
Originally Posted by
fallenpowa
do you have any code for noclip? That’s the only thing I still need.
alright bro like I said you need noclip that only works on your side so it doesn’t affect any other entity but you
you can apply this idea by creating a new function in memory and hooking it to the address that handles clipping in the game
to explain it better the function you create in memory would look like this:
Code:
DATA_IN = bytearray([
# pop eax ; add esp, 8 ; push eax ; mov eax,[ebx+14]
0x58, 0x83, 0xC4, 0x08, 0x50, 0x8B, 0x43, 0x14,
# push ebx ; push ecx ; sub esp, 0x30
0x53, 0x51, 0x83, 0xEC, 0x30,
# save xmm0, xmm1, xmm2 to stack
0xF3, 0x0F, 0x7F, 0x44, 0x24, 0x20,
0xF3, 0x0F, 0x7F, 0x4C, 0x24, 0x10,
0xF3, 0x0F, 0x7F, 0x14, 0x24,
# mov ebx, [Trove.exe+108BD70] ; mov ecx, 0
0xBB, 0xE0, 0xE6, 0x30, 0x1D,
0xB9, 0x00, 0x00, 0x00, 0x00,
# loop
# add ebx, [Offset + ecx * 4]
0x03, 0x1C, 0x8D, 0xFF, 0xFF, 0xFF, 0xFF, # <- patched later with offset address
# mov ebx, [ebx] ; cmp ebx, 0 ; je return
0x8B, 0x1B, 0x83, 0xFB, 0x00,
0x0F, 0x84, 0x32, 0x00, 0x00, 0x00,
# inc ecx ; cmp ecx, 4 ; jl loop
0x41, 0x83, 0xF9, 0x04, 0x7C, 0xE8,
# movups xmm0, [ebx+80]
0x0F, 0x10, 0x83, 0x80, 0x00, 0x00, 0x00,
# movaps xmm1, xmm0 ; cmpps xmm1, xmm4, 2
0x0F, 0x28, 0xC8, 0x0F, 0xC2, 0xCC, 0x02,
# movaps xmm2, xmm5 ; cmpps xmm2, xmm0, 2
0x0F, 0x28, 0xD5, 0x0F, 0xC2, 0xD0, 0x02,
# pand xmm1, xmm2 ; movmskps ecx, xmm1
0x66, 0x0F, 0xDB, 0xCA, 0x0F, 0x50, 0xC9,
# and ecx, 7 ; cmp ecx, 7 ; jne return
0x83, 0xE1, 0x07, 0x83, 0xF9, 0x07,
0x0F, 0x85, 0x04, 0x00, 0x00, 0x00,
# mov byte ptr [eax+1], 0
0xC6, 0x40, 0x01, 0x00,
# restore xmm2, xmm1, xmm0
0xF3, 0x0F, 0x6F, 0x14, 0x24,
0xF3, 0x0F, 0x6F, 0x4C, 0x24, 0x10,
0xF3, 0x0F, 0x6F, 0x44, 0x24, 0x20,
# add esp, 0x30 ; pop ecx ; pop ebx ; ret
0x83, 0xC4, 0x30, 0x59, 0x5B, 0xC3,
# offset (4 DWORDs)
0x00, 0x00, 0x00, 0x00, # offset 0
0x28, 0x00, 0x00, 0x00, # offset 1
0xC4, 0x00, 0x00, 0x00, # offset 2
0x04, 0x00, 0x00, 0x00 # offset 3
])
of course I won’t leave it to your imagination I made you a simple example to show how you can use it to make noclip work only for you
example:
Code:
import pymem, ctypes
import pymem.memory, pymem.process, pymem.pattern
# Constants
MODULE = "Trove.exe" # Name of the target process
PLAYER_OFFS = [0x1097680, 0x0] # Offsets to reach the player structure
SIG = bytes([0x8B, 0x43, 0x14, 0x83, 0xC4, 0x08, 0x0F]) # Signature to find the target instruction
DATA_ON = b'\xE8\xFF\xFF\xFF\xFF\x90' # Pattern when Noclip is enabled
DATA_OFF = b'\x8B\x43\x14\x83\xC4\x08\xF8' # Original bytes to restore when disabling Noclip
DATA_IN = bytearray([
0x58, 0x83, 0xC4, 0x08, 0x50, 0x8B, 0x43, 0x14, 0x53, 0x51, 0x83, 0xEC, 0x30,
0xF3, 0x0F, 0x7F, 0x44, 0x24, 0x20, 0xF3, 0x0F, 0x7F, 0x4C, 0x24, 0x10, 0xF3,
0x0F, 0x7F, 0x14, 0x24, 0xBB, 0xE0, 0xE6, 0x30, 0x1D, 0xB9, 0x00, 0x00, 0x00,
0x00, 0x03, 0x1C, 0x8D, 0xFF, 0xFF, 0xFF, 0xFF, 0x8B, 0x1B, 0x83, 0xFB, 0x00,
0x0F, 0x84, 0x32, 0x00, 0x00, 0x00, 0x41, 0x83, 0xF9, 0x04, 0x7C, 0xE8, 0x0F,
0x10, 0x83, 0x80, 0x00, 0x00, 0x00, 0x0F, 0x28, 0xC8, 0x0F, 0xC2, 0xCC, 0x02,
0x0F, 0x28, 0xD5, 0x0F, 0xC2, 0xD0, 0x02, 0x66, 0x0F, 0xDB, 0xCA, 0x0F, 0x50,
0xC9, 0x83, 0xE1, 0x07, 0x83, 0xF9, 0x07, 0x0F, 0x85, 0x04, 0x00, 0x00, 0x00,
0xC6, 0x40, 0x01, 0x00, 0xF3, 0x0F, 0x6F, 0x14, 0x24, 0xF3, 0x0F, 0x6F, 0x4C,
0x24, 0x10, 0xF3, 0x0F, 0x6F, 0x44, 0x24, 0x20, 0x83, 0xC4, 0x30, 0x59, 0x5B,
0xC3, 0x00, 0x00, 0x00, 0x00, 0x28, 0x00, 0x00, 0x00, 0xC4, 0x00, 0x00, 0x00,
0x04, 0x00, 0x00, 0x00
]) # Custom code injected to handle Noclip logic
# Resolve a pointer using a list of offsets
def get_ptr(pm, base, offs):
try:
for o in offs[:-1]:
base = pm.read_int(base + o)
return base + offs[-1]
except:
raise ValueError("Pointer resolution failed")
# Change memory protection on a specific region
def protect(h, addr, sz, prot):
old = ctypes.c_uint32()
if not ctypes.windll.kernel32.VirtualProtectEx(h, addr, sz, prot, ctypes.byref(old)):
raise RuntimeError("VirtualProtectEx failed")
return old.value
# Scan the module for the target instruction using a signature
def find_target(pm, base):
try:
mod = pymem.process.module_from_name(pm.process_handle, MODULE)
found = pymem.pattern.pattern_scan_module(pm.process_handle, mod, SIG)
if found is None:
raise ValueError("Signature not found")
return found # Return address where signature was found
except Exception as e:
print(f"Error finding target: {e}")
return None
# Enable Noclip by injecting custom code and patching a function call
def enable_noclip(pm):
try:
base = pm.process_base.lpBaseOfDll
target = find_target(pm, base)
if target is None:
raise ValueError("Target not found")
player = get_ptr(pm, base, PLAYER_OFFS)
original = pm.read_bytes(target, len(DATA_OFF)) # Backup original bytes
size = len(DATA_IN)
in_addr = pymem.memory.allocate_memory(pm.process_handle, size) # Allocate memory for custom code
# Inject the player address and custom return address
DATA_IN[31:35] = player.to_bytes(4, 'little')
DATA_IN[43:47] = ((in_addr + 131) & 0xFFFFFFFF).to_bytes(4, 'little')
pymem.memory.write_bytes(pm.process_handle, in_addr, bytes(DATA_IN), size) # Write custom code
protect(pm.process_handle, in_addr, size, 0x40) # Make memory executable
# Calculate relative jump from target to injected code
rel = (in_addr - (target + 5)) & 0xFFFFFFFF
patch = b'\xE8' + rel.to_bytes(4, 'little', signed=True) + b'\x90' # Call to injected code
protect(pm.process_handle, target, len(patch), 0x40) # Change protection for patching
pymem.memory.write_bytes(pm.process_handle, target, patch, len(patch)) # Overwrite target with call
return in_addr, original, target # Return info to disable later
except Exception as e:
print(f"Enable error: {e}")
return None, None, None
# Disable Noclip by restoring the original bytes
def disable_noclip(pm, addr, orig, target):
try:
if target is None:
raise ValueError("Target not found")
protect(pm.process_handle, target, len(orig), 0x40)
pymem.memory.write_bytes(pm.process_handle, target, orig, len(orig))
except Exception as e:
print(f"Disable error: {e}")
# Main entry point
def main():
try:
pm = pymem.Pymem(MODULE)
print(f"Connected: {MODULE} (PID {pm.process_id})")
in_addr, orig, target = enable_noclip(pm) # Enable Noclip and get state
if not in_addr or not target:
return print("Enable failed")
input("Press Enter to disable...")
disable_noclip(pm, in_addr, orig, target) # Restore original state
except pymem.exception.ProcessNotFound:
print(f"{MODULE} not found")
except Exception as e:
print(f"Error: {e}")
finally:
if 'pm' in locals():
pm.close_process()
# Run main when the script is executed
if __name__ == "__main__":
main()
so what do you think now is it what you were looking for?