Results 1 to 8 of 8
  1. #1
    arun823's Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Los Angeles, California
    Posts
    523
    Reputation
    151
    Thanks
    1,899
    My Mood
    Amused

    Cshell Dumped 9/19/12

    Bleh, took me 30 seconds to dump this, Have fun!

    Virus Scan 1

    Virus Scan 2

    /Approve attachment? @.REZ @Kid Cudi
    <b>Downloadable Files</b> Downloadable Files

  2. The Following 6 Users Say Thank You to arun823 For This Useful Post:

    ChaosMagician (11-16-2012),DragonHacker123 (10-07-2012),[MPGH]Flengo (09-19-2012),gtaiv2 (10-06-2012),LePROTECTEUR101 (09-26-2012),Otaviomorais (11-04-2012)

  3. #2
    Flengo's Avatar
    Join Date
    May 2010
    Gender
    male
    Location
    /admincp/banning.php
    Posts
    20,591
    Reputation
    5180
    Thanks
    14,177
    My Mood
    Inspired
    I might look into this just for fun

    Wonder what I can find.
    I Read All Of My PM's & VM's
    If you need help with anything, just let me know.

     


     
    VM | PM | IM
    Staff Administrator Since 10.13.2019
    Publicist Since 04.04.2015
    Middleman Since 04.14.2014
    Global Moderator Since 08.01.2013
    Premium Since 05.29.2013

    Minion+ Since 04.18.2013

    Combat Arms Minion Since 12.26.2012
    Contributor Since 11.16.2012
    Member Since 05.11.2010


  4. #3
    .REZ's Avatar
    Join Date
    Jun 2011
    Gender
    male
    Location
    Real life
    Posts
    10,385
    Reputation
    1110
    Thanks
    2,218
    My Mood
    Psychedelic
    Good work
    /approved

  5. #4
    Avery17's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    28
    Reputation
    21
    Thanks
    10
    Can someone tell me how to open this properly? It seems like I'm the only one who isn't getting it....

    Code:
    ADR_NameTags1			0x37255A7F
    CShellOffset                        0x37100000
    Offset Address                     0x00155A7F
    
    
    Address   Hex dump          Command                                  Comments
    00155A7B    BB 01000000     MOV EBX,1
    00155A80    A1 70858037     MOV EAX,DWORD PTR DS:[37808570]
    00155A85    8D5424 1C       LEA EDX,[ESP+1C]
    00155A89    C74424 1C 00000 MOV DWORD PTR SS:[ESP+1C],0
    00155A91    8B88 84000000   MOV ECX,DWORD PTR DS:[EAX+84]
    00155A97    52              PUSH EDX
    It's just not coming up right for me...

  6. #5
    arun823's Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Los Angeles, California
    Posts
    523
    Reputation
    151
    Thanks
    1,899
    My Mood
    Amused
    Quote Originally Posted by Avery17 View Post
    Can someone tell me how to open this properly? It seems like I'm the only one who isn't getting it....

    Code:
    ADR_NameTags1			0x37255A7F
    CShellOffset                        0x37100000
    Offset Address                     0x00155A7F
    
    
    Address   Hex dump          Command                                  Comments
    00155A7B    BB 01000000     MOV EBX,1
    00155A80    A1 70858037     MOV EAX,DWORD PTR DS:[37808570]
    00155A85    8D5424 1C       LEA EDX,[ESP+1C]
    00155A89    C74424 1C 00000 MOV DWORD PTR SS:[ESP+1C],0
    00155A91    8B88 84000000   MOV ECX,DWORD PTR DS:[EAX+84]
    00155A97    52              PUSH EDX
    It's just not coming up right for me...
    You need a disassembler, preferably IDA. Look up on google or youtube how to use IDA or learn the basics.
    Last edited by arun823; 09-19-2012 at 10:53 PM.

  7. #6
    Avery17's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    28
    Reputation
    21
    Thanks
    10
    Quote Originally Posted by arun823 View Post
    You need a disassembler, preferably IDA. Look up on google or youtube how to use IDA or learn the basics.
    I've tried IDA but I still have the same issues... I'm not sure what I should set all the settings to for this either.

  8. #7
    arun823's Avatar
    Join Date
    Jun 2010
    Gender
    male
    Location
    Los Angeles, California
    Posts
    523
    Reputation
    151
    Thanks
    1,899
    My Mood
    Amused
    Quote Originally Posted by Avery17 View Post
    I've tried IDA but I still have the same issues... I'm not sure what I should set all the settings to for this either.
    I don't even understand what your issue is, Enlighten me?

  9. #8
    Avery17's Avatar
    Join Date
    Aug 2012
    Gender
    male
    Posts
    28
    Reputation
    21
    Thanks
    10
    Refer to previous post explaining the issue...

    I go to an address, expecting certain Assembly code and it's obviously the wrong assembly code. Meaning the file is offset incorrectly, however when I reset the file to have the correct offset it only lines up certain addresses correctly and other addresses are still misaligned.

Similar Threads

  1. [Help] Windows 7 x64 CShell Dumping
    By khaozizleet in forum C++/C Programming
    Replies: 2
    Last Post: 08-14-2011, 05:12 PM
  2. [Help] Working CShell Dump technique
    By wtfhaksftw in forum CrossFire Hack Coding / Programming / Source Code
    Replies: 6
    Last Post: 02-28-2011, 04:23 PM
  3. [Request] cshell dumped pls
    By whit in forum Combat Arms EU Hack Coding/Source Code
    Replies: 3
    Last Post: 01-09-2011, 08:48 AM
  4. CShell Dump>
    By ipwnuuaal5 in forum Combat Arms EU Hack Coding/Source Code
    Replies: 2
    Last Post: 09-03-2010, 08:50 PM
  5. 11.08.2010 [CShell dumped + Strings]
    By doofbla in forum Combat Arms EU Hack Coding/Source Code
    Replies: 16
    Last Post: 08-18-2010, 01:50 AM