Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Need Help with AOB Script

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine
View previous topic :: View next topic  
Author Message
Xx XoTiC V1 xX
Cheater
Reputation: 1

Joined: 03 Aug 2012
Posts: 41

PostPosted: Thu Dec 29, 2022 11:09 pm    Post subject: Need Help with AOB Script Reply with quote

How do you make it so you don't have to keep deactivating and reactivating the AOB script whenever the address changes in-game? Like being able to keep the address updated automatically and value frozen between address changes. If that's possible. I have to have certain values froze in order to get desired affect when game loads (character swapping, level changing etc.)

Code:
[ENABLE]
aobscan(ammo,00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ?? ?? 00 00 ?? 00 00 00 ?? 00 00 00 ?? 00 00 ?? 00 00 ?? 00 00 ?? 00 ?? 00 00 00 00 FF FF FF FF 00 00 00 00 01 00 00 00 00 00 00 00 ?? 00 00 00 ?? 00 00 00 00 00 00 00 ?? 00 ?? ?? ?? 00 00 ?? ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 00 ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 ?? ?? 00 00 00 ?? 00 00 00 ?? 00 ?? ?? ?? 00 ?? ?? ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 ?? 00 00 00 ?? 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0D 00 00 00 00 00 00 00 00 00 00 00 0E 00 00 00 00 00 00 00 FF FF ?? ?? 03 60 00 00 FF 00 FF 00 01 00 61 66 65 00 FF ?? 00 00 00 00 06 00 00 00 ?? 00 00 00 ?? 00 00 00)
registersymbol(_ammo)
label(_ammo)

ammo+58:
_ammo:




[DISABLE]
unregistersymbol(_ammo)


It works wonders but I just want it to automatically get the new address without having to manually turn it off and on each time.

_________________
Learning as I go.
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Fri Dec 30, 2022 12:20 am    Post subject: Reply with quote

Pointer and/or injection copy

aobscans for writable data have always been a poor choice IMO

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
Xx XoTiC V1 xX
Cheater
Reputation: 1

Joined: 03 Aug 2012
Posts: 41

PostPosted: Fri Dec 30, 2022 1:32 am    Post subject: Reply with quote

ParkourPenguin wrote:
Pointer and/or injection copy

aobscans for writable data have always been a poor choice IMO


I should've mentioned I'm doing this in an emulator but it doesn't use JIT or anything like that. I can find pointers in this emulator but some of the values have addresses that change per level or even during it.

I know for some emulators pointers are not reliable which is why I was looking for other methods, injection copy should work shouldn't it to grab my value to change anytime? Will I have to backtrace?

_________________
Learning as I go.
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Fri Dec 30, 2022 2:29 am    Post subject: Reply with quote

What emulator are you using?

If it's interpreting code instead of using JIT compilation, you could debug the interpreter and find a pointer path pretty quickly. This would require you to be able to read assembly quite well. (borderline reverse engineering: e.g. identifying calling conventions)

You could try setting the max offset on the pointer scanner to something ridiculously big and lowering the max level to compensate for it. I don't know if this is feasible.

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
Xx XoTiC V1 xX
Cheater
Reputation: 1

Joined: 03 Aug 2012
Posts: 41

PostPosted: Fri Dec 30, 2022 4:25 am    Post subject: Reply with quote

ParkourPenguin wrote:
What emulator are you using?

If it's interpreting code instead of using JIT compilation, you could debug the interpreter and find a pointer path pretty quickly. This would require you to be able to read assembly quite well. (borderline reverse engineering: e.g. identifying calling conventions)

You could try setting the max offset on the pointer scanner to something ridiculously big and lowering the max level to compensate for it. I don't know if this is feasible.


Redream, it's a Sega Dreamcast emulator, pointer scanning the allocationbase does give me my pointer which is good it's just the offset changes cause the value is reallocated but it seems it's only for some things in game, I have been able to do this in some of the other emulators but there are some pointer scanning does nothing so I resort to alternatives.

I know it's possible with opcode modifying like nops and stuff but... Sometimes I just only need to change the value and keep it froze before and while the game is loading for some things. I watched a bit on injection copy and it's what I need but how would I make


Code:
mov [r15+rax],ebp




work? This is what pops up when I shoot my weapon, if I add r15 and RAX together I do get my current address, just can't figure out my base or offset and I made sure there's nothing else accessing it. I'm sure I'll figure it out sooner or later if I can't right now and I do appreciate any info. Maybe one day I can be a pro at programming, I have a bit of knowledge on this I just didn't really get into it always thought it was hard but I realize it's worth it.

Also as far as I know it doesn't use JIT. I would figure for JIT you would have to do AOB or something in that manner. I could be wrong though.



CE.png
 Description:
 Filesize:  46.67 KB
 Viewed:  2127 Time(s)

CE.png



_________________
Learning as I go.
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Fri Dec 30, 2022 12:55 pm    Post subject: Reply with quote

r15, 0xD6E0000, is surely the base of the emulated architecture's memory, and rax is probably the emulated address being written to.

Right click the instruction `mov [rax+r15],ebp` in the disassembler and select "Find out what addresses this instruction accesses". After playing the game for a bit, if the only address that comes up is the address you want, then simply follow an injection copy tutorial to get the address. If many addresses come up, consider doing something else, or see step 9 of the CE tutorial if you insist on code injection.

I'd do a pointer scan for the address 0D6E0000 (or whatever the new base is the next time you launch the game). Regular settings this time- reasonable max offset and max level. Modify the last offset of the result as you need. e.g. in this case change the last offset to rax: C6A4478.

If you enter a new level and the emulated address changes (i.e. rax), then you'll need to figure out what's going on in the emulated architecture. Maybe there's an index that stores what level you're on and the game stores different copies of values for each level using that index.

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
Xx XoTiC V1 xX
Cheater
Reputation: 1

Joined: 03 Aug 2012
Posts: 41

PostPosted: Fri Dec 30, 2022 2:02 pm    Post subject: Reply with quote

ParkourPenguin wrote:
r15, 0xD6E0000, is surely the base of the emulated architecture's memory, and rax is probably the emulated address being written to.

Right click the instruction `mov [rax+r15],ebp` in the disassembler and select "Find out what addresses this instruction accesses". After playing the game for a bit, if the only address that comes up is the address you want, then simply follow an injection copy tutorial to get the address. If many addresses come up, consider doing something else, or see step 9 of the CE tutorial if you insist on code injection.

I'd do a pointer scan for the address 0D6E0000 (or whatever the new base is the next time you launch the game). Regular settings this time- reasonable max offset and max level. Modify the last offset of the result as you need. e.g. in this case change the last offset to rax: C6A4478.

If you enter a new level and the emulated address changes (i.e. rax), then you'll need to figure out what's going on in the emulated architecture. Maybe there's an index that stores what level you're on and the game stores different copies of values for each level using that index.


Thank you I will try this, and yes for some addresses the memory will reallocate on a new level, I've actually ran into ones that change in-game like during a battle but some addresses don't use DMA I've found too. Also this specific emulator, has several valid memory regions. I can find a valid address in 19xxxxxx 1A 1B and 1C all at once these bases always remain the same just xxxxxx changes. I find pointers to them and they will work for non DMA but for DMA the offset changes.

So if all else I have code injection I can do, I should still be able to get my value to modify if I'm right? And I did see something about like emurpm but have no idea how to use, I was trying to understand what Dark Byte was saying when others asked but I'm not that good yet. I know with that you can simply change the base but I don't know if AllocationBase is what you use for it and if so if the size you use is the same as the AllocationBase. I don't know if you've used it or not but it sounds useful too.

_________________
Learning as I go.
Back to top
View user's profile Send private message
Xx XoTiC V1 xX
Cheater
Reputation: 1

Joined: 03 Aug 2012
Posts: 41

PostPosted: Sat Dec 31, 2022 12:46 am    Post subject: Reply with quote

I figured out how to do it with AOB injection Copy! At least till the emulator closes, then 0DA8000 changes. But I just simply made RAX (0C6A3F58) my base since it always updates per level and cheat engine updates that for me when I use it as a base, and r15 which is DA8000 as the offset. what could I put to solve the DA8000 situation?

Here is my code:


Code:
[ENABLE]

aobscanmodule(INJECT,redream.exe,08 89 D8 25 FF FF FF 1F 41 89 2C 07 41 C7 06 01 00 00 00) // should be unique
alloc(newmem,$1000,INJECT)

label(code)
label(return)

globalalloc(base,8)

newmem:

code:
  mov [base],rax
  mov [r15+rax],ebp
  mov [r14],00000001
  jmp return

INJECT+08:
  jmp newmem
  nop 6
return:
registersymbol(INJECT)

[DISABLE]

INJECT+08:
  db 41 89 2C 07 41 C7 06 01 00 00 00

unregistersymbol(INJECT)
dealloc(newmem)


So far for every level it has been working fantastic. I do notice that in order for it to activate the function has to be executed ingame, like me firing. Maybe I can use a function that's constantly being watched. I also have been told that injection copies are like pointers but I don't know. Anyways thank you for the help.

_________________
Learning as I go.
Back to top
View user's profile Send private message
ParkourPenguin
I post too much
Reputation: 155

Joined: 06 Jul 2014
Posts: 4774

PostPosted: Sat Dec 31, 2022 4:06 am    Post subject: Reply with quote

Does that instruction really not access any other addresses? Are you sure it's not JIT compiling code?
Code:
push rcx
lea rcx,[r15+rax]  // rcx = r15 + rax
mov [base],rcx
pop rcx
...

_________________
I don't know where I'm going, but I'll figure it out when I get there.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Cheat Engine All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites