[Help][Pointers]

Posts 1–15 of 27 · Page 1 of 2
[Help][Pointers]
I just have a quick question here. I just took this from a code im not sure for a ltclient. I do not take credits for it. I just wanted to learn. Theres so many astrieks I'm not even sure what these 2 lines do this.:
1st line: Looks like cILTClient is going to point to the value pointed by ILTClient.
2nd Line: No Hell of a clue. I would appreciate if you could explain what each dereference operator is doing in stages. Like the first one points to this, then the second one inside the brack points to that etc...
Code:
cILTClient *ILTClient;

ILTClient = *(cILTClient**)0x377ED910
Code:
cILTClient *ILTClient
cILTTClient = Interface for Lith Tech Client

*ILTClient = a pointer to a Lith Tech Client Interface. // it is Currently not initialized so points to nothing.

I would have personally written the previous line as:
Code:
cILTClient *pILTClient
That way the "p" would tell people this variable is a pointer. This sort of prefixing is called Hungarian Notation

also notice when someone puts a "c" in front of their class name that it is probably a reversed class. This means cILTClient is the hackers best interpretation of the class. Since LithTech Engine is closed-source engine there is no public source code which means this class had to be either reverse engineered, or taken from a leaked source from a similar game using LithTech.

Now for the next part:
Code:
ILTClient = *(cILTClient**)0x377ED910
In this part we are assigning our pointer to an Interface for Lith Tech Client and address. pointers store addresses. Remember this.

Now there's this address: 0x377ED910

There is a casting before it: *(cILTClient**)

And the whole thing looks like: *(cILTClient**)0x377ED910

*(cILTClient**) = the [value of] ( a [pointer] to a [pointer] to a (Interface for an Lith Tech Client))

The"[]" represent the asterisks "*".

So you see {0x377ED910} this address is in fact a pointer to a Client pointer, but we don't want a pointer to an LTClient pointer, otherwise we would have declared pLTClient like this:

Code:
 cILTClient** pLTClient;
So what we need is what 0x377ED910 points to. Now remember when I said that an Pointer stores an address? That was important, because now we want what 0x377ED910 points to, not 0x377ED910 itself which is a (ILTCLient**). So now we use what is called a "dereference operator"... in other words that little asterisk at the beginning of the cast.
Code:
 *(cILTClient**)0x377ED910
So this says 0x377ED910 is a cILTClient**. And I want the pointer/value it holds which would be a (cILTCLient*).

So now:
ILTCLient can equal what 0x377ED910 is pointing to. and viola...
Code:
 ILTClient = *(cILTClient**)0x377ED910
a [pointer to] an (Interface for a LithTech Client) = the [value of] a [pointer to] a [pointer to] an (Interface for a LithTech Client).

As you see [value of] and [pointer] cancel each other out so we are left with:
or a [pointer to] an (Interface for a LithTech Client) = a [pointer to] an (Interface for a LithTech Client).
Quote Originally Posted by why06 View Post
Code:
cILTClient *ILTClient
cILTTClient = Interface for Lith Tech Client

*ILTClient = a pointer to a Lith Tech Client Interface. // it is Currently not initialized so points to nothing.

I would have personally written the previous line as:
Code:
cILTClient *pILTClient
That way the "p" would tell people this variable is a pointer. This sort of prefixing is called Hungarian Notation

also notice when someone puts a "c" in front of their class name that it is probably a reversed class. This means cILTClient is the hackers best interpretation of the class. Since LithTech Engine is closed-source engine there is no public source code which means this class had to be either reverse engineered, or taken from a leaked source from a similar game using LithTech.

Now for the next part:
Code:
ILTClient = *(cILTClient**)0x377ED910
In this part we are assigning our pointer to an Interface for Lith Tech Client and address. pointers store addresses. Remember this.

Now there's this address: 0x377ED910

There is a casting before it: *(cILTClient**)

And the whole thing looks like: *(cILTClient**)0x377ED910

*(cILTClient**) = the [value of] ( a [pointer] to a [pointer] to a (Interface for an Lith Tech Client))

The"[]" represent the asterisks "*".

So you see {0x377ED910} this address is in fact a pointer to a Client pointer, but we don't want a pointer to an LTClient pointer, otherwise we would have declared pLTClient like this:

Code:
 cILTClient** pLTClient;
So what we need is what 0x377ED910 points to. Now remember when I said that an Pointer stores an address? That was important, because now we want what 0x377ED910 points to, not 0x377ED910 itself which is a (ILTCLient**). So now we use what is called a "dereference operator"... in other words that little asterisk at the beginning of the cast.
Code:
 *(cILTClient**)0x377ED910
So this says 0x377ED910 is a cILTClient**. And I want the pointer/value it holds which would be a (cILTCLient*).

So now:
ILTCLient can equal what 0x377ED910 is pointing to. and viola...
Code:
 ILTClient = *(cILTClient**)0x377ED910
a [pointer to] an (Interface for a LithTech Client) = the [value of] a [pointer to] a [pointer to] an (Interface for a LithTech Client).

As you see [value of] and [pointer] cancel each other out so we are left with:
or a [pointer to] an (Interface for a LithTech Client) = a [pointer to] an (Interface for a LithTech Client).
Excellent, I like how you even explained the name of the variable and such.
This was unbelievably helpful. I have learned so much from your post thank you so so much. I'm suprised how far you went for someone like me who only has a 11 post count... I'm so thankful.
I have a few more questions. I'll just put them in a list.
Credits: IcySeal for the LtClient method and Nu11V0id for some codes as well.

I DID NOT MAKE ANY OF THESE CODES.
1. For you're explanation why06 about the LithTech Game Engine Client Console..

Code:
*(cILTClient**) = the [value of] ( a [pointer] to a [pointer] to a (Interface for an Lith Tech Client))
What are each one of these pointers pointing to as that was not clear to me. Everything else was fine.

2.
Is this right?
The 1st line just looks like a pointer declartion for the "LTClient" Variable. Looks to me like DWORD is pointing to a address, and then being pointed to the Lith Tech Game Engine Client. I'm not sure
Code:
//DWORD *LTClient = ( DWORD* )( 0x377ED910 );
I'd rather not say what I think lol.
//void* CONoff = ( void* )*( DWORD* )( *LTClient + 0x208 );
3.
Is this right?
Here's what I believe, szCommand is getting the value pointed by the char array above it which inside store's offset's or an offset( which one is it??) and this points to "PushToConsole" function.

Code:
Code:
class cILTClient
{
public:
    char offset[520];
    int ( *PushToConsole ) ( char* szCommand );
}; }
4. I did not make this.
Well, I have no clue what the parameter list is, a brief discription of what this does would be great.

Code:
bool Memoria( void * pDest, char * szPatch, size_t sSize ) //Nopping Method
{
    DWORD dwOrgProtect = NULL;
    if ( !VirtualProtect ( pDest, sSize, PAGE_EXECUTE_READWRITE, &dwOrgProtect ))
        return FALSE;

    memcpy( pDest, szPatch, sSize );
    VirtualProtect( pDest, sSize, dwOrgProtect, NULL );
    return TRUE;
}
5.
Code:
Memoria(( void* )( SUPER_BULLETS ), "\x0F\x94\xC0", 3 );
I see alot of these codes,
to get the sigs nopped.
I'm wondering what is ""\x0F\x94\xC0" and, the last parameter 3 what is that for.

6. What are sigs, what can they be used for, what are sig searches..?
I have decided to tackle number 2 & 3 at the same time. It took a while for me to realise that 520 in decimal was the same as 0x208 in hexadecimal. These are just two different ways to access the same function. I've seen the first one done more often, but the second is more valid. So lets start with the first.

I already went over pointers so this one should be easy. All you need to know is what a DWORD is. A DWORD literally means double word. a WORD on 32bit Windows is made up of 2 bytes. So a DWORD is four bytes. What's important about this is everything stored in memory can be referenced with a DWORD, atleast in flat memory model. Since pointers store addresses this means that EVERY pointer to a pointer can be considered a DWORD*. In fact many pointers that do not point to other pointers can be considered DWORD*. Now you should know some people take shorcuts with pointers. If you understand them well enough you can pretty much do whatever you want, name variables whatever you want, and COMPLETELY forget about perspective. The following code is an example of that:

Code:
DWORD *LTClient = ( DWORD* )( 0x377ED910 );
void* CONoff = ( void* )*( DWORD* )( *LTClient + 0x208 );
And let me finish by saying this code is utterly wrong. Sure it works right, but it does not make sense. The writer of this function did not know at the time atleast, from what he told me what he was doing. However the "Push2Console" function has become so popular now that this erroneous function has stuck. You can't have LTClient is not a LTClient. It is a pointer to a DWORD. That DWORD is stored at address 0x377ED910. That DWORD stored at that address is infact the address of LTClient. So you see LTClient should actually be named pLTClient. So we need to open the door at pLTClient to get to LTClient.

Then to get to push to console we need to offset from the Object pointer LTClient to get to its members. The member "Push2Console" is 520 bytes away or 0x208. (*LTClient + 0x208) would be the address of that function. This should be written (LTClient + 0x208) or (*pLTClient + 0x208). Then the whole thing quickly deteriorates. He says the address of the P2C is a DWORD* when it is in fact the address of a function!

Then he goes on to find the value that DWORD* stores which will be the beginning of the function itself. Then he says the start of the function is a void*. Now void* confuse even me. So he said the start of the function points to no data and calls that pointer to no data CONoff. If you see the rest of the function he starts using inline asm and its a royal mess! And this is exactly the reason people aren't able to learn from these codes. I've seen it time and time again. If you don't understand something don't just assume that the code ur using is right. Some very skilled coders can write like this because they understand concepts well enough that the data types don't matter so they can abstractly understand something like this:

Code:
 int* k;
&k = (int**) 0x428F3D28;
int MessageBoxHook(HWND hWnd, LPCSTR text, LPCSTR title, UINT type)
{
cout<<"hooked";
return 1;
}
k = (int*)MessageBoxhook;
And then they tell you if you don't understand it its because you didn't learn C++! Fuck that! You just assigned an int a function. Proper notation makes for cleaner code with less mistakes.

Now back to the code. The proper way to do it is like so.
Code:
Code:
class cILTClient
{
public:
    char offset[520];
    int ( *PushToConsole ) ( char* szCommand );
}; }
See IcySeal knew what he was doing when he coded this. Though the code class is not completely reversed we see that he fills in the distance to PushToConsole with 520 bytes or 0x208 bytes. P2C becomes a function pointer. I don't the real PushtoConsole is a function pointer, but this allows him to easily call his function simply by doing the following ILTClient.PushToConsole("text");
1. You have to understand I'm describing the casting as: *(cILTClient**) as a:
the [value of] ( [pointer to] a [pointer to] an (Interface for a LithTech Client)).

if you don't know any C++ very well this will be difficult if not impossible to understand, but when casting we force a value to behave like another type. For instance if I had:
Code:
 int c = 0;
double b = 0.999;
c = (int) b;
I am forcing one data type to another. In your original code you had an address... 0x377ED910

This is just a number. It does not matter that it is in hexadecimal format. Your compiler would treat it as a long type. Since we want to treat this number as the address of our LTClient pointer we must cast this number as that.

Now what stores addresses? That's right pointers. So if 0x377ED910 was say a variable it would be the same as this:
Code:
 &pILTClient == 0x377ED910
So you see the actual location in memory where pILTClient chills at is 0x377ED910 . That's his home. If you knock on his door he'll come out, but his address is not him. Just like your address is not you, it's just where your at.

This cast says:
Code:
pILTClient = *(cILTClient**)0x377ED910;
I want to find pILTClient. I don't know where he's at, but I know his home address. In a way since we can find pILTClient by his address we say that his "home address" or 0x377ED910 points to him. Now that we have his home address I can NOT go ahead and say that:

Code:
 pILTClient = 0x377ED910;
That is like saying your address is you! or I am Swadley rd. APT 55, lol. I'm not an apartment! I'm a person! SO we must open the door at that address to see who's inside. The "*" in front of (cILTClient**) means "open this door" or "value of". So:
*(cILTClient**)0x377ED910 = open the door at apartment "0x377ED910" and get the (ILTClient*) person who lives there.
Now we want to move that person to a new home which will be the address of our variable pILTClient.
Code:
pILTClient = *(ILTClient**)0x377ED910;
yeh our person has a new home! We will call that person pILTClient. And his home is &pILTCLient, but we can just call him pILTClient directly now, and don't have to knock on his door anymore. Since we have gave him a name we can just call him pILTClient like I would talk and refer to you as Aqollo now.

Even though before when I didn't know your name I had to refer to you by your address:
Code:
Aqollo = that guy who lives in Swadley rd. APT.55, Canada
(I know that's not where u live I'm making this up)

So we could say:
Code:
 Person = Aqollo;
Aqollo = *(Person*)Swadley rd. APT. 55; //open door at address
Now if you had a watch on then I could find that watch by finding you
Code:
Watch* Aqollo;
Aqollo = *(Watch**)Swadley APT.55;
So I can find the watch by finding Aqollo so Aqollo "points to the watch". If I don't know Aqollo I can find the watch by finding Aqollo address. His address Swadley rd. (0x377ED910) [points to] Aqollo and Aqollo points to his watch. A watch is the end of the chain so we say Watch** because there were two levels of indirection before we get to the watch. Look familiar?

Code:
ILTClient* pILTClient;
pILTClient = *(ILTClient**)0x377ED910; //open door at address
As you become more proficient you can drop all the mnemonics and memory devices I used and just start saying "the value of" and "points to", but for now I think it would be a good idea if you wrote everything out the way I did. Remember 0x377ED910 is just a number just like Swadley rd. is just a word. I have to treat it like an adress to use it. 0x377ED910 is pILTClient's home and if you want to see him you have to open the door. Finally try thinking a little more generally. pILTClient though we treated him like a person is actually a pointer himself. and what he contains is an ILTClient in his pocket or whatever. So we could treat pILTClient's as the home of ILTClient. It's really only a matter of perspective. Go ahead and experiment a little. However I recommend you only look at the perspective of one pointer at a time. Take your time, because you don't want to be thinking ILTClient and pILTClient share the same house, this is where this memory device breaks down! pointers only reference one thing! do not take this memory device and then try to infer other things out of it. If you get to that point it is time to move on and put the memory devices behind you.

I'll get to the rest of the questions later.
Fuck you why, trying to steal my minion position posting smart stuff >.<
Why is taking over again... :O
You have honestlye helped so much its unbelievable. Due to how dumb I'm, I still have a bit of confusion, it would be great if you could help clear it up.
The problem is expressing the problem really. Hopefully you can find out, where I am going wronge about this.

Code:
cILTClient *ILTClient;

ILTClient = *(cILTClient**)0x377ED910
1. Just to comfirm, without the asterisk outside of the paraenthesis the address would have just pointed to the LT Client pointer?
2.Was the astrieks inside the bracket just saying that the address was just pointing to the LTClient Pointer and that will store the address of 0x377ED910?

I'm confused at this part of your post for quite a while. I thought 0x377ED910 was pointing to the LTClient pointer, but in ur post you metnion it's pointing to ILTClient**

So what we need is what 0x377ED910 points to. Now remember when I said that an Pointer stores an address? That was important, because now we want what 0x377ED910 points to, not 0x377ED910 itself which is a (ILTCLient**). So now we use what is called a "dereference operator"... in other words that little asterisk at the beginning of the cast.

Code:
Code:
 *(cILTClient**)0x377ED910
So this says 0x377ED910 is a cILTClient**. And I want the pointer/value it holds which would be a (cILTCLient*).
So now:
ILTCLient can equal what 0x377ED910 is pointing to. and viola...
I just figured I should get used to helping out a bit more since NextGen isn't here.

@ Aqollo: I said that 0 your addreess 0x003watever is pointing to a LTClient* so that address itself is a LTClient** because its the address of an LTClient*

LTClient** = &LTClient*;
I'm still stumped ;l

Code:
cILTClient *ILTClient;

ILTClient = *(cILTClient**)0x377ED910
What are the two levels of "indirection" here, this is what I'm not getting clear. Is it that..

You had already mentioned how ILTClient** itself is 0x377ED910 I remember that...

So the two astrieks mean:
initally the address 0x377.. is ILTClient** but the value it holds points to ILTClient* which points to cILTClient?
Quote Originally Posted by Aqollo View Post
So the two astrieks mean:
initally the address 0x377.. is ILTClient** but the value it holds points to ILTClient* which points to cILTClient?
Yes. Also you should formally learn what pointers and references are in a C++ book or tutorial.
Why06 for programming mod.
Did you not pay attention when you learned about pointers or what?
Posts 1–15 of 27 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us