2012 3:49 pm    Post subject: Reply with quote

I don't understand what you mean.

What you just said sounded alien to me.

Could you explain it in a little more detail? Im really slow when it comes to this.

Thanks for your answer
-Dennis
Back to top
View user's profile Send private message
n0 m3rcY
Cheater
Reputation: 0

Joined: 18 Jun 2012
Posts: 42

PostPosted: Mon Aug 13, 2012 11:47 pm    Post subject: Reply with quote

Droppinacid wrote:
I don't understand what you mean.

What you just said sounded alien to me.

Could you explain it in a little more detail? Im really slow when it comes to this.

Thanks for your answer
-Dennis

Okay, so some terms:
code cave: routing the game to a seperate location where you have empty bytes and can modify the game's routine and inject instructions
pointer: stores instead of a value such as an int or data, a memory address that has the data. Use pointers to assign value to the data.

So your instructions posted are doing (from the limited instructions I can see:)
Code:

001A dec edi                       ; can't tell from context exactly what the purpose of this is
001C call player.dll+51B0     ; calls some function, most functions will follow standard windows and set eax as a return value. in this case,                                   it's most likely allocating memory and assigning a pointer to your value (health, ammo?)
0022 mov [eax], edi             ; copies edi to the data pointed to by eax, ie if eax is 0023, it assigns edi to 0023.
0025 pop edi                        ; just re-assigns edi's original value from when it was push'd onto the stack
0026 mov eax, 1                  ; I have no idea why that's there, but that's what makes me think it's DMA because it's not storing the pointer anywhere. If it was you'd see something like:
mov dword ptr:[0000004A], eax
memory leak much? or does it generate the same pointer each time? is it getting info from a struct? are there any "push" instructions near this call instruction?


After looking at it, it does look somewhat like an ammo decreasing thing. Idk why it's not storing the value in eax though. What is this for, it's intriguing me.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites