 |
Cheat Engine The Official Site of Cheat Engine
|
| View previous topic :: View next topic |
| Author |
Message |
mibiz Cheater
Reputation: 0
Joined: 14 Jun 2009 Posts: 31
|
Posted: Mon Feb 15, 2010 9:46 pm Post subject: |
|
|
| tombana wrote: | I have a bot for an mmorpg. What I do is basically have a thread that loops and does:
- check if it needs to use food
- check if it needs to get buffs
- attack every monster on the target list
- if the targetlist is empty (all monsters on the list died) then add new monsters
- repeat
I use packet editing. So I receive the packets from the server and parse them to get the monster info and so on. And to attack I send packets etc. |
Bot via packets? NICE!!! I'm trying to create one in C# v2 but using low level hooks to keyboard/mouse to the app but having problems
EDIT:
| kot1990 wrote: | Anyone who has created a bot for mmorpg games? I want an explanation about how a bot works and what I have to learn to do it. I am not newbie. I understand C/C++ classes/pointers and all that stuff and a little winapi and how to write/read from memory. I don't ask for any hack/cheat for specific game.
What is really happening when I target something or attacking/using skill etc.? Is there a way to force the application do that? |
I suggest you first get structure of the character profile/stats in the memory. Then base your bot on how you would play the character's class but then expand or simplify a bit to include for other classes also. As for send the input keyboard/mouse for the action, you could do packets as tombana is doing. Or use low level hooks to send keyboard/mouse, which is what I'm doing now. I got most of the logic for bot operations in place. Only thing left is get the low level hooks working. Then my bot can run multi-game/multi-client.
|
|
| Back to top |
|
 |
kot1990 Expert Cheater
Reputation: 1
Joined: 06 Sep 2009 Posts: 131 Location: Greece
|
Posted: Wed Feb 17, 2010 8:33 am Post subject: |
|
|
I think I found how to hook send function from ws2_32.dll but I need a little help to understand, where what is copied and what's happening. I'm confused.
| Code: | //http://somebastardstolemyname.wordpress.com
//The_Undead : Rhys M.
//winsock send hook
#include "windows.h"
#include "winsock.h"
#pragma comment ( lib, "Ws2_32.lib" )
#define JMP(frm, to) (int)(((int)to - (int)frm) - 5);
DWORD SendOriginalAddress = 0;
DWORD SendReturnAddress = 0;
DWORD* SendNewAddress = 0;
DWORD OldProtection = 0;
char* send_buffer;
int send_sizeofdata = 0;
SOCKET send_s;
int send_flags = 0;
void __declspec(naked) __stdcall SendHookFunc()
{
__asm
{
mov edi,edi
push ebp
mov ebp, esp
mov eax, [ebp+0x08] /* Param 1 : Socket */
mov send_s, eax
mov eax, [ebp+0x0C] /* Param 2 : buffer */
mov [send_buffer], eax
mov eax, [ebp+0x10] /*Param 3 : Size*/
mov send_sizeofdata, eax
mov eax, [ebp+0x14] /*Param 4 : flags*/
mov send_flags, eax
jmp SendReturnAddress
}
}
void UnHookSend()
{
/* To unhook on a WinXP post SP2 box you need to restore the 5 byte preamble */
*(WORD *)SendOriginalAddress = 0xFF8B; // mov edi,edi
*(BYTE *)(SendOriginalAddress+2) = 0x55; // push epb
*(WORD *)(SendOriginalAddress+3) = 0xEC8B; // mov epb, esp
VirtualProtect( (void*)SendOriginalAddress, 0x05, OldProtection, &OldProtection );
}
void HookSend()
{
SendNewAddress = (DWORD*)SendHookFunc;
HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll");
SendOriginalAddress = (DWORD)GetProcAddress(hDll, "send");
SendReturnAddress = SendOriginalAddress + 5;
VirtualProtect( (void*)SendOriginalAddress, 0x05, PAGE_READWRITE , &OldProtection );
*(BYTE *)(SendOriginalAddress) = 0xe9;
*(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress);
}
BOOL APIENTRY DllMain( HMODULE hModule,
DWORD ul_reason_for_call,
LPVOID lpReserved
)
{
if (ul_reason_for_call == DLL_PROCESS_ATTACH)
HookSend();
if (ul_reason_for_call == DLL_THREAD_DETACH)
UnHookSend();
return TRUE;
}
|
It seems that the first 5 byte instructions are the first 5 bytes of the send() in the ws2_32 module.
| Code: | void HookSend()
{
SendNewAddress = (DWORD*)SendHookFunc; // <-- The address of my SendHookFunc().
HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll"); // <-- Load the library into my process' address space and get a handle.
SendOriginalAddress = (DWORD)GetProcAddress(hDll, "send"); // <-- Get the address of the module's function send().
SendReturnAddress = SendOriginalAddress + 5; // <--Point to +5 bytes.
VirtualProtect( (void*)SendOriginalAddress, 0x05, PAGE_READWRITE , &OldProtection );// <-- Change the protection of the 5 bytes to PAGE_READWRITE.
*(BYTE *)(SendOriginalAddress) = 0xe9; // <-- what is this?
*(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress); // <-- and this?
} |
What are these double asterisks *(BYTE *) . The one in the end shows that is it a pointer to BYTE, and the first one?? dereference?
EDIT: Ok got it
0xe9 is the code for a jmp instruction and then with *(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress); I will change the 4 bytes that is the address of the hook function, and then the last jmp in my hook function will return to the 5 bytes modified and continue.
Ok, but that will alter only my proccesse's functionality. Do I have to use writeprocessmemory() to do that in client? or should I do something different?
EDIT2: I compliled this dll, but I have a little problem here. I created an application that loads this dll. When it is loaded the HookSend() is called, but the HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll"); fails for some reason . what could it be?
|
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
|