Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Another Assembly Issue!
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking
View previous topic :: View next topic  
Author Message
Cake-san
Grandmaster Cheater
Reputation: 8

Joined: 18 Dec 2014
Posts: 541
Location: Semenanjung

PostPosted: Mon May 30, 2016 7:39 am    Post subject: Reply with quote

Code:

[ENABLE]
aobscan(inj_item,48 8D 44 C8 20 48 8B 00 48 8B 40 18 48 63 48 18 2B 4D E0)
inj_item:
db 48 8D 44 C8 20 48 8B 00 48 8B 40 18 B9 E7 03 00 00 90 90
registersymbol(inj_item)
[DISABLE]
inj_item:
db 48 8D 44 C8 20 48 8B 00 48 8B 40 18 48 63 48 18 2B 4D E0
unregistersymbol(inj_item)

_________________
...
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 7:47 am    Post subject: Reply with quote

Oh wow that's the code, hmm As I said i'm new to this, Unity is a bit harsh on me right now haha
Back to top
View user's profile Send private message
++METHOS
I post too much
Reputation: 92

Joined: 29 Oct 2010
Posts: 4196

PostPosted: Mon May 30, 2016 7:49 am    Post subject: Reply with quote

Sigh...

How do you expect to learn if you just copy other people's work...especially when the solution and approach isn't even remotely similar?

What a waste...
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 7:52 am    Post subject: Reply with quote

I did not copied the code, I am trying to Hack games myself, I already did for 2 games, Terraria and Youtubers Life, They were easy but mainly Unity is hard for me at the moment.

There are not many good tut out there, I mean Videos that I know anyway.

To get this code I would have to work for 1-2 weeks, not to mention that I don't know where to start with.


I'm only 1 week into AA, not to mention that I did not know the basics of Cheat engine Before so I had more to learn, value types and other stuff.
Back to top
View user's profile Send private message
Cake-san
Grandmaster Cheater
Reputation: 8

Joined: 18 Dec 2014
Posts: 541
Location: Semenanjung

PostPosted: Mon May 30, 2016 8:50 am    Post subject: Reply with quote

Since, this is an item script and the instruction isn't protected nor shared with other things that you don't want, you can just take a direct approach. Note: you need to have basic knowledge of assembly or just English and simple math. -_-

Let started:
Code:

""+7914A7B2: 48 8B 47 10                    -  mov rax,[rdi+10]
""+7914A7B6: 48 63 8F 94 00 00 00           -  movsxd  rcx,dword ptr [rdi+00000094]
""+7914A7BD: 48 63 C9                       -  movsxd  rcx,ecx
""+7914A7C0: 39 48 18                       -  cmp [rax+18],ecx
""+7914A7C3: 0F 86 14 01 00 00              -  jbe 7914A8DD
""+7914A7C9: 48 8D 44 C8 20                 -  lea rax,[rax+rcx*8+20] <_and this.
""+7914A7CE: 48 8B 00                       -  mov rax,[rax] <_same as this.
""+7914A7D1: 48 8B 40 18                    -  mov rax,[rax+18] <_ this rax/eax come from/the offset for item's pointer.
""+7914A7D5: 48 63 48 18                    -  movsxd  rcx,dword ptr [rax+18] <_ copy the value of the address rax+18 which is the current item amount onto rcx, double word size/4 bytes. This is where ecx/rcx come from.
""+7914A7D9: 2B 4D E0                       -  sub ecx,[rbp-20] <_ subtract ecx with the value of address rbp-20 & you can just change sub to add to increase item value everytime item is comsumed or just nop-ed this.
// ---------- INJECTING HERE ----------
""+7914A7DC: 89 48 18                       -  mov [rax+18],ecx  <_copy the value ecx into the value of address rax+18 & this instruction looks identical with others instruction in the game,so,not good enough to use as aobscan signature.
""+7914A7DF: 48 8B 47 10                    -  mov rax,[rdi+10]
// ---------- DONE INJECTING  ----------
""+7914A7E3: 48 63 8F 94 00 00 00           -  movsxd  rcx,dword ptr [rdi+00000094]
""+7914A7EA: 48 63 C9                       -  movsxd  rcx,ecx
""+7914A7ED: 39 48 18                       -  cmp [rax+18],ecx
""+7914A7F0: 0F 86 D0 00 00 00              -  jbe 7914A8C6
""+7914A7F6: 48 8D 44 C8 20                 -  lea rax,[rax+rcx*8+20]
""+7914A7FB: 48 8B 00                       -  mov rax,[rax]
""+7914A7FE: 48 8B 40 18                    -  mov rax,[rax+18]
""+7914A802: 48 63 40 18                    -  movsxd  rax,dword ptr [rax+18]
""+7914A806: 85 C0                          -  test eax,eax
""+7914A808: 40 0F 9F C0                    -  setg al


Sorry, I typed the comment for the instruction from below to upper.

So, in conclusion the info that I get is:

1. pointer for Item address is [ ? +rcx*8+20]+18 ,which you have to go deeper if you want to know the base address.

2.I can use instruction from lea rax,[rax+rcx*8+20] to sub ecx,[rbp-20] as aobscan signature because it looks unique to me. ( it comes with experience -_- )

3. I'm too lazy to alloc the new cave and since I had mention that you can just used direct approach( because you don't have to filter anything ).
I just do it like this:
Code:

[ENABLE]
aobscan(inj_item,48 8D 44 C8 20 48 8B 00 48 8B 40 18 48 63 48 18 2B 4D E0) //unique signature
inj_item:
db 48 8D 44 C8 20 48 8B 00 48 8B 40 18 B9 E7 03 00 00 90 90 //I had converted the instruction that I want to inject into array of bytes
//lea rax,[rax+rcx*8+20] // originalcode
//mov rax,[rax]  // originalcode
//mov rax,[rax+18]  // originalcode
//mov ecx,999  // copy 999 onto ecx
//nop  // replace the remainder code with code that does nothing so,it won't crash the game
//nop  // same -_-
registersymbol(inj_item) //registersymbol to make it able to use the symbol on disable part.
[DISABLE]
inj_item:
db 48 8D 44 C8 20 48 8B 00 48 8B 40 18 48 63 48 18 2B 4D E0  // originalcode
unregistersymbol(inj_item) //self explained


I'm sorry for my poor language and explanation.
Regards. Laughing

_________________
...
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 9:07 am    Post subject: Reply with quote

Haha thank you, I will look into more Videos about this since even with your explanation It's a bit hard for me to understand, but yea since It's Unity game I guess it makes it a bit harder to Hack.

I will stick with other games and try to Hack other stuff
Back to top
View user's profile Send private message
Cake-san
Grandmaster Cheater
Reputation: 8

Joined: 18 Dec 2014
Posts: 541
Location: Semenanjung

PostPosted: Mon May 30, 2016 9:21 am    Post subject: Reply with quote

KalasWD wrote:
Haha thank you, I will look into more Videos about this since even with your explanation It's a bit hard for me to understand, but yea since It's Unity game I guess it makes it a bit harder to Hack.

I will stick with other games and try to Hack other stuff


When making cheat/s for unity game, I always open 2 CE windows/process.One for debugger and the other one for mono features & dissect mono.
Both mono features & dissect mono really help to find info/s regarding the game itself.
The problem is, either you know how to use it or not. Laughing

Well, sometimes you just have to play around and figure it out how it work by yourselves. Cool

_________________
...
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 9:25 am    Post subject: Reply with quote

I do know how to use dissect yes, but depends on what for example for Terraria since it's a net type of game or something you can find a lot of good information in the dissect data, but mainly I'm into the Scripts so yea I am just looking around on Youtube to see how to work with that. not a lot of good tuts out there I wish someone like you could make one, A video perhaps to make it more easy to follow.


I'm watching him mostly : Stephen Chapman

PS: When using Cheat Engine my PC is slow as hell, my RAM is 8RAM incase that's matter, what could I do to like make it less laggy haha, I mean I didn't had that much of lags since the latest update.
Back to top
View user's profile Send private message
Cake-san
Grandmaster Cheater
Reputation: 8

Joined: 18 Dec 2014
Posts: 541
Location: Semenanjung

PostPosted: Mon May 30, 2016 9:42 am    Post subject: Reply with quote

KalasWD wrote:
I do know how to use dissect yes, but depends on what for example for Terraria since it's a net type of game or something you can find a lot of good information in the dissect data, but mainly I'm into the Scripts so yea I am just looking around on Youtube to see how to work with that. not a lot of good tuts out there I wish someone like you could make one, A video perhaps to make it more easy to follow.


I'm watching him mostly : Stephen Chapman

PS: When using Cheat Engine my PC is slow as hell, my RAM is 8RAM incase that's matter, what could I do to like make it less laggy haha, I mean I didn't had that much of lags since the latest update.


Sorry,I'm no youtuber/video person.( my net are too slow for that )
I can only typed & read. Laughing

For the laggy part, you can just freeze the game while CE is scanning or while you're writing script / browsing info/s dumped on CE.

Go to setting below the CE logo -> Hotkeys -> Pause the selected process -> set your hotkey -> OK

Now you can paused your game's process. Rolling Eyes

_________________
...
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Mon May 30, 2016 9:46 am    Post subject: Reply with quote

Your first script (link) is obviously not going to do anything besides what the original code did.

You said the script works when you first inject it. Then, in your very next post, you say it just doesn't work (even when you first inject it). That's confusing and generally makes people not want to help you.

KalasWD wrote:
The value does change, it's decreasing even with the script is on, It's like the address is changing when I Restart my game

How is the address changing when you restart the game and your script not working related in any way? If that instruction isn't inside a module, then of course it's going to change when you exit the game and reopen it. That won't make your script work any better if it's already wrong.

In your second script (link), I don't know why you're writing an injection at 69C90000. I'm guessing you had your first script active, saw it in the disassembler, and (for some reason) still injected there despite that obviously not being the game's code. Also, you forgot to execute the instruction mov rax,[rdi+10] which was a part of the original code.

If you used a unique AoB signature in an AoB scan, wrote your jmp at the instruction mov [rax+18],ecx, and executed the instructions mov [rax+18],3E7 / mov rax,[rdi+10], your script would be functionally equivalent to Cake-san's script. The only difference would be that your script jumps to other code and jumps back while Cake-san's script uses the memory already there (more efficient). Based on your first and second scripts, you obviously had the right idea, but lacked common sense somewhere along the way.

PS: if Unity JITs code, you'll need to trigger that asm to run at least once in-game before attempting to search for it. Of course, if you did anything in Terraria, you should already know this.

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 9:53 am    Post subject: Reply with quote

I mean that when making the Script I was simply adding the mov [rax+10],(int)999

It works when I make it in place, but for example if I save my CT, and launch the game again, attach it to Cheatengine, the script will no longer be active, means my items will keep decreasing and will not be set to 999 Like the Code was meant to do. Also sorry I'm from Israel my English is rusty Smile


The game is Empyrion by the way, so you think we can do this process one more time I will post the new script, and if you willing to help me out step by step after Smile
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Mon May 30, 2016 10:06 am    Post subject: Reply with quote

KalasWD wrote:
If I save my CT, and launch the game again, attach it to Cheatengine, the script will no longer be active...

Of course. The modifications CE makes to a process's memory will not persist when restarting the process. That means you have to reactivate your script when you restart the game. If you can't reactivate your script but you could activate it the first time:
ParkourPenguin wrote:
If Unity JITs code, you'll need to trigger that asm to run at least once in-game before attempting to search for it.


Also, both you and Cake-san shouldn't worry about your use of the English language. I've seen far worse, some of whom were probably native English speakers.

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 10:08 am    Post subject: Reply with quote

Oh haha, thank you for your help first of all, I moved on to another game I can't deal with Empyrion it's to much for me at the moment with my lack of skills...

I moved to one troll army, also Unity but It seems more easy to Hack. I will make a new Thread about this game since this thread is just full of junks.
Back to top
View user's profile Send private message
Cake-san
Grandmaster Cheater
Reputation: 8

Joined: 18 Dec 2014
Posts: 541
Location: Semenanjung

PostPosted: Mon May 30, 2016 10:20 am    Post subject: Reply with quote

ParkourPenguin wrote:

Also, both you and Cake-san shouldn't worry about your use of the English language.

I feel some weight from my heart has been lifted. Very Happy
KalasWD wrote:

I moved to one troll army, also Unity but It seems more easy to Hack.

Why not try Idling to Rule the Gods steam version ? You have to make full use of mono features/dissector to make/find cheat/s for this game because simply scanning seems pretty useless. This game has so much variables,thought. Rolling Eyes

_________________
...
Back to top
View user's profile Send private message
KalasDev
Master Cheater
Reputation: 1

Joined: 29 May 2016
Posts: 311

PostPosted: Mon May 30, 2016 12:07 pm    Post subject: Reply with quote

finding Pointers is not the issue for me, the main thing I want to learn is Scripts, AA, Is there any place you might know that could be usefull for me ? So I can learn alot from it. I want to know basics, for example how to do Godmode, but for games like Doom 2016 so you need to cmp, cause the Address accesses all the enemy and player for example.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites