| View previous topic :: View next topic |
| Author |
Message |
Xx XoTiC V1 xX Cheater
Reputation: 1
Joined: 03 Aug 2012 Posts: 41
|
Posted: Thu Dec 29, 2022 11:09 pm Post subject: Need Help with AOB Script |
|
|
How do you make it so you don't have to keep deactivating and reactivating the AOB script whenever the address changes in-game? Like being able to keep the address updated automatically and value frozen between address changes. If that's possible. I have to have certain values froze in order to get desired affect when game loads (character swapping, level changing etc.)
| Code: | [ENABLE]
aobscan(ammo,00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ?? ?? 00 00 ?? 00 00 00 ?? 00 00 00 ?? 00 00 ?? 00 00 ?? 00 00 ?? 00 ?? 00 00 00 00 FF FF FF FF 00 00 00 00 01 00 00 00 00 00 00 00 ?? 00 00 00 ?? 00 00 00 00 00 00 00 ?? 00 ?? ?? ?? 00 00 ?? ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 00 ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 ?? ?? 00 00 00 ?? 00 00 00 ?? 00 ?? ?? ?? 00 ?? ?? ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D 00 00 00 00 00 00 00 00 00 00 00 0E 00 00 00 00 00 00 00 FF FF ?? ?? 03 60 00 00 FF 00 FF 00 01 00 61 66 65 00 FF ?? 00 00 00 00 06 00 00 00 ?? 00 00 00 ?? 00 00 00)
registersymbol(_ammo)
label(_ammo)
ammo+58:
_ammo:
[DISABLE]
unregistersymbol(_ammo) |
It works wonders but I just want it to automatically get the new address without having to manually turn it off and on each time.
_________________
Learning as I go. |
|
| Back to top |
|
 |
ParkourPenguin I post too much
Reputation: 155
Joined: 06 Jul 2014 Posts: 4774
|
Posted: Fri Dec 30, 2022 12:20 am Post subject: |
|
|
Pointer and/or injection copy
aobscans for writable data have always been a poor choice IMO
_________________
I don't know where I'm going, but I'll figure it out when I get there. |
|
| Back to top |
|
 |
Xx XoTiC V1 xX Cheater
Reputation: 1
Joined: 03 Aug 2012 Posts: 41
|
Posted: Fri Dec 30, 2022 1:32 am Post subject: |
|
|
| ParkourPenguin wrote: | Pointer and/or injection copy
aobscans for writable data have always been a poor choice IMO |
I should've mentioned I'm doing this in an emulator but it doesn't use JIT or anything like that. I can find pointers in this emulator but some of the values have addresses that change per level or even during it.
I know for some emulators pointers are not reliable which is why I was looking for other methods, injection copy should work shouldn't it to grab my value to change anytime? Will I have to backtrace?
_________________
Learning as I go. |
|
| Back to top |
|
 |
ParkourPenguin I post too much
Reputation: 155
Joined: 06 Jul 2014 Posts: 4774
|
Posted: Fri Dec 30, 2022 2:29 am Post subject: |
|
|
What emulator are you using?
If it's interpreting code instead of using JIT compilation, you could debug the interpreter and find a pointer path pretty quickly. This would require you to be able to read assembly quite well. (borderline reverse engineering: e.g. identifying calling conventions)
You could try setting the max offset on the pointer scanner to something ridiculously big and lowering the max level to compensate for it. I don't know if this is feasible.
_________________
I don't know where I'm going, but I'll figure it out when I get there. |
|
| Back to top |
|
 |
Xx XoTiC V1 xX Cheater
Reputation: 1
Joined: 03 Aug 2012 Posts: 41
|
Posted: Fri Dec 30, 2022 4:25 am Post subject: |
|
|
| ParkourPenguin wrote: | What emulator are you using?
If it's interpreting code instead of using JIT compilation, you could debug the interpreter and find a pointer path pretty quickly. This would require you to be able to read assembly quite well. (borderline reverse engineering: e.g. identifying calling conventions)
You could try setting the max offset on the pointer scanner to something ridiculously big and lowering the max level to compensate for it. I don't know if this is feasible. |
Redream, it's a Sega Dreamcast emulator, pointer scanning the allocationbase does give me my pointer which is good it's just the offset changes cause the value is reallocated but it seems it's only for some things in game, I have been able to do this in some of the other emulators but there are some pointer scanning does nothing so I resort to alternatives.
I know it's possible with opcode modifying like nops and stuff but... Sometimes I just only need to change the value and keep it froze before and while the game is loading for some things. I watched a bit on injection copy and it's what I need but how would I make
work? This is what pops up when I shoot my weapon, if I add r15 and RAX together I do get my current address, just can't figure out my base or offset and I made sure there's nothing else accessing it. I'm sure I'll figure it out sooner or later if I can't right now and I do appreciate any info. Maybe one day I can be a pro at programming, I have a bit of knowledge on this I just didn't really get into it always thought it was hard but I realize it's worth it.
Also as far as I know it doesn't use JIT. I would figure for JIT you would have to do AOB or something in that manner. I could be wrong though.
| Description: |
|
| Filesize: |
46.67 KB |
| Viewed: |
2127 Time(s) |

|
_________________
Learning as I go. |
|
| Back to top |
|
 |
ParkourPenguin I post too much
Reputation: 155
Joined: 06 Jul 2014 Posts: 4774
|
Posted: Fri Dec 30, 2022 12:55 pm Post subject: |
|
|
r15, 0xD6E0000, is surely the base of the emulated architecture's memory, and rax is probably the emulated address being written to.
Right click the instruction `mov [rax+r15],ebp` in the disassembler and select "Find out what addresses this instruction accesses". After playing the game for a bit, if the only address that comes up is the address you want, then simply follow an injection copy tutorial to get the address. If many addresses come up, consider doing something else, or see step 9 of the CE tutorial if you insist on code injection.
I'd do a pointer scan for the address 0D6E0000 (or whatever the new base is the next time you launch the game). Regular settings this time- reasonable max offset and max level. Modify the last offset of the result as you need. e.g. in this case change the last offset to rax: C6A4478.
If you enter a new level and the emulated address changes (i.e. rax), then you'll need to figure out what's going on in the emulated architecture. Maybe there's an index that stores what level you're on and the game stores different copies of values for each level using that index.
_________________
I don't know where I'm going, but I'll figure it out when I get there. |
|
| Back to top |
|
 |
Xx XoTiC V1 xX Cheater
Reputation: 1
Joined: 03 Aug 2012 Posts: 41
|
Posted: Fri Dec 30, 2022 2:02 pm Post subject: |
|
|
| ParkourPenguin wrote: | r15, 0xD6E0000, is surely the base of the emulated architecture's memory, and rax is probably the emulated address being written to.
Right click the instruction `mov [rax+r15],ebp` in the disassembler and select "Find out what addresses this instruction accesses". After playing the game for a bit, if the only address that comes up is the address you want, then simply follow an injection copy tutorial to get the address. If many addresses come up, consider doing something else, or see step 9 of the CE tutorial if you insist on code injection.
I'd do a pointer scan for the address 0D6E0000 (or whatever the new base is the next time you launch the game). Regular settings this time- reasonable max offset and max level. Modify the last offset of the result as you need. e.g. in this case change the last offset to rax: C6A4478.
If you enter a new level and the emulated address changes (i.e. rax), then you'll need to figure out what's going on in the emulated architecture. Maybe there's an index that stores what level you're on and the game stores different copies of values for each level using that index. |
Thank you I will try this, and yes for some addresses the memory will reallocate on a new level, I've actually ran into ones that change in-game like during a battle but some addresses don't use DMA I've found too. Also this specific emulator, has several valid memory regions. I can find a valid address in 19xxxxxx 1A 1B and 1C all at once these bases always remain the same just xxxxxx changes. I find pointers to them and they will work for non DMA but for DMA the offset changes.
So if all else I have code injection I can do, I should still be able to get my value to modify if I'm right? And I did see something about like emurpm but have no idea how to use, I was trying to understand what Dark Byte was saying when others asked but I'm not that good yet. I know with that you can simply change the base but I don't know if AllocationBase is what you use for it and if so if the size you use is the same as the AllocationBase. I don't know if you've used it or not but it sounds useful too.
_________________
Learning as I go. |
|
| Back to top |
|
 |
Xx XoTiC V1 xX Cheater
Reputation: 1
Joined: 03 Aug 2012 Posts: 41
|
Posted: Sat Dec 31, 2022 12:46 am Post subject: |
|
|
I figured out how to do it with AOB injection Copy! At least till the emulator closes, then 0DA8000 changes. But I just simply made RAX (0C6A3F58) my base since it always updates per level and cheat engine updates that for me when I use it as a base, and r15 which is DA8000 as the offset. what could I put to solve the DA8000 situation?
Here is my code:
| Code: | [ENABLE]
aobscanmodule(INJECT,redream.exe,08 89 D8 25 FF FF FF 1F 41 89 2C 07 41 C7 06 01 00 00 00) // should be unique
alloc(newmem,$1000,INJECT)
label(code)
label(return)
globalalloc(base,8)
newmem:
code:
mov [base],rax
mov [r15+rax],ebp
mov [r14],00000001
jmp return
INJECT+08:
jmp newmem
nop 6
return:
registersymbol(INJECT)
[DISABLE]
INJECT+08:
db 41 89 2C 07 41 C7 06 01 00 00 00
unregistersymbol(INJECT)
dealloc(newmem) |
So far for every level it has been working fantastic. I do notice that in order for it to activate the function has to be executed ingame, like me firing. Maybe I can use a function that's constantly being watched. I also have been told that injection copies are like pointers but I don't know. Anyways thank you for the help.
_________________
Learning as I go. |
|
| Back to top |
|
 |
ParkourPenguin I post too much
Reputation: 155
Joined: 06 Jul 2014 Posts: 4774
|
Posted: Sat Dec 31, 2022 4:06 am Post subject: |
|
|
Does that instruction really not access any other addresses? Are you sure it's not JIT compiling code?
| Code: | push rcx
lea rcx,[r15+rax] // rcx = r15 + rax
mov [base],rcx
pop rcx
... |
_________________
I don't know where I'm going, but I'll figure it out when I get there. |
|
| Back to top |
|
 |
|