What am I doing wrong here..?

Posts 1–9 of 9 · Page 1 of 1
What am I doing wrong here..?
Code:
/****/
void PushToConsole(char* text)
{
	DWORD base_addr = 0x005450D1;
	DWORD addr = base_addr + 0x00430590;
	__asm{
		push text
		call addr
		retn
	};
}

DWORD WINAPI DllMain( HINSTANCE hinstDLL,
	  DWORD dwReason,
	  LPVOID lpvReserved)
{
	if (dwReason == DLL_PROCESS_ATTACH)
	{
		//for (int i = 0; i < 10; i++)
			PushToConsole("Test");
	}
	return 0;
}
Alright so I wanted to print out a text in the console (call of duty 2) but once injected the DllMain entry point does not return anything which means that the "PushToConsole" is not working properly and that there's a bug somewhere. So in Olly I saw that a parameter is pushed and then a specific address is being called which I suppose is the address that will call the function. It is the same on each text printed in the console so yeah...
Am I missing something here ?

EDIT: Oh also in Olly the call is like:
Code:
CALL <ExeName>.00430590
and the entry point is the "base_addr", so am I calculating the final address wrong?
@OP I think the "retn" in your inline-asm is causing the problem -- the retn instruction pops an addr off the stack and jmps there (essentially). Your C++ function was about to 'return' anyway, so, the asm retn isn't needed/is actuallycausing the problem? Try removing it : D


Why are you typing in the base addr by hand instead of doing it programmatically? Are you sure this isn't the problem? It does change each time you load the game, right?
^^set a breakpoint on the game's function before you inject your dll ; see if
Code:
DWORD base_addr = 0x005450D1;
	DWORD addr = base_addr + 0x00430590;
	__asm{
		push text
		call addr
                ..
is actually getting to that function, or if you're 'calculating' the addr wrong. Please find base_addr programmatically, please.

edit: Also, you should post the beginning of the game-function you're calling -- so we can see how it's using the char* you passed it -- does it pop it like it's hot, etc. Another important question: how does the game's function 'return' back to your code -- if it uses 'retn', you need to 'push' your function's address (see my first sentence). If not, how is it getting back?
Quote Originally Posted by abuckau907 View Post
@OP I think the "retn" in your inline-asm is causing the problem -- the retn instruction pops an addr off the stack and jmps there (essentially). Your C++ function was about to 'return' anyway, so, the asm retn isn't needed/is actuallycausing the problem? Try removing it : D


Why are you typing in the base addr by hand instead of doing it programmatically? Are you sure this isn't the problem? It does change each time you load the game, right?
^^set a breakpoint on the game's function before you inject your dll ; see if
Code:
DWORD base_addr = 0x005450D1;
	DWORD addr = base_addr + 0x00430590;
	__asm{
		push text
		call addr
                ..
is actually getting to that function, or if you're 'calculating' the addr wrong. Please find base_addr programmatically, please.

edit: Also, you should post the beginning of the game-function you're calling -- so we can see how it's using the char* you passed it -- does it pop it like it's hot, etc. Another important question: how does the game's function 'return' back to your code -- if it uses 'retn', you need to 'push' your function's address (see my first sentence). If not, how is it getting back?
In the first try I did not add the "retn", but it still doesn't work. In each case the program pushes a specific address and then calls the other address.
Like:
Code:
push <ExeName>.Addy      ; "%s is read only."
call <exename>.addy2
the comment there is also in olly it's how I found the address, you prob assumed that but w/e lol
For your base address you can just do :

Code:
DWORD baseAddr = (DWORD)GetModuleHandle(NULL);
Then if your offset isn't wrong then all you can correct is the stack where you would do :

Code:
__asm{
		push text
		call addr
		add esp,4
	};
Quote Originally Posted by Knochove View Post
For your base address you can just do :

Code:
DWORD baseAddr = (DWORD)GetModuleHandle(NULL);
Then if your offset isn't wrong then all you can correct is the stack where you would do :

Code:
__asm{
		push text
		call addr
		add esp,4
	};
That is assuming it's a __cdecl

Lots of CoD games use "__usercalls" ( Blame IDA ). Aka non-standard stack handling.
Oh and OP is returning false from DllMain.
Posts 1–9 of 9 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us