UnhappyHelpCoding C++ Cheats with Pointers

Posts 1–15 of 15 · Page 1 of 1
Coding C++ Cheats with Pointers
Hello, I'm coding a C++ cheat using a Console Application just for testing and I'm having a bit trouble.

The game uses a 64 bit process, I have few pointers but I'm pretty sure none of them will work and I need to find a real pointer and make it write in memory as a loop.

The problem is I cant find a correct pointer, addresses are dynamic and dont know what can I do.

For example, most of the pointers I find are like "game.exe" +05644684 + offsets 307 and 3A0 and dont know if they will work or I have to find a pointer by a different way.
Quote Originally Posted by exploit_modz View Post
Hello, I'm coding a C++ cheat using a Console Application just for testing and I'm having a bit trouble.

The game uses a 64 bit process, I have few pointers but I'm pretty sure none of them will work and I need to find a real pointer and make it write in memory as a loop.

The problem is I cant find a correct pointer, addresses are dynamic and dont know what can I do.

For example, most of the pointers I find are like "game.exe" +05644684 + offsets 307 and 3A0 and dont know if they will work or I have to find a pointer by a different way.
That pointer you listed looks right, you need to read the address at
"game.exe" + 0x05644684
Then add 0x307 to that and read that address
Then add 0x3A0 to that and that will be the address your value is at.
Quote Originally Posted by Nimboso View Post
That pointer you listed looks right, you need to read the address at
"game.exe" + 0x05644684
Then add 0x307 to that and read that address
Then add 0x3A0 to that and that will be the address your value is at.
For example, let's take this pointer as the correct one, (but I dont know if it will work...)

Screenshot: https://gyazo.com/7eed5dbb1840c3d7274987cdb6e6d984

What could be the code in C++ to make it work including variables, ints, reinterpret, qword. dword... etc?
Quote Originally Posted by exploit_modz View Post
For example, let's take this pointer as the correct one, (but I dont know if it will work...)

Screenshot: https://gyazo.com/7eed51840c3d7274987cdb6e6d984

What could be the code in C++ to make it work including variables, ints, reinterpret, qword. dword... etc?
Didn't get the full game name, but it should look something like this

Code:
#include <Windows.h>
#include <iostream>
#include <vector>
#include <TlHelp32.h>

DWORD GetModuleBaseAddress(DWORD dwProcessIdentifier, TCHAR *lpszModuleName)
{
	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, dwProcessIdentifier);
	DWORD dwModuleBaseAddress = 0;
	if (hSnapshot != INVALID_HANDLE_VALUE)
	{
		MODULEENTRY32 ModuleEntry32 = { 0 };
		ModuleEntry32.dwSize = sizeof(MODULEENTRY32);
		if (Module32First(hSnapshot, &ModuleEntry32))
		{
			do
			{
				if (strcmp(ModuleEntry32.szModule, lpszModuleName) == 0)
				{
					dwModuleBaseAddress = (DWORD)ModuleEntry32.modBaseAddr;
					break;
				}
			} while (Module32Next(hSnapshot, &ModuleEntry32));
		}
		CloseHandle(hSnapshot);
	}
	return dwModuleBaseAddress;
}

DWORD getPointer(HANDLE pHandle, DWORD pID, char name[], std::vector<DWORD> offsets) {
	DWORD gameBase = GetModuleBaseAddress(pID, name);
	DWORD address = gameBase;

	if (offsets.empty()) {
		return NULL;
	}
	address += offsets[0];

	for (std::vector<DWORD>::iterator it = offsets.begin() + 1; it != offsets.end(); ++it) {
		ReadProcessMemory(pHandle, (LPVOID)address, &address, 4, 0);
		address = address + *it;
	}

	if (address <= gameBase) { // Increase accuracy
		return NULL;
	}

	return address;
}


DWORD getPID(char procName[]) {
	PROCESSENTRY32 entry;
	entry.dwSize = sizeof(PROCESSENTRY32);
	DWORD pID = 0;

	HANDLE snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, NULL);

	if (Process32First(snapshot, &entry) == TRUE)
	{
		while (Process32Next(snapshot, &entry) == TRUE)
		{
			if (_stricmp(entry.szExeFile, procName) == 0)
			{
				pID = entry.th32ProcessID;
				break;
			}
		}
	}

	CloseHandle(snapshot);

	return pID;

}

int main() {

	char gameName[] = " Shipping.exe";
	std::vector<DWORD> offsets = { 0x02d3b0f0 , 0x3A0, 0x318 };

	DWORD pID = getPID(gameName);
	if (!pID) {
		std::cout << "Could not find game." << std::endl;
		std::cin.get();
		return 1;
	}

	HANDLE pHandle = OpenProcess(PROCESS_ALL_ACCESS, false, pID);
	if (!pHandle) {
		std::cout << "Could not obtain handle." << std::endl;
		std::cin.get();
		return 2;
	}

	DWORD pointerAddress = getPointer(pHandle, pID, gameName, offsets);
	if (!pointerAddress) {
		std::cout << "Invalid pointer." << std::endl;
		std::cin.get();
		return 3;
	}

	std::cout << "Your address is : " << std::hex << pointerAddress << std::endl;
	std::cin.get();

        return 0;

}
Quote Originally Posted by Nimboso View Post
Didn't get the full game name, but it should look something like this

Code:
#include <Windows.h>
#include <iostream>
#include <vector>
#include <TlHelp32.h>

DWORD GetModuleBaseAddress(DWORD dwProcessIdentifier, TCHAR *lpszModuleName)
{
	HANDLE hSnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, dwProcessIdentifier);
	DWORD dwModuleBaseAddress = 0;
	if (hSnapshot != INVALID_HANDLE_VALUE)
	{
		MODULEENTRY32 ModuleEntry32 = { 0 };
		ModuleEntry32.dwSize = sizeof(MODULEENTRY32);
		if (Module32First(hSnapshot, &ModuleEntry32))
		{
			do
			{
				if (strcmp(ModuleEntry32.szModule, lpszModuleName) == 0)
				{
					dwModuleBaseAddress = (DWORD)ModuleEntry32.modBaseAddr;
					break;
				}
			} while (Module32Next(hSnapshot, &ModuleEntry32));
		}
		CloseHandle(hSnapshot);
	}
	return dwModuleBaseAddress;
}

DWORD getPointer(HANDLE pHandle, DWORD pID, char name[], std::vector<DWORD> offsets) {
	DWORD gameBase = GetModuleBaseAddress(pID, name);
	DWORD address = gameBase;

	if (offsets.empty()) {
		return NULL;
	}
	address += offsets[0];

	for (std::vector<DWORD>::iterator it = offsets.begin() + 1; it != offsets.end(); ++it) {
		ReadProcessMemory(pHandle, (LPVOID)address, &address, 4, 0);
		address = address + *it;
	}

	if (address <= gameBase) { // Increase accuracy
		return NULL;
	}

	return address;
}


DWORD getPID(char procName[]) {
	PROCESSENTRY32 entry;
	entry.dwSize = sizeof(PROCESSENTRY32);
	DWORD pID = 0;

	HANDLE snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS, NULL);

	if (Process32First(snapshot, &entry) == TRUE)
	{
		while (Process32Next(snapshot, &entry) == TRUE)
		{
			if (_stricmp(entry.szExeFile, procName) == 0)
			{
				pID = entry.th32ProcessID;
				break;
			}
		}
	}

	CloseHandle(snapshot);

	return pID;

}

int main() {

	char gameName[] = " Shipping.exe";
	std::vector<DWORD> offsets = { 0x02d3b0f0 , 0x3A0, 0x318 };

	DWORD pID = getPID(gameName);
	if (!pID) {
		std::cout << "Could not find game." << std::endl;
		std::cin.get();
		return 1;
	}

	HANDLE pHandle = OpenProcess(PROCESS_ALL_ACCESS, false, pID);
	if (!pHandle) {
		std::cout << "Could not obtain handle." << std::endl;
		std::cin.get();
		return 2;
	}

	DWORD pointerAddress = getPointer(pHandle, pID, gameName, offsets);
	if (!pointerAddress) {
		std::cout << "Invalid pointer." << std::endl;
		std::cin.get();
		return 3;
	}

	std::cout << "Your address is : " << std::hex << pointerAddress << std::endl;
	std::cin.get();

        return 0;

}
Do you have skype? Im getting few errors with that code
Quote Originally Posted by exploit_modz View Post
Do you have skype? Im getting few errors with that code
Yeah I don't use it though. Compile with multi byte instead of Unicode byte.
Quote Originally Posted by Nimboso View Post
Yeah I don't use it though. Compile with multi byte instead of Unicode byte.
Nice I could compile it but then I get this => Could not obtain handle. What can be wrong there?
Quote Originally Posted by exploit_modz View Post
Nice I could compile it but then I get this => Could not obtain handle. What can be wrong there?
Try running it as admin.
Stop trying to run when you can't walk yet, or even sit for that matter.
Quote Originally Posted by Nimboso View Post
He means learn to program instead of copy pasting.
Exactly this, there's no point in "coding" this if you're even having trouble copy pasting, that just indicated you don't even understand the basics of the language. I'm all for helping people learn, but spoonfeeding people answers isn't going to do them any good.
Quote Originally Posted by Hell_Demon View Post
Exactly this, there's no point in "coding" this if you're even having trouble copy pasting, that just indicated you don't even understand the basics of the language. I'm all for helping people learn, but spoonfeeding people answers isn't going to do them any good.
I said I needed help coding a simple cheat using a pointer, I know how to code more or less simple cheats but I never coded with pointers, also I asked for help with the pointer because I dont usually work with them and didnt know if I did it correctly. He posted his code and I appreciate it, but please stop saying to everybody in all forums " Learn yourself, you spoonfed scrub! " That isnt going to help anybody that wants to learn.

I never asked for a source, just help with my simple project and learn how to code with pointers, that's it.

If you are not going to help, please dont post.
In cheat engine's context,

`game.exe` refers to the base address the game's module is mapped at. ( For x86 processes, it's 0x400000 and for x64 processes, it's 0x1400000. Assuming ofc it is mapped at its preferred base address and doesn't have a custom address )

The theory of reading pointers is simple.

[ game.exe + 0xdead ] = read 64 bit address at ( ( base address of game.exe ) + 0xdead )
[ pointer_value + 0xc0de ] = read 64 bit address at ( pointer_value + 0xc0de )

Then simply reinterpret_cast to your target var type.
Quote Originally Posted by Hitokiri~ View Post
In cheat engine's context,

`game.exe` refers to the base address the game's module is mapped at. ( For x86 processes, it's 0x400000 and for x64 processes, it's 0x1400000. Assuming ofc it is mapped at its preferred base address and doesn't have a custom address )
Actually the base address for 64-bit applications by default is 0x140000000, not 0x1400000.
Just letting you know so you don't make a mistake in the future.
Posts 1–15 of 15 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us