Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


help with CE and mono dissect
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine
View previous topic :: View next topic  
Author Message
Tr1gun87
Cheater
Reputation: 0

Joined: 17 May 2017
Posts: 27

PostPosted: Tue Aug 25, 2020 7:20 am    Post subject: Reply with quote

no still can't find the solution Smile

i need to understand how to get the memory value from a getUser() method

with ILSpy of the method i get this:
public static hs User => SimManager?.CurrentContext?.ag();
(called by a static object)

if i use a breakpoint and trace i get the value in the img but don't know how find it (the code of the img is the ag() )
nothing have a clear address... eax came from the stack... so i have no idea where and when that value get pushed
from what i understand ebp is the start of the stack inside the function, so is the return value, but i have still no idea how to get that value

any hint? Very Happy

https://controlc.com/cd787069 <- the trace of the img



getuser.png
 Description:
 Filesize:  26.8 KB
 Viewed:  639 Time(s)

getuser.png


Back to top
View user's profile Send private message
Csimbi
I post too much
Reputation: 94

Joined: 14 Jul 2007
Posts: 3110

PostPosted: Tue Aug 25, 2020 7:48 am    Post subject: Reply with quote

Some based offset seems to come from the stack: EPB+08.
The, base+14 is read.
Did you check what's the base and where's that base coming from?
Back to top
View user's profile Send private message
Tr1gun87
Cheater
Reputation: 0

Joined: 17 May 2017
Posts: 27

PostPosted: Tue Aug 25, 2020 8:21 am    Post subject: Reply with quote

on the link there is the export of the trace
i don't see anything...

i saw ebp = starting position of the stack at the start of the call, so maybe ebp+8 is the esi value?


i noticed now the trace and the image come from 2 different sessions Very Happy
the select line of the img is line 9263 on the trace file
184AFA8E - lea esp,[ebp-08]
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites