QuestionHow do I add multiple offsets to a pointer?

Posts 1–10 of 10 · Page 1 of 1
How do I add multiple offsets to a pointer?
So I'm wanting to add multiple offset to a pointer and I've tried what I currently have.

C++ Empty Project

Code:
const DWORD exeAddr = 0x7FF68BFC0000;
const DWORD BaseAddr = 0x011167C8;

const DWORD StatusOff1 = 0x210;
const DWORD StatusOff2 = 0xF8;
const DWORD StatusOff3 = 0x8;
const DWORD StatusOff4 = 0xE8;
const DWORD StatusOff5 = 0x18;
const DWORD StatusOff6 = 0x60;
const DWORD StatusOff7 = 0x53;

WriteProcessMemory(hProc, (BYTE*)((((((((exeAddr + BaseAddr) + StatusOff1) + StatusOff2) + StatusOff3) + StatusOff4) + StatusOff5) + StatusOff6) + StatusOff7), (LPVOID)&StatusValues, 1, 0);
This Thread, Post #7

Quote Originally Posted by Sammy View Post
Easiest way would be
Code:
ReadProcessMemory(phandle,(void*)(((clienbase + value) + offset1) + offset2), &value, sizeof (value), 0)
...
I think I now know what my problem is, I'm using the EXE's address and not the EXE. In CE it will say Process . exe + [address], but I put the Process as an individual address in CE and took that address.

Would I use
Code:
GetModuleHandle(NULL);
?
Quote Originally Posted by ActualCheats View Post
I think I now know what my problem is, I'm using the EXE's address and not the EXE. In CE it will say Process . exe + [address], but I put the Process as an individual address in CE and took that address.

Would I use
Code:
GetModuleHandle(NULL);
?
Yes generally the base address changes everytime. If you want to obtain the actual baseaddress you'll have to do something in the lines of this:

Code:
DWORD baseaddr = (DWORD)GetModuleHandle (NULL);
Unless you doing it external i presume. Not much experience with that.

Or in the new cast style:

Code:
DWORD baseaddr = reinterpret_cast<DWORD>(GetModuleHandle (NULL));
I don't think WriteProcessMemory requires you to provide the base address of the main module. Also those brackets are not needed when adding the offsets
Quote Originally Posted by Biesi View Post
I don't think WriteProcessMemory requires you to provide the base address of the main module. Also those brackets are not needed when adding the offsets
So would I just put 0x011167C8 + offset?
In CE it says Process.exe + 011167C8, then it's a multi level pointer (I know I'm doing that wrong in the example above)

Edit: It's external
Right so I got bored I tried some things.
Firstly I went into CE and put the process in a manual address and took the value after I converted it to HEX. I then put that into my c++ project and used a multilevel pointer solution I found.
Code:
        
        const DWORD Base = 0x905A4D;

        const DWORD BaseAddr = 0x011167C8;

	DWORD thebase = (DWORD)(*(DWORD*)Base + BaseAddr);
	DWORD thefirst = (DWORD)(*(DWORD*)thebase + 0x210);
	DWORD thesecond = (DWORD)(*(DWORD*)thefirst + 0xF8);
	DWORD thethird = (DWORD)(*(DWORD*)thesecond + 0x8);
	DWORD thefourth = (DWORD)(*(DWORD*)thethird + 0xE8);
	DWORD thefifth = (DWORD)(*(DWORD*)thefourth + 0x18);
	DWORD thesixth = (DWORD)(*(DWORD*)thefifth + 0x60);
	DWORD theresult = (DWORD)(*(DWORD*)thesixth + 0x54);

        WriteProcessMemory(hProc, (DWORD*)theresult, (LPVOID)&StatusValues, 4, 0);
When I run it it throws a permissions error.

From the debug : Exception thrown at 0x00007FF76BA47C02 in ExternalTest.exe: 0xC0000005: Access violation reading location 0x0000000000905A4D.

imgur. com/egWZTK1
Quote Originally Posted by ActualCheats View Post
Right so I got bored I tried some things.
Firstly I went into CE and put the process in a manual address and took the value after I converted it to HEX. I then put that into my c++ project and used a multilevel pointer solution I found.
Code:
        
        const DWORD Base = 0x905A4D;

        const DWORD BaseAddr = 0x011167C8;

	DWORD thebase = (DWORD)(*(DWORD*)Base + BaseAddr);
	DWORD thefirst = (DWORD)(*(DWORD*)thebase + 0x210);
	DWORD thesecond = (DWORD)(*(DWORD*)thefirst + 0xF8);
	DWORD thethird = (DWORD)(*(DWORD*)thesecond + 0x8);
	DWORD thefourth = (DWORD)(*(DWORD*)thethird + 0xE8);
	DWORD thefifth = (DWORD)(*(DWORD*)thefourth + 0x18);
	DWORD thesixth = (DWORD)(*(DWORD*)thefifth + 0x60);
	DWORD theresult = (DWORD)(*(DWORD*)thesixth + 0x54);

        WriteProcessMemory(hProc, (DWORD*)theresult, (LPVOID)&StatusValues, 4, 0);
When I run it it throws a permissions error.

From the debug : Exception thrown at 0x00007FF76BA47C02 in ExternalTest.exe: 0xC0000005: Access violation reading location 0x0000000000905A4D.

imgur. com/egWZTK1
you are completely mixing everything together now. Please, if you are working on this, watch some tutorials and such. I can't and won't explain you the full theory of how everything works. You are working on an external process. That attaches to another process. If you do that you have to use different methods for receving memory data and such. If you do internal, then yea this could work. But you gotta make a decision and stick to that. Go and read some tutorials.
it's external, so to read the pointer you will use ReadProcessMemory(), to write to the pointer you will use WriteProcessMemory().

...the whole code is not coherent and this part of code tells me you are trying to talk directly to the memory (like you are doing an internal hack).
Code:
DWORD thebase = (DWORD)(*(DWORD*)Base + BaseAddr);
	DWORD thefirst = (DWORD)(*(DWORD*)thebase + 0x210);
	DWORD thesecond = (DWORD)(*(DWORD*)thefirst + 0xF8);
	DWORD thethird = (DWORD)(*(DWORD*)thesecond + 0x8);
	DWORD thefourth = (DWORD)(*(DWORD*)thethird + 0xE8);
	DWORD thefifth = (DWORD)(*(DWORD*)thefourth + 0x18);
	DWORD thesixth = (DWORD)(*(DWORD*)thefifth + 0x60);
	DWORD theresult = (DWORD)(*(DWORD*)thesixth + 0x54);
As the above have said, if it is external, you are doing internal things. If it is internal, you are doing external things (WriteProcessMemory can be done internal but is... kind of stupid?).

Here is some crappy pseudocode of what you want to do:
Code:
ReadProcessMemory( handle, firstoffset , addresstoread , sizeofadword, numberofbytesread)
ReadProcessMemory( handle, addresstoread + secondoffset , addresstoread , sizeofadword, numberofbytesread)
ReadProcessMemory( handle, addresstoread + thirdoffset , addresstoread , sizeofadword, numberofbytesread)
ReadProcessMemory( handle, addresstoread + fourthoffset, yourvalue , sizeofyourvalue, numberofbytesread)
Hope this helps. There are lots of good tutorials on the forums.
Posts 1–10 of 10 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us