| View previous topic :: View next topic |
| Author |
Message |
mamaorha Newbie cheater
Reputation: 0
Joined: 10 Mar 2012 Posts: 14
|
Posted: Fri Mar 16, 2012 3:59 am Post subject: C# finding what is game.exe + is |
|
|
| how can i find in C# what is game.exe + 00994504?
|
|
| Back to top |
|
 |
Pingo Grandmaster Cheater
Reputation: 8
Joined: 12 Jul 2007 Posts: 571
|
Posted: Fri Mar 16, 2012 4:38 am Post subject: |
|
|
ProcessModuleCollection if you need to loop through all the modules.
But from the looks of it, you only need the base for the main module.
So once you have the process, it'l be MainModule.BaseAddress
MainModule.BaseAddress + 994504 = address
_________________
|
|
| Back to top |
|
 |
mamaorha Newbie cheater
Reputation: 0
Joined: 10 Mar 2012 Posts: 14
|
Posted: Fri Mar 16, 2012 5:14 am Post subject: |
|
|
like this?
| Code: |
Process[] test = Process.GetProcessesByName("League of Legends");
int Base = test[0].MainModule.BaseAddress.ToInt32();
int Pointer = Base + 00994504;
|
with this i cant find the right address [/code]
|
|
| Back to top |
|
 |
Pingo Grandmaster Cheater
Reputation: 8
Joined: 12 Jul 2007 Posts: 571
|
Posted: Fri Mar 16, 2012 7:03 am Post subject: |
|
|
I believe 00994504 should be HEX so change it to 0x994504
Like the code below
| Code: | Process[] test = Process.GetProcessesByName("League of Legends");
int Base = test[0].MainModule.BaseAddress.ToInt32();
int Pointer = Base + 0x994504; |
Did you check your PM, i have a small piece of code you can use.
I cant post it here though.
_________________
|
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
Posted: Fri Mar 16, 2012 12:45 pm Post subject: |
|
|
Using Firefox as a test:
| Code: |
Process proc = (from p in Process.GetProcesses()
where p.ProcessName.ToLower() == "firefox"
select p).FirstOrDefault();
if (proc == null)
return;
IntPtr lpBaseAddress = proc.MainModule.BaseAddress + 0x00994504;
|
_________________
- Retired. |
|
| Back to top |
|
 |
tprice88 How do I cheat?
Reputation: 0
Joined: 07 Dec 2011 Posts: 4
|
Posted: Fri Mar 23, 2012 2:49 pm Post subject: |
|
|
| main module usually ='s 400000
|
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
Posted: Fri Mar 23, 2012 6:26 pm Post subject: |
|
|
| tprice88 wrote: | | main module usually ='s 400000 |
Depends on the target as well as the system configurations. It's not guaranteed to load at 0x00400000.
_________________
- Retired. |
|
| Back to top |
|
 |
troxan How do I cheat?
Reputation: 0
Joined: 02 May 2012 Posts: 4
|
Posted: Wed May 02, 2012 2:23 am Post subject: |
|
|
Hi,
i got a problem i try to read
"EXE.exe"+00909E40 , offsett, offset, offset
but i get always a "0"
Sorry
Last edited by troxan on Wed May 02, 2012 7:37 am; edited 1 time in total |
|
| Back to top |
|
 |
Pingo Grandmaster Cheater
Reputation: 8
Joined: 12 Jul 2007 Posts: 571
|
Posted: Wed May 02, 2012 3:59 am Post subject: |
|
|
Start a new post troxan. Don't highjack this thread.
Your code will never work like that cause pointers dont work like that.
All you're doing is adding offsets to the same address.
Go read up on how multilevel pointers work and you should see what you're doing wrong.
_________________
|
|
| Back to top |
|
 |
|