QuestionHelpCan't Pattern Scan.

Posts 1–8 of 8 · Page 1 of 1
Can't Pattern Scan.
I've been trying to make sigscan all day.
I used Fleep's code for this but I can not find the address.

I have this AoB Pattern
Code:
F3 0F 7E 40 10 66 0F D6 45 ?? 8D ?? ?? ?? 00 00 8D 55 ?? E8 ?? ?? ?? ?? F3 0F 7E 4D ?? 8B D0
But I need a signature and a mask to use PatterScan

So I decided to use Olly to find a sig and a mask

I found Bytes in the order of the Array of Bytes I had




I used sig-maker to do SigTest

And it looks fine.



But when I put it in c ++



It fails =/



Things I've tried:

Make a sig with bytes before the address and then add bytes to it.

Used sigs that the mask's contained "?"


Code:
void InitiateHooks()
{

	DWORD JumpAddy = FindPattern("Transformice.exe",
	"\xF3\x0F\x7E\x40\x10\x66\x0F\xD6\x45\x88\x8D\x8E\x60\x40\x00\x00\x8D\x55\xB0\xE8\xCE\x63\x67\x66\xF3\x0F\x7E\x4D\x88\x8B\xD0",
		"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx");

	MsgBoxAddy(JumpAddy);




}
why don't you just use same mask as your aob pattern?
Code:
DWORD JumpAddy = FindPattern("Transformice.exe",
	"\xF3\x0F\x7E\x40\x10\x66\x0F\xD6\x45\x88\x8D\x8E\x60\x40\x00\x00\x8D\x55\xB0\xE8\xCE\x63\x67\x66\xF3\x0F\x7E\x4D\x88\x8B\xD0",
		"xxxxxxxxx?x???xxxx?x????xxxx?xx");
Quote Originally Posted by Ren4rd View Post
why don't you just use same mask as your aob pattern?
Code:
DWORD JumpAddy = FindPattern("Transformice.exe",
	"\xF3\x0F\x7E\x40\x10\x66\x0F\xD6\x45\x88\x8D\x8E\x60\x40\x00\x00\x8D\x55\xB0\xE8\xCE\x63\x67\x66\xF3\x0F\x7E\x4D\x88\x8B\xD0",
		"xxxxxxxxx?x???xxxx?x????xxxx?xx");


I've tried this, and it's the same thing :-c



That's the code i get from fleeps tutorial:

Code:
#include <iostream>
#include <Windows.h>
#include <tlhelp32.h>
#include <Psapi.h>


//Print our pattern scan results if necessary
void MsgBoxAddy(DWORD addy)
{
	
	char szBuffer[1024];
	sprintf(szBuffer, "Addy: %02x", addy);
	MessageBox(NULL, szBuffer, "Title", MB_OK);


}


//Get all module related info, this will include the base DLL. 
//and the size of the module
MODULEINFO GetModuleInfo(char *szModule)
{
	MODULEINFO modinfo = { 0 };
	HMODULE hModule = GetModuleHandle(szModule);
	if (hModule == 0)
		return modinfo;
	GetModuleInformation(GetCurrentProcess(), hModule, &modinfo, sizeof(MODULEINFO));
	return modinfo;
}


void WriteToMemory(uintptr_t addressToWrite, char* valueToWrite, int byteNum)
{
	//used to change our file access type, stores the old
	//access type and restores it after memory is written
	unsigned long OldProtection;
	//give that address read and write permissions and store the old permissions at oldProtection
	VirtualProtect((LPVOID)(addressToWrite), byteNum, PAGE_EXECUTE_READWRITE, &OldProtection);

	//write the memory into the program and overwrite previous value
	memcpy((LPVOID)addressToWrite, valueToWrite, byteNum);

	//reset the permissions of the address back to oldProtection after writting memory
	VirtualProtect((LPVOID)(addressToWrite), byteNum, OldProtection, NULL);
}


DWORD FindPattern(char *module, char *pattern, char *mask)
{
	//Get all module related information
	MODULEINFO mInfo = GetModuleInfo(module);

	//Assign our base and module size
	//Having the values right is ESSENTIAL, this makes sure
	//that we don't scan unwanted memory and leading our game to crash
	DWORD base = (DWORD)mInfo.lpBaseOfDll;
	DWORD size = (DWORD)mInfo.SizeOfImage;


	//Get length for our mask, this will allow us to loop through our array
	DWORD patternLength = (DWORD)strlen(mask);

	for (DWORD i = 0; i < size - patternLength; i++)
	{
		bool found = true;
		for (DWORD j = 0; j < patternLength; j++)
		{
			//if we have a ? in our mask then we have true by default, 
			//or if the bytes match then we keep searching until finding it or not
			found &= mask[j] == '?' || pattern[j] == *(char*)(base + i + j);
		}

		//found = true, our entire pattern was found
		//return the memory addy so we can write to it
		if (found)
		{
			return base + i;
		}
	}

	return NULL;
}

And this is my dllmain

Code:
#include <iostream>
#include <Windows.h>
#include <TlHelp32.h>
#include <Psapi.h>
#include "Functions.h"

char FakeWJ[] = "\x45";


void InitiateHooks()
{
	DWORD PseudumAddy = 0xDEA1DBEEF;
	MsgBoxAddy(PseudumAddy);
	MessageBox(NULL, "Engine", "starting...", MB_OK);
	DWORD JumpAddy = FindPattern("Transformice.exe",
		"\xF3\x0F\x7E\x40\x10\x66\x0F\xD6\x45\x88\x8D\x8E\x60\x40\x00\x00\x8D\x55\xB0\xE8\xCE\x63\x67\x66\xF3\x0F\x7E\x4D\x88\x8B\xD0",
		"xxxxxxxxx?x???xxxx?x????xxxx?xx");

	MsgBoxAddy(JumpAddy);

	


}



BOOL WINAPI DllMain(
	HINSTANCE hinstDLL,
	DWORD fdwReason,
	LPVOID lpReserved)
{
	switch (fdwReason)
	{
	case DLL_PROCESS_ATTACH:
	MessageBoxA(NULL, "Attached", "", 0);
	InitiateHooks();

	break;

	}
}
Maybe there's something wrong with the code?





edit: it also works on sigtest








Bingo!



After changing this:

Code:
//DWORD base = (DWORD)mInfo.lpBaseOfDll;
	//DWORD size = (DWORD)mInfo.SizeOfImage;
	DWORD base = 0xe710000;
	DWORD size = 0x180000;
it works.

How do i get the correctly base and size from mInfo?


note: if i restart the game base and size changes
you re looking for module in your own process, not target
sometimes it works, because some dlls always load to the same offset in all process
but not in your case

use CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, pId) and Module32First, Module32Next to iterate through it
moduleEntry.szModuleto to find a module name and moduleEntry.modBaseAddr to get base addr then
Quote Originally Posted by Ren4rd View Post
you re looking for module in your own process, not target
sometimes it works, because some dlls always load to the same offset in all process
but not in your case

use CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, pId) and Module32First, Module32Next to iterate through it
moduleEntry.szModuleto to find a module name and moduleEntry.modBaseAddr to get base addr then

Thanks for the response, do you have an example there?

Code:
VOID GetExBaseAddress(DWORD pID)
{
   HANDLE hsnapshot = CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, pID);
   MODULEENTRY32 me32;
   me32.dwSize = sizeof(MODULEENTRY32);
   Module32First(hsnapshot, &me32);
   do
   {
      if (strstr(me32.szExePath, "Example.exe"))
      {
           BaseAddress = (DWORD)me32.modBaseAddr;
           break;
      }
   } while(Module32Next(hsnapshot,&me32));
   CloseHandle(hsnapshot);
}
How do i get the size?
Quote Originally Posted by Ren4rd View Post
https://msdn.microsoft.com/ru-ru/lib...(v=vs.85).aspx
modBaseSize
The size of the module, in bytes.
I'm trying but I can not do it at all

Can you show me an example of using CreateToolhelp32Snapshot (TH32CS_SNAPMODULE, pId) and

modBaseSize?


I think I'm going to give up, I liked c ++ but this thing of the base and the size are not right gave a broken
Code:
MODULEENTRY32 get_module_info(char const* name)
{
	HANDLE snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPMODULE, 0);
	if(!snapshot)
	{
		throw std::runtime_error("CreateToolhelp32Snapshot() failed");
	}

	MODULEENTRY32 module;
	module.dwSize = sizeof(MODULEENTRY32);
	if(!Module32First(snapshot, &module))
	{
		CloseHandle(snapshot);
		throw std::runtime_error("failed to get first module");
	}

	do
	{
		if (!strcmp(module.szModule, name))
		{
			CloseHandle(snapshot);
			return module;
		}
	} while (Module32Next(snapshot, &module));

	CloseHandle(snapshot);
	throw std::runtime_error("module not found");
}
Code:
DWORD get_module_length(void* base)
{
	PIMAGE_DOS_HEADER dos_header = static_cast<PIMAGE_DOS_HEADER>(base);
	if (dos_header->e_magic != IMAGE_DOS_SIGNATURE)
	{
		throw std::runtime_error("invalid dos header");
	}
	
	PIMAGE_NT_HEADERS nt_headers = static_cast<PIMAGE_NT_HEADERS>(reinterpret_cast<DWORD>(base) + dos_header->e_lfanew);
	if (nt_headers->Signature != IMAGE_NT_SIGNATURE)
	{
		throw std::runtime_error("invalid nt headers");
	}
	
	// or use BaseOfCode and SizeOfCode (to avoid searching headers and data for the aob)
	return nt_headers->OptionalHeader.SizeOfImage;
}
Posts 1–8 of 8 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us