Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Can some1 tells me what's wrong with that code? (C++)
Goto page Previous  1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming
View previous topic :: View next topic  
Author Message
oib111
I post too much
Reputation: 0

Joined: 02 Apr 2007
Posts: 2947
Location: you wanna know why?

PostPosted: Sat Jun 07, 2008 11:41 am    Post subject: Reply with quote

Btw, jus while we are on the subject. What does this code do (I haven't learned asm Razz)

Code:

mov edi,edi
push ebp
mov ebp,esp
jmp dword ptr ds:[pmDLLFunc]


I understand the mov, push, and jump command. But I don't understand what each of them are doing, like they're effect, and what the overall code does.

_________________


8D wrote:

cigs dont make people high, which weed does, which causes them to do bad stuff. like killing
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Stylo
Grandmaster Cheater Supreme
Reputation: 3

Joined: 16 May 2007
Posts: 1073
Location: Israel

PostPosted: Sat Jun 07, 2008 11:43 am    Post subject: Reply with quote

oib111 wrote:
Btw, jus while we are on the subject. What does this code do (I haven't learned asm Razz)

Code:

mov edi,edi
push ebp
mov ebp,esp
jmp dword ptr ds:[pmDLLFunc]


I understand the mov, push, and jump command. But I don't understand what each of them are doing, like they're effect, and what the overall code does.

joining the question . . i'm using it alot and doesn't know what it means
how do you know the value that store in edi, ebp and stuff? and what does it do that you're pushing it and moving it from each other

_________________
Stylo
Back to top
View user's profile Send private message
oib111
I post too much
Reputation: 0

Joined: 02 Apr 2007
Posts: 2947
Location: you wanna know why?

PostPosted: Sat Jun 07, 2008 11:54 am    Post subject: Reply with quote

I have an idea just by viewing it. Does it hook hop (lol, now I understand that term) GG's PostMessage hook? Because he declares his own function, PostMessageX, to jump to PostMessageW. So GG sees PostMessageX being called instead of PostMessageW.
_________________


8D wrote:

cigs dont make people high, which weed does, which causes them to do bad stuff. like killing


Last edited by oib111 on Sat Jun 07, 2008 11:55 am; edited 1 time in total
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Ferocious
Advanced Cheater
Reputation: 0

Joined: 06 Feb 2008
Posts: 54

PostPosted: Sat Jun 07, 2008 11:55 am    Post subject: Reply with quote

those are the initial 5 bytes of the function, those are needed to be copied so that the function wont fail.
_________________
I wanna hack, but I don't know how...
Back to top
View user's profile Send private message
oib111
I post too much
Reputation: 0

Joined: 02 Apr 2007
Posts: 2947
Location: you wanna know why?

PostPosted: Sat Jun 07, 2008 11:56 am    Post subject: Reply with quote

Elaborate...? What do you mean "needed to be copied so that the function wont fail?"
_________________


8D wrote:

cigs dont make people high, which weed does, which causes them to do bad stuff. like killing
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Ferocious
Advanced Cheater
Reputation: 0

Joined: 06 Feb 2008
Posts: 54

PostPosted: Sat Jun 07, 2008 11:58 am    Post subject: Reply with quote

i've written about this in my trampoline documentation.

check it out, it'll make things clearer.

_________________
I wanna hack, but I don't know how...
Back to top
View user's profile Send private message
Stylo
Grandmaster Cheater Supreme
Reputation: 3

Joined: 16 May 2007
Posts: 1073
Location: Israel

PostPosted: Sat Jun 07, 2008 11:59 am    Post subject: Reply with quote

Ferocious wrote:
those are the initial 5 bytes of the function, those are needed to be copied so that the function wont fail.

let me see if i got you straight
push ebp - means copy the bytes to the stack so the function wont fail?
mov edi,edi - no clue what's this for . .
mov ebp,esp - moving stack pointer bla bla..
and jmp dword ptr ds:[DLLFunc] - jumping to the function's address?

edit: where can i find your trampoline documentation

_________________
Stylo


Last edited by Stylo on Sat Jun 07, 2008 12:05 pm; edited 2 times in total
Back to top
View user's profile Send private message
oib111
I post too much
Reputation: 0

Joined: 02 Apr 2007
Posts: 2947
Location: you wanna know why?

PostPosted: Sat Jun 07, 2008 12:02 pm    Post subject: Reply with quote

Ferocious wrote:
i've written about this in my trampoline documentation.

check it out, it'll make things clearer.


Understand now.

_________________


8D wrote:

cigs dont make people high, which weed does, which causes them to do bad stuff. like killing


Last edited by oib111 on Sat Jun 07, 2008 12:07 pm; edited 1 time in total
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Ferocious
Advanced Cheater
Reputation: 0

Joined: 06 Feb 2008
Posts: 54

PostPosted: Sat Jun 07, 2008 12:05 pm    Post subject: Reply with quote

Code:
mov edi,edi
push ebp
mov ebp,esp


these are the initial 5 bytes of almost every API.

so since we overwrite the intial 5 bytes to JUMP to our function, we missed out those bytes causing the existing function not to work.

so we just copy them and make sure they are there.

EDIT: oh sorry, i forgotten that we are working against GameGuard.

here's the deal, Gameguard hooked the initial 5 bytes, to jump into its module for some logging.

so, HookHop or PMX, basically write those 5 opcodes, and jumps to the following opcodes, skipping GameGuard's hook.

Example:

Code:
7E46630A JMP nppgt.xxxxxxxx
7E46630F CMP DWORD PTR DS:[7E4704BC], 0


so applying HookHop or PMX,

Skips the JMP to GameGuard module, and cotinues the operation.

hence, rewrite the initial 5 bytes, then jump to Function+5.



I'm really bad at explaining :S

_________________
I wanna hack, but I don't know how...


Last edited by Ferocious on Sat Jun 07, 2008 12:11 pm; edited 1 time in total
Back to top
View user's profile Send private message
Stylo
Grandmaster Cheater Supreme
Reputation: 3

Joined: 16 May 2007
Posts: 1073
Location: Israel

PostPosted: Sat Jun 07, 2008 12:09 pm    Post subject: Reply with quote

thanks i think i got it now =]
_________________
Stylo
Back to top
View user's profile Send private message
oib111
I post too much
Reputation: 0

Joined: 02 Apr 2007
Posts: 2947
Location: you wanna know why?

PostPosted: Sat Jun 07, 2008 12:10 pm    Post subject: Reply with quote

So you're saying, gameguard hooks the API so then what the asm is doing is replacing the initial five bytes so it doesn't get hooked?
_________________


8D wrote:

cigs dont make people high, which weed does, which causes them to do bad stuff. like killing
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Ferocious
Advanced Cheater
Reputation: 0

Joined: 06 Feb 2008
Posts: 54

PostPosted: Sat Jun 07, 2008 12:12 pm    Post subject: Reply with quote

ive edited my post, check it out.
_________________
I wanna hack, but I don't know how...
Back to top
View user's profile Send private message
Symbol
I'm a spammer
Reputation: 0

Joined: 18 Apr 2007
Posts: 5094
Location: Israel.

PostPosted: Sat Jun 07, 2008 12:37 pm    Post subject: Reply with quote

oib111 wrote:
So you're saying, gameguard hooks the API so then what the asm is doing is replacing the initial five bytes so it doesn't get hooked?

It is hooked, you just jump over the hook (PostMessageA/W) by calling PostMessageA/W + 5.

The parameters (HWND, UINT, WPARAM, LPARAM) are already pushed when you call the function, also the return address (address called to PostMessageX + 5) so all you have to do is jumping to PostMessageA/W + 5, then it works normally.
Back to top
View user's profile Send private message
Stylo
Grandmaster Cheater Supreme
Reputation: 3

Joined: 16 May 2007
Posts: 1073
Location: Israel

PostPosted: Sat Jun 07, 2008 12:58 pm    Post subject: Reply with quote

another question about hotkeys if you dont mind
i used RegisterHotKey to use f2,f3 and f4 to turn on/off some of bot's functions
Code:

case WM_CREATE:
      RegisterHotKey(hWnd,100,NULL,0x71);
      RegisterHotKey(hWnd,100,NULL,0x72);
      RegisterHotKey(hWnd,100,NULL,0x73);
//
//
case WM_HOTKEY:
      if (0x71)
         //etc
      if (0x72)
         //etc
      if (0xx73)
         //etc

for some reason all of them besides the last one that i registered aren't responsing
i tried using GetAsyncKeyState but it's not working for me unless the window is focused

_________________
Stylo
Back to top
View user's profile Send private message
atom0s
Moderator
Reputation: 205

Joined: 25 Jan 2006
Posts: 8588
Location: 127.0.0.1

PostPosted: Sat Jun 07, 2008 1:02 pm    Post subject: Reply with quote

Code:
if (0xx73)


Too many x's?

_________________
- Retired.
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General programming All times are GMT - 6 Hours
Goto page Previous  1, 2, 3, 4, 5  Next
Page 3 of 5

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites