Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Checking valid offset before reading its value

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine
View previous topic :: View next topic  
Author Message
thefreestyle
Cheater
Reputation: 0

Joined: 29 Oct 2015
Posts: 35

PostPosted: Wed Sep 19, 2018 12:00 pm    Post subject: Checking valid offset before reading its value Reply with quote

Hi guys,

My script sometimes crashes the game and from what i see its because im trying to get value from offset which actually not exist ( question marks ) or just number instead of address , since its shared function for damage all kind of stuff going trough, my goal is to check if this my player or not, and i check this by some offset from some register.
Problem is that sometimes that offset is not valid player and has some random value instead address and any subsequent offsets reading crash the game, for example :

Code:

mov ecx,[ebp+A8]  // 1st offset reading, at this point ebp always exist
mov ecx,[ecx+000000EC]   //2nd offset, at this point +ec can have valid address or some random value, like 1
mov ecx,[ecx+00000098]   // 3rd offset, if prev offset was address then all ok, but if it was a number then crash occur, my guess since im trying to read value from some address but its just a number


So how could this be avoided ? how can i check that given offset is pointer and not just number or no value at all, like question marks (??) ?

Any help would be appreciated
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 379

Joined: 09 May 2003
Posts: 22555
Location: The netherlands

PostPosted: Wed Sep 19, 2018 12:43 pm    Post subject: Reply with quote

if the only invalid values are either 0 or 1 or below 10000 then you can you can of course check if ecx is bigger than 10000 and if so it's valid

or if you're on 6.8.1 use {$try}/{$except}

e.g:
Code:

{$try}
mov ecx,[ebp+A8]  // 1st offset reading, at this point ebp always exist
mov ecx,[ecx+000000EC]   //2nd offset, at this point +ec can have valid address or some random value, like 1
mov ecx,[ecx+00000098]   // 3rd offset, if prev offset was address then all ok, but if it was a number then crash occur, my guess since im trying to read value from some address but its just a number
jmp stillalive
{$except}
//this code gets executed on an exception ( like invalid memory access or ce's VEH debug single step, etc...)
jmp originalcode

stillalive:
//No exception happened and "jmp stillalive" was executed
//do stuff you'd normally do

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
thefreestyle
Cheater
Reputation: 0

Joined: 29 Oct 2015
Posts: 35

PostPosted: Wed Sep 19, 2018 1:27 pm    Post subject: Reply with quote

Hi Dark Byte

Thank you for your reply. Cant believe i did not see that simple and elegant solution.

Actually i am on 6.8.1 and had no idea about try/catch.

Gonna try both approaches.

Btw, about the questions marks (no value), is checking against zero is enough ?

So checking bigger then 10000 covers no values too ?
Back to top
View user's profile Send private message
Dark Byte
Site Admin
Reputation: 379

Joined: 09 May 2003
Posts: 22555
Location: The netherlands

PostPosted: Wed Sep 19, 2018 1:50 pm    Post subject: Reply with quote

Windows allocates memory from address 0x10000 and up. So you can be sure that any value smaller than that is an invalid address

Also, you may want to have a way to restore ECX (in case it's important), so perhaps put a push ecx in front, and in the except and stillalive add a pop ecx

_________________
Do not ask me about online cheats. I don't know any and wont help finding them.

Like my help? Join me on Patreon so i can keep helping
Back to top
View user's profile Send private message MSN Messenger
thefreestyle
Cheater
Reputation: 0

Joined: 29 Oct 2015
Posts: 35

PostPosted: Wed Sep 19, 2018 2:00 pm    Post subject: Reply with quote

Quote:

Windows allocates memory from address 0x10000 and up. So you can be sure that any value smaller than that is an invalid address


That i did not knew either, that explains why you said 10000 before, i thought it just random high number.

Yes, i have pushed and poped ECX, its just portion of the script.

Anyway thank you so much, you helped me a lot, now i go to work and hope i get rid of those crashes !!!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites