CS register

Posts 1–5 of 5 · Page 1 of 1
CS register
Assembly is dead and since C++ as inline assembler I'll ask this here...
Now the cs register points at the current executing code segment in the memory. Now my question is, is it possible (to somehow manage) to code a proxy and extract the exact function that we want from a program.
For instance:
Let's say a game has a special function which loads game assets, now coding a DLL that pretty much work as a proxy and waits for the game to finally load the assets (say [for example] the game starts loading them when bit X at Y location becomes 1) and then starts to dump all the information inside the code segment ?
Is that plausible?
Quote Originally Posted by user590177 View Post
The Game Starts Loading Them When Bit X At Y Location Becomes 1)
Just use an exception handler w/ VirtualProtect or some form of breakpoint at that location then dump the memory.

VEHs are especially useful for this.
Quote Originally Posted by Hitokiri~ View Post

Just use an exception handler w/ VirtualProtect or some form of breakpoint at that location then dump the memory.

VEHs are especially useful for this.
The idea was to do this automatically, say we don't have the address but we know when the game is going to call it.
Quote Originally Posted by user590177 View Post


The idea was to do this automatically, say we don't have the address but we know when the game is going to call it.
Same thing.
Quote Originally Posted by Hitokiri~ View Post

Same thing.
Great, so pretty much it is going to receive the instructions being processed ?
A way would be to simply start tracking the instruction pointer until we know the function has terminated?
Posts 1–5 of 5 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us