 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
Slugsnack Grandmaster Cheater Supreme
Reputation: 71
Joined: 24 Jan 2007 Posts: 1857
|
Posted: Thu Dec 18, 2008 10:27 am Post subject: |
|
|
that was what i meant by being careful.. and hence my suggestion to build in some debugging code.
if you left cef.. either stay away or properly come back.
|
|
| Back to top |
|
 |
nog_lorp Grandmaster Cheater
Reputation: 0
Joined: 26 Feb 2006 Posts: 743
|
Posted: Fri Dec 19, 2008 10:13 pm Post subject: |
|
|
How the call is made does not matter in the least. The ONLY source of information about the caller is the return address, which can only be of two things: are RET or a RETF (if it is something else it will be apparent by the function). If it is a RET, the return address will be [esp] when the function is called, regardless of how the function is called. If it is a RETF, the return address will be segment [esp-4] : [esp]. All other details of the call are not concerns.
Also, since when has anything in this forum been considered not a valid suggestion because it is "a hack", especially one that is a hack because "Microsoft does not support it". _ReturnAddress() is certainly a useful suggestion, but its existence in certain scenarios does not invalidate all other options. He could be using any other compiler, or delphi (a favorite for these forums eh), or another operating system.
I'm glad I'm still capable of pissing you off x0r.
~nog_lorp
_________________
Mutilated lips give a kiss on the wrist of the worm-like tips of tentacles expanding in my mind
I'm fine accepting only fresh brine you can get another drop of this yeah you wish |
|
| Back to top |
|
 |
Trucido Moderator
Reputation: 6
Joined: 08 Sep 2007 Posts: 2792
|
Posted: Sat Dec 20, 2008 1:58 am Post subject: |
|
|
| Slugsnack wrote: | | that was what i meant by being careful.. and hence my suggestion to build in some debugging code. |
...And hence my saying that anyone attempting to code something like that is probably brain-dead.
| Slugsnack wrote: | | if you left cef.. either stay away or properly come back. |
wat.
| nog_lorp wrote: | | How the call is made does not matter in the least. The ONLY source of information about the caller is the return address, which can only be of two things: are RET or a RETF (if it is something else it will be apparent by the function). If it is a RET, the return address will be [esp] when the function is called, regardless of how the function is called. If it is a RETF, the return address will be segment [esp-4] : [esp]. All other details of the call are not concerns. |
This isn't the problem, but you're seemingly too dense to deduce this; OP wanted the caller address, which led you to reply with "If you do it before the function prologue, then it is [esp]", seemingly oblivious to his question. I stated that it wasn't feasible to get the call address, instead settling for the return address. You misconstrued what I said and assumed that I was saying depending on the call type, retrieving the call address wasn't possible. So quit hammering away at this, you're either blind or stupid, hell, maybe even a combination of both!
| nog_lorp wrote: | | Also, since when has anything in this forum been considered not a valid suggestion because it is "a hack", especially one that is a hack because "Microsoft does not support it". _ReturnAddress() is certainly a useful suggestion, but its existence in certain scenarios does not invalidate all other options. He could be using any other compiler, or delphi (a favorite for these forums eh), or another operating system. |
Again, either your eyes are faltering or you're just seeing what you want to see. I explicitly stated that I was saying this under the assumption that he was coding in C, so you mentioning Delphi just further perpetuates my belief that you're either blind or stupid. Also, most compilers (GCC, LCC, PCC, etc) come with support for the __builtin_return_address() function, which essentially has the same functionality as _ReturnAddress(). Your suggestion of directly accessing ESP became erroneous when it was superseded by my suggestion of using a supported way of getting the return address.
| nog_lorp wrote: | I'm glad I'm still capable of pissing you off x0r.
~nog_lorp |
Didn't really get what Slugsnack meant until you said that, So thanks for informing me that I'm actually x0r and not... myself?
_________________
I'm out. |
|
| Back to top |
|
 |
nog_lorp Grandmaster Cheater
Reputation: 0
Joined: 26 Feb 2006 Posts: 743
|
Posted: Sat Dec 20, 2008 2:49 pm Post subject: |
|
|
I did misunderstand your comment regarding call type. However, in light of the context of the thread (every post before yours and mine, up to the original one), it had been made clear the only viable method of doing something similar to what void wanted was to get the return address. Apologies for trying to take your post in context (although I can't blame you for skipping over most of the posts on CEF in general).
Additionally, as I have misunderstood your post, so have you misunderstood mine: I never made a suggestion or gave any directions. I was providing information, and accurate at that. While some of it may have been extraneous (regarding call type, as I was arguing with you about something you never said ), none of it was erroneous (this is where you really start to sound like x0r).
Finally, the supported method is not always the best method. Facts embedded in the architecture do not risk "deprecation by microsoft". If you know the exact location of the return address it is a waste of time and space to use a scanning function to find it. Also, the fact that you assumed he was using C does not make your assumption valid. Nor does the fact the GCC has a similar intrinsic mean that the original poster is using a compiler that does.
You take a very Irwinesque philosophical standpoint that information, even correct information with no moral attachments, can be bad or evil.
But, I hope you are actually you and not someone else - good luck with your identity crisis
_________________
Mutilated lips give a kiss on the wrist of the worm-like tips of tentacles expanding in my mind
I'm fine accepting only fresh brine you can get another drop of this yeah you wish |
|
| Back to top |
|
 |
sponge I'm a spammer
Reputation: 1
Joined: 07 Nov 2006 Posts: 6009
|
Posted: Sat Dec 20, 2008 3:38 pm Post subject: |
|
|
Let's face it guys. Trucido isn't that smart.
_________________
|
|
| Back to top |
|
 |
rapion124 Grandmaster Cheater Supreme
Reputation: 0
Joined: 25 Mar 2007 Posts: 1095
|
Posted: Sat Dec 20, 2008 4:11 pm Post subject: |
|
|
Just do
| Code: |
mov eax, [esp]
... //do something using return address (just don't fuck up the stack)
jmp [Trampoline]
|
Regardless of the call method, if you are hooking before the prologue, the return address is always in [esp]. After the prologue and into the function, it's very hard to find the return address as a new stack frame will be set up.
Microsoft calls this method a "hack" because most data on the stack isn't a pointer. If you dereference the wrong thing, you are screwed.
|
|
| Back to top |
|
 |
nog_lorp Grandmaster Cheater
Reputation: 0
Joined: 26 Feb 2006 Posts: 743
|
Posted: Sat Dec 20, 2008 5:29 pm Post subject: |
|
|
rapion, [esp] doesn't deference the data ON the stack, it dereferences the stack pointer - IE giving you the top element of the stack. Only if esp has been corrupted (i.e., not possible unless someone was intentionally crashing the program, and not possible after a real call because esp has to be valid at the time of the call) would [esp] cause problems.
_________________
Mutilated lips give a kiss on the wrist of the worm-like tips of tentacles expanding in my mind
I'm fine accepting only fresh brine you can get another drop of this yeah you wish |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|