Learn how to hook

Posts 1–15 of 28 · Page 1 of 2
Learn how to hook
Hello every one,

This is a littel tutorial how to hook:

1: First make a test application. Make a loop:



2: Load it up in olly and find a place to hook:

Code:
01161030  |>  8B4424 04     /MOV EAX,DWORD PTR SS:[ESP+4]
01161034  |.  8B0D 64201601 |MOV ECX,DWORD PTR DS:[<&MSVCP100.?cout@
0116103A  |.  40            |INC EAX
0116103B  |.  68 18211601   |PUSH OFFSET 01162118                    ; /_Val = " Feel free to hook in this part of code This is a very yes a very easy part to hook.
"
01161040  |.  50            |PUSH EAX                                ; |/Arg1
01161041  |.  68 70211601   |PUSH OFFSET 01162170                    ; ||/_Val = "We are at number: "
01161046  |.  51            |PUSH ECX                                ; |||_Ostr
01161047  |.  894424 14     |MOV DWORD PTR SS:[ESP+14],EAX           ; |||
0116104B  |.  E8 E0000000   |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
01161050  |.  83C4 08       |ADD ESP,8                               ; ||
01161053  |.  8BC8          |MOV ECX,EAX                             ; ||
01161055  |.  FF15 5C201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@J@Z
0116105B  |.  50            |PUSH EAX                                ; |_Ostr
0116105C  |.  E8 CF000000   |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
01161061  |.  A1 64201601   |MOV EAX,DWORD PTR DS:[<&MSVCP100.?cout@
01161066  |.  83C4 08       |ADD ESP,8
01161069  |.  68 84211601   |PUSH OFFSET 01162184                    ; /_Val = " gl!!

"
0116106E  |.  8D5424 08     |LEA EDX,[ESP+8]                         ; |
01161072  |.  52            |PUSH EDX                                ; |/Arg1
01161073  |.  68 8C211601   |PUSH OFFSET 0116218C                    ; ||/_Val = "THe address of counter is: "
01161078  |.  50            |PUSH EAX                                ; |||_Ostr
01161079  |.  E8 B2000000   |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
0116107E  |.  83C4 08       |ADD ESP,8                               ; ||
01161081  |.  8BC8          |MOV ECX,EAX                             ; ||
01161083  |.  FF15 58201601 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z
01161089  |.  50            |PUSH EAX                                ; |_Ostr
0116108A  |.  E8 A1000000   |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
0116108F  |.  83C4 08       |ADD ESP,8
01161092  |.  68 E8030000   |PUSH 3E8
01161097  |.  FFD6          |CALL ESI
01161099  \.- EB 95         \JMP SHORT 01161030
You will think, why how do I know a nice place to hook? And what do I need for that?

Nice place
You need to over ride a part of code. I chose a part with out any jumps or calls. Why? Becouse that is easy.

What do I need
You need 5 bytes. Becouse you are going to over ride 5 bytes with code. Why? A jump to a custom function needs 5 bytes

What are "5 bytes"
The 2nd "command" are the bytes:
0116108F |. 83C4 08 |ADD ESP,8
01161092 |. 68 E8030000 |PUSH 3E8
01161097 |. FFD6 |CALL ESI

83C4 08 = 3 bytes
68 E8030000 = 5 bytes
FFD6 = 2 bytes

Why do you took more?
You need a place to jump back. You need to resume the code.

Can I take a part of a command?
no!

What do I need to do if I have left?
Nop it.

Oke, now we have a nice place. We are going to place a jump here.
Searth the bytes and over ride them with a jump to your location: (I pref a dll)

Code:
01181069  |.  68 84211801   |PUSH OFFSET 01182184                    ; /_Val = " gl!!

"
0118106E  |.  8D5424 08     |LEA EDX,[ESP+8]                         ; |
01181072  |.  52            |PUSH EDX                                ; |/Arg1
01181073  |.  68 8C211801   |PUSH OFFSET 0118218C                    ; ||/_Val = "THe address of counter is: "
01181078  |.  50            |PUSH EAX                                ; |||_Ostr
01181079  |.  E8 B2000000   |CALL std::operator<<<std::char_traits<c ; ||\std::operator<<<std::char_traits<char> >
0118107E  |.  83C4 08       |ADD ESP,8                               ; ||
01181081  |.  8BC8          |MOV ECX,EAX                             ; ||
01181083  |.  FF15 58201801 |CALL DWORD PTR DS:[<&MSVCP100.??6?$basi ; |\MSVCP100.??6?$basic_ostream@DU?$char_traits@D@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@@<a href="http://www.mpgh.net/forum/member.php?u=567241" target="_blank">STD</a>@@QAEAAV01@PBX@Z
01181089  |.  50            |PUSH EAX                                ; |_Ostr
0118108A  |.  E8 A1000000   |CALL std::operator<<<std::char_traits<c ; \std::operator<<<std::char_traits<char> >
0118108F  |.  E9 6CFFDF61   |JMP hookfunction
01181094  |?  90            |NOP
01181095  |?  90            |NOP
01181096  |?  90            |NOP
01181097  |.  FFD6          |CALL ESI
01181099  \.- EB 95         \JMP SHORT 01181030
0118109B      CC            INT3
Now we have a jump to our location. But w8? We deleted some bytes...

What to do if you made a jump
Restore the old bytes. use inline assambly for that.

Can I do hacks now?
Yes, afther the restore do some hacks

Do I need to do more?
Yes, Return back under your jump

Code:
Dump - Crossfire:.text
Address   Hex dump          Command                                  Comments
0118108F  |.  E9 6CFFDF61   |JMP hookfunction
01181094  |?  90            |NOP
01181095  |?  90            |NOP
01181096  |?  90            |NOP
01181097  |.  FFD6          |CALL ESI
The result:

The loop in my test app:

Code:
0118108F  |.  E9 6CFFDF61   |JMP hookfunction
01181094  |?  90            |NOP
01181095  |?  90            |NOP
01181096  |?  90            |NOP
01181097  |.  FFD6          |CALL ESI
01181099  \.- EB 95         \JMP SHORT 01181030
The function I called:

Code:
62F81009  |.  68 F4010000   PUSH 1F4                                 ; /Duration = 500.
62F8100E  |.  68 F4010000   PUSH 1F4                                 ; |Frequency = 500.
62F81013  |.  FF15 0020F862 CALL DWORD PTR DS:[<&KERNEL32.Beep>]     ; \KERNEL32.Beep

More, and more, and more

62F8101A  \.  FF25 4433F862 JMP DWORD PTR DS:[jumplocation]
A video:


If you know the C++ basics, and know somting about memory edeting.. Then you can use this tutorial to make a hook. Good luck all

By Brimir

Edit:
Thanks @258456 for correcting a part.

You don't need the "83C4 08" any more. You just can hook the 5 bytes bellow.
Thanks for sharing Brimir! Your a great help to this section and to the game! I sometimes think you are FALLEN on a different account lol
Quote Originally Posted by Brimir View Post
What do I need
You need 6 bytes. Becouse you are going to over ride 6 bytes with code. Why? A jump to a custom function needs 6 bytes
it's actually 5 bytes, cuz 0xE9 (1 byte) and then 4 bytes for the operand (dword) = 5-bytes. Other than that good job
Quote Originally Posted by 258456 View Post
it's actually 5 bytes, cuz 0xE9 (1 byte) and then 4 bytes for the operand (dword) = 5-bytes. Other than that good job
You are ride,
In the example I did 5 bytes, but I told that it need to be 6 bytes.

Code:
 E9 6CFFDF61   |JMP hookfunction //5 bytes
Thanks!
Quote Originally Posted by Brimir View Post
You are ride,
In the example I did 5 bytes, but I told that it need to be 6 bytes.

Code:
 E9 6CFFDF61   |JMP hookfunction //5 bytes
Thanks!
No problem man, good job on the tut.
Great Job! + Rep, Thanked.
Good job
nvrmnd....
nice work @Brimir although xtrap detectes this one...
Quote Originally Posted by giniyat101 View Post
nice work @Brimir although xtrap detectes this one...
Well, it depends on where you hook and on what byte you hook. That's what i read some where. I read that xtrap checks only the first few bytes of a function or something like that.
When I make an hotkey hack, I hook into where crossfire checks for Debuggers
Quote Originally Posted by giniyat101 View Post
nice work @Brimir although xtrap detectes this one...
A anti cheat doesn't cheak a full game

But what part is detected? The methode how to jump or the way I hook?
omg, awesome!
good job dude
working hooks?
Posts 1–15 of 28 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?