QuestionSomething about addys

Posts 1–15 of 23 · Page 1 of 2
Something about addys
Hello,
[NOTE]: I'm not an expert about assembly or C++ but i got enough knowledge.
-----------------------------------
When i try to find address like WeaponMGR, i gets this addy "0xEE1AE8C" while the right addy is "0x156AE8C" so i want to understand this point "Why to change EE1 to 156".
The same for PlayerClient it's "0xEC7FC68" i think it will be changed to something like "0x???FC68" ?
Quote Originally Posted by [Snake] View Post
0xEE1AE8C - cshell.dll = 0x156AE8C
i didn't understand you actually, Do you mean that cshell is a value or what ?
Quote Originally Posted by syounes03 View Post
i didn't understand you actually, Do you mean that cshell is a value or what ?
you need to substract cshell start point
Quote Originally Posted by 96neko View Post
you need to substract cshell start point
Yea i got it finally, but now still the glow prob.
Quote Originally Posted by [Snake] View Post
yes , your address is added to cshell

Didn't understand it yet, i only got that EE1AE8C - 156AE8C = D8B0000 so i think CShell.dll = "D8B0000" if that right how to get the value of cshell direct, i'm not using ollydbg i'm using x64dbg

i think i'm right because no more errors for me, but when i tried to use the glow nothing changed.
Code:
Cshell+PlayerMGR+GlowAddy = 1
i'm using this code and not working.
Quote Originally Posted by syounes03 View Post
Hello,
[NOTE]: I'm not an expert about assembly or C++ but i got enough knowledge.
-----------------------------------
When i try to find address like WeaponMGR, i gets this addy "0xEE1AE8C" while the right addy is "0x156AE8C" so i want to understand this point "Why to change EE1 to 156".
The same for PlayerClient it's "0xEC7FC68" i think it will be changed to something like "0x???FC68" ?
To really understand what's going on, search about ASLR, this should explain what you need to know
Quote Originally Posted by syounes03 View Post
Hello,
[NOTE]: I'm not an expert about assembly or C++ but i got enough knowledge.
-----------------------------------
When i try to find address like WeaponMGR, i gets this addy "0xEE1AE8C" while the right addy is "0x156AE8C" so i want to understand this point "Why to change EE1 to 156".
The same for PlayerClient it's "0xEC7FC68" i think it will be changed to something like "0x???FC68" ?
Now crossfire uses a new compiler system so you will need to do some steps to find currently addresses you want:

If you use OllyDbg (not recommended) you will notice some strange things:
- CShell changing contents every time you open OllyDbg.
- 5B191000 Address not constant so it will not same at your CShell.

- Some MOV(s), XOR(s), LEA(s), DWORD(s),JMP(s), BYTE(s), WORD(s), SUB(s)...etc will be encrypted and contains Hidden address.

So OllyDbg not Recommended at this time...
But If you want to find static address must to some steps:
- Convert ????1000 to ????0000.
- I will take example to find PlayerObject Function address [ Array of bytes : 56 8B F1 80 BE ?? ?? ?? ?? ?? 0F B7 86 ?? ?? ?? ?? 74 1F ]:



Address is 69C13430 , Calculate this [ 668D160F - ????0000(mine is 5B190000) ] = Real address = 0x7C36E0 .

But If you use IDA Pro (or Trial) Now It is different:
- IDA Have an Imagebase It will be different with you:



- We will do same we did with OllyDbg, I will take example to find WeaponMgr Address [ Array of bytes: A1 ?? ?? ?? ?? 8B 0C 88 81 C1 ?? ?? ?? ?? 8A 02 ]:



Address is 66C6AE8C then Calculate [ 66C6AE8C - IDA Imagebase (mine is 65700000) ] = Real Address = 0x156AE8C .

Quote Originally Posted by TheGe2k View Post


Now crossfire uses a new compiler system so you will need to do some steps to find currently addresses you want:

If you use OllyDbg (not recommended) you will notice some strange things:
- CShell changing contents every time you open OllyDbg.
- 5B191000 Address not constant so it will not same at your CShell.
- Some MOV(s), XOR(s), LEA(s), DWORD(s),JMP(s), BYTE(s), WORD(s), SUB(s)...etc will be encrypted and contains Hidden address.

So OllyDbg not Recommended at this time...
But If you want to find static address must to some steps:
- Convert ????1000 to ????0000.
- I will take example to find PlayerObject Function address [ Array of bytes : 56 8B F1 80 BE ?? ?? ?? ?? ?? 0F B7 86 ?? ?? ?? ?? 74 1F ]:



Address is 69C13430 , Calculate this [ 668D160F - ????0000(mine is 5B190000) ] = Real address = 0x7C36E0 .

But If you use IDA Pro (or Trial) Now It is different:
- IDA Have an Imagebase It will be different with you:



- We will do same we did with OllyDbg, I will take example to find WeaponMgr Address [ Array of bytes: A1 ?? ?? ?? ?? 8B 0C 88 81 C1 ?? ?? ?? ?? 8A 02 ]:



Address is 66C6AE8C then Calculate [ 66C6AE8C - IDA Imagebase (mine is 65700000) ] = Real Address = 0x156AE8C .

Thank you alot, i understood now and will try it.
another question about glow, is it connected with BasicPlayerInfo addy or it's alone, in code am i suppose to use BasicPlayerInfo + Glow addy or what ?
Quote Originally Posted by syounes03 View Post
Thank you alot, i understood now and will try it.
another question about glow, is it connected with BasicPlayerInfo addy or it's alone, in code am i suppose to use BasicPlayerInfo + Glow addy or what ?
if you are using the function, it's just cshell+addr
Quote Originally Posted by vaisefud3 View Post
if you are using the function, it's just cshell+addr
Tried this before and got ERROR after cf start, before login.
Quote Originally Posted by syounes03 View Post
Tried this before and got ERROR after cf start, before login.
Of course, you're trying to use a function that should be used ingame before login
Quote Originally Posted by vaisefud3 View Post
Of course, you're trying to use a function that should be used ingame before login
didn't got what you mean.
Quote Originally Posted by syounes03 View Post
didn't got what you mean.
put like, a hotkey or something to activate it ingame, otherwise it's going to crash
@TheGe2k actually, it's not the compiler that is breaking the sigs ( could be that as well )
but one of the reasons so many sigs broke is new settings on themida
API Wrapping for example, broke many API hooks
@vaisefud3, I know what are you mean , but He will not understand what you say , I Just Explain How is works...
Posts 1–15 of 23 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?