| 
			
				|  | Cheat Engine The Official Site of Cheat Engine
 
 
 |  
 
	
		| View previous topic :: View next topic |  
		| Author | Message |  
		| thefreestyle Cheater
 
 ![]() Reputation: 0 
 Joined: 29 Oct 2015
 Posts: 35
 
 
 | 
			
				|  Posted: Wed Sep 19, 2018 12:00 pm    Post subject: Checking valid offset before reading its value |   |  
				| 
 |  
				| Hi guys, 
 My script sometimes crashes the game and from what i see its because im trying to get value from offset which actually not exist ( question marks ) or just number instead of address , since its shared function for damage all kind of stuff going trough, my goal is to check if this my player or not, and i check this by some offset from some register.
 Problem is that sometimes that offset is not valid player and has some random value instead address and any subsequent offsets reading crash the game,  for example :
 
 
  	  | Code: |  	  | mov ecx,[ebp+A8]  // 1st offset reading, at this point ebp always exist
 mov ecx,[ecx+000000EC]   //2nd offset, at this point +ec can have valid address or some random value, like 1
 mov ecx,[ecx+00000098]   // 3rd offset, if prev offset was address then all ok, but if it was a number then crash occur, my guess since im trying to read value from some address but its just a number
 
 | 
 
 So how could this be avoided ? how can i check that given offset is pointer and not just number or no value at all, like question marks (??) ?
 
 Any help would be appreciated
 |  |  
		| Back to top |  |  
		|  |  
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25806
 Location: The netherlands
 
 | 
			
				|  Posted: Wed Sep 19, 2018 12:43 pm    Post subject: |   |  
				| 
 |  
				| if the only invalid values are either 0 or 1 or below 10000 then you can you can of course check if ecx is bigger than 10000 and if so it's valid 
 or if you're on 6.8.1 use {$try}/{$except}
 
 e.g:
 
  	  | Code: |  	  | {$try}
 mov ecx,[ebp+A8]  // 1st offset reading, at this point ebp always exist
 mov ecx,[ecx+000000EC]   //2nd offset, at this point +ec can have valid address or some random value, like 1
 mov ecx,[ecx+00000098]   // 3rd offset, if prev offset was address then all ok, but if it was a number then crash occur, my guess since im trying to read value from some address but its just a number
 jmp stillalive
 {$except}
 //this code gets executed on an exception ( like invalid memory access or ce's VEH debug single step, etc...)
 jmp originalcode
 
 stillalive:
 //No exception happened and "jmp stillalive" was executed
 //do stuff you'd normally do
 
 | 
 _________________
 
 Do not ask me about online cheats. I don't know any and wont help finding them.
 Like my help? Join me on Patreon so i can keep helping
 |  |  
		| Back to top |  |  
		|  |  
		| thefreestyle Cheater
 
 ![]() Reputation: 0 
 Joined: 29 Oct 2015
 Posts: 35
 
 
 | 
			
				|  Posted: Wed Sep 19, 2018 1:27 pm    Post subject: |   |  
				| 
 |  
				| Hi Dark Byte 
 Thank you for your reply. Cant believe i did not see that simple and elegant solution.
 
 Actually i am on 6.8.1 and had no idea about try/catch.
 
 Gonna try both approaches.
 
 Btw, about the questions marks (no value), is checking against zero is enough ?
 
 So checking bigger then 10000 covers no values too ?
 |  |  
		| Back to top |  |  
		|  |  
		| Dark Byte Site Admin
 
  Reputation: 470 
 Joined: 09 May 2003
 Posts: 25806
 Location: The netherlands
 
 | 
			
				|  Posted: Wed Sep 19, 2018 1:50 pm    Post subject: |   |  
				| 
 |  
				| Windows allocates memory from address 0x10000 and up. So you can be sure that any value smaller than that is an invalid address 
 Also, you may want to have a way to restore ECX (in case it's important), so perhaps put a push ecx in front, and in the except and stillalive add a pop ecx
 _________________
 
 Do not ask me about online cheats. I don't know any and wont help finding them.
 Like my help? Join me on Patreon so i can keep helping
 |  |  
		| Back to top |  |  
		|  |  
		| thefreestyle Cheater
 
 ![]() Reputation: 0 
 Joined: 29 Oct 2015
 Posts: 35
 
 
 | 
			
				|  Posted: Wed Sep 19, 2018 2:00 pm    Post subject: |   |  
				| 
 |  
				|  	  | Quote: |  	  | Windows allocates memory from address 0x10000 and up. So you can be sure that any value smaller than that is an invalid address
 
 | 
 
 That i did not knew either, that explains why you said 10000 before, i thought it just random high number.
 
 Yes, i have pushed and poped ECX, its just portion of the script.
 
 Anyway thank you so much, you helped me a lot, now i go to work and hope i get rid of those crashes !!!
 |  |  
		| Back to top |  |  
		|  |  
		|  |  
  
	| 
 
 | You cannot post new topics in this forum You cannot reply to topics in this forum
 You cannot edit your posts in this forum
 You cannot delete your posts in this forum
 You cannot vote in polls in this forum
 You cannot attach files in this forum
 You can download files in this forum
 
 |  |