Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Help to understand the logic of bots.
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
mibiz
Cheater
Reputation: 0

Joined: 14 Jun 2009
Posts: 31

PostPosted: Mon Feb 15, 2010 9:46 pm    Post subject: Reply with quote

tombana wrote:
I have a bot for an mmorpg. What I do is basically have a thread that loops and does:

- check if it needs to use food
- check if it needs to get buffs
- attack every monster on the target list
- if the targetlist is empty (all monsters on the list died) then add new monsters
- repeat

I use packet editing. So I receive the packets from the server and parse them to get the monster info and so on. And to attack I send packets etc.


Bot via packets? NICE!!! I'm trying to create one in C# v2 but using low level hooks to keyboard/mouse to the app but having problems Sad

EDIT:

kot1990 wrote:
Anyone who has created a bot for mmorpg games? I want an explanation about how a bot works and what I have to learn to do it. I am not newbie. I understand C/C++ classes/pointers and all that stuff and a little winapi and how to write/read from memory. I don't ask for any hack/cheat for specific game.

What is really happening when I target something or attacking/using skill etc.? Is there a way to force the application do that?


I suggest you first get structure of the character profile/stats in the memory. Then base your bot on how you would play the character's class but then expand or simplify a bit to include for other classes also. As for send the input keyboard/mouse for the action, you could do packets as tombana is doing. Or use low level hooks to send keyboard/mouse, which is what I'm doing now. I got most of the logic for bot operations in place. Only thing left is get the low level hooks working. Then my bot can run multi-game/multi-client.
Back to top
View user's profile Send private message
kot1990
Expert Cheater
Reputation: 1

Joined: 06 Sep 2009
Posts: 131
Location: Greece

PostPosted: Wed Feb 17, 2010 8:33 am    Post subject: Reply with quote

I think I found how to hook send function from ws2_32.dll but I need a little help to understand, where what is copied and what's happening. I'm confused.

Code:
//http://somebastardstolemyname.wordpress.com
//The_Undead : Rhys M.

//winsock send hook

#include "windows.h"
#include "winsock.h"

#pragma comment ( lib, "Ws2_32.lib" )
#define JMP(frm, to) (int)(((int)to - (int)frm) - 5);

DWORD SendOriginalAddress = 0;
DWORD SendReturnAddress = 0;
DWORD* SendNewAddress = 0;
DWORD OldProtection = 0;

char* send_buffer;
int send_sizeofdata = 0;
SOCKET send_s;
int send_flags = 0;

void __declspec(naked) __stdcall  SendHookFunc()    
{
   __asm
   {
            mov  edi,edi
            push ebp
            mov ebp, esp
            mov eax, [ebp+0x08] /* Param 1 : Socket */
            mov send_s, eax
            mov eax, [ebp+0x0C] /* Param 2 : buffer */
            mov [send_buffer], eax
            mov eax, [ebp+0x10] /*Param 3 : Size*/
            mov send_sizeofdata, eax
            mov eax, [ebp+0x14] /*Param 4 : flags*/
            mov send_flags, eax
            jmp SendReturnAddress
   }
}

void UnHookSend()
{
   /* To unhook on a WinXP post SP2 box you need to restore the 5 byte preamble */
   *(WORD *)SendOriginalAddress = 0xFF8B;      // mov  edi,edi
   *(BYTE *)(SendOriginalAddress+2) = 0x55;   // push epb
   *(WORD *)(SendOriginalAddress+3) = 0xEC8B;   // mov epb, esp
   VirtualProtect( (void*)SendOriginalAddress, 0x05, OldProtection, &OldProtection );
}

void HookSend()
{
   SendNewAddress = (DWORD*)SendHookFunc;
   HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll");
   SendOriginalAddress = (DWORD)GetProcAddress(hDll, "send");
   SendReturnAddress = SendOriginalAddress + 5;
   VirtualProtect( (void*)SendOriginalAddress, 0x05, PAGE_READWRITE , &OldProtection );
   *(BYTE *)(SendOriginalAddress) = 0xe9;
   *(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress);
}

BOOL APIENTRY DllMain( HMODULE hModule,
                       DWORD  ul_reason_for_call,
                       LPVOID lpReserved
                )
{
   if (ul_reason_for_call == DLL_PROCESS_ATTACH)
      HookSend();
   if (ul_reason_for_call == DLL_THREAD_DETACH)
      UnHookSend();
    return TRUE;
}



It seems that the first 5 byte instructions are the first 5 bytes of the send() in the ws2_32 module.

Code:
void HookSend()
{
   SendNewAddress = (DWORD*)SendHookFunc; // <-- The address of my SendHookFunc().
   HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll"); // <-- Load the library into my process' address space and get a handle.
   SendOriginalAddress = (DWORD)GetProcAddress(hDll, "send"); // <-- Get the address of the module's function send().
   SendReturnAddress = SendOriginalAddress + 5; // <--Point to +5 bytes.
   VirtualProtect( (void*)SendOriginalAddress, 0x05, PAGE_READWRITE , &OldProtection );// <-- Change the protection of the 5 bytes to PAGE_READWRITE.
   *(BYTE *)(SendOriginalAddress) = 0xe9; // <-- what is this?
   *(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress); // <-- and this?
}


What are these double asterisks *(BYTE *) . The one in the end shows that is it a pointer to BYTE, and the first one?? dereference?

EDIT: Ok got it Very Happy
0xe9 is the code for a jmp instruction and then with *(int *)(SendOriginalAddress+1) = JMP(SendOriginalAddress, SendNewAddress); I will change the 4 bytes that is the address of the hook function, and then the last jmp in my hook function will return to the 5 bytes modified and continue.

Ok, but that will alter only my proccesse's functionality. Do I have to use writeprocessmemory() to do that in client? or should I do something different?

EDIT2: I compliled this dll, but I have a little problem here. I created an application that loads this dll. When it is loaded the HookSend() is called, but the HINSTANCE hDll = LoadLibrary((LPCTSTR) "Ws2_32.dll"); fails for some reason Sad . what could it be?
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites