ExclamationCF Hack

Posts 1–15 of 23 · Page 1 of 2
CF Hack
So..finally. Lesson 70 FINISHED. I'm still kind of unclear about pointers and what not, but I WILL revise them with my dad. The lesson didn't really talk about pointers & references, all he talked about mostly was like functions and stuff, which I already made sense of completely. Also I'm kind of unclear about the use of random numbers, but again, will revise.

These are the things I'm still KIND of unclear about:

-pointers
-use of random numbers
-classes (just a tiny bit)

NOW, I can start looking at some CF codes. Hopefully it will go well.

I need some serious help, because this will be my very first time even attempting to LOOK at these codes. I need all the help I can get. @giniyat101 , etc.

I need help from how to unpack CShell.dll, to the point of how to make it undetected, to the point of how to make a base.



These, will be probably in my v1. Hopefully.

-Wall hack
-See Ghost

Then in my v2 I'll add a base for turning features on/off.




I will NOT be working today. I will start working tomorrow. I was too pumped up on "infdef" and "infndef" stuff so I need some rest.


Any professional CF hack makers, please send me a VM or PM about their skype info, that would be very much likely appreciated. I only need 1 person, not like 10.






THIS WAS ORIGINALLY ALREADY POSTED IN HELP SECTION. ITS JUST MOVED HERE BY ME.
lol good job.
teach me how to use c++ a bit?
Quote Originally Posted by Hydrogen View Post
lol good job.
teach me how to use c++ a bit?
Sure, but I can't teach extremely well and organized, as I'm still a learner. If you want to learn by an expert, go ask @giniyat101 or any other coders.
i will give some tips here which could help :

1- learn using some winapis .. learning what LoadLibrary and GetModuleHandle do is a good idea

2- learn basics of assembly.. you will need some of them which iam going to explain:

registers : acts like variables in coding , but they are stored in the cpu not the ram
in x86 there is 9 32 bit registers : EAX, EBX, ECX, EDX, ESI, EDI, ESP, EBP, EIP
a 16 bit version of them is also available (without the E)
and AX, BX, CX, DX is formed of two 8 bit registers (replacing the X with either L or H)

MOV dest, source command: copies the value of source to dest can appear in different forms like :
MOV [dest], source : copies the value of source to the variable stored in address dest
MOV dest, [source] : copies the value stored in address source to dest
the signs + and * can also appear, only with the []

examples:
mov eax, eax ; nothing happens
mov eax, 100 ; eax equals 0x100 after this operation
mov [40EA00], eax ;value at 0x40EA00 becomes 0x100 after this operation
mov ecx, 40EA00 ;ecx will equal 0x40EA00
mov edx, [ecx] ;edx will equal 0x100

lea dest, [source] command :
almost like mov, but the difference it calculates source expression but without reading a value from it
example:

lea esi, [ecx+edx*2] ; esi equals 0x40EA00 + 0x100 * 2 = 0x40EC00
lea eax, [eax] ; nothing will happen ofc

fld [source] and fstp [dest] :
acts like mov but with floats.

3- download and try to practice ollydbg
OllyDbg v1.10

after finishing these steps get latest unpacked cshell.dll from here
http://www.mpgh.net/forum/242-crossf...-7-2012-a.html

and try to load it in ollydbg .. the stats bar should say "entry point of debugged dll"
if it doesnt say that try making a program that loads the unpacked cshell (if you read info about LoadLibrary you will find it easy!)

make sure you are viewing cshell by right click -> view -> module cshell_whatever

try to search common string refrences used in cshell.. to do that right click then pick search for -> all refrenced text strings
then right click in the new window and pick find then type a string.. u may use these:

ReloadAnimRatio : no reload delay
ChangeWeaponAnimRatio : no change delay
AmmoDamage : no need to explain
CharacterHiddenAlpha / CharacterHiddenWalkAlpha / CharacterHiddenRunAlpha : see ghosts
DistFallDamageStartFrom /DamagePerMeter : no fall damage

for example iam going to DistFallDamageStartFrom as its very easy
so u type DistFallDamageStartFrom in the search box and press enter twice to go to the code

you would see something like this :



there is two useful commands here

MOV EDX,DWORD PTR DS:[10B740F8]
FSTP DWORD PTR DS:[EDX]

translating to c++ will give something like that:

Code:
DWORD myEDX = *(0x10B740F8);
*(myEDX) = something; // (lets say 99999.0f)
correct? no it isnt because in first line you are trying to read from a dword
and in the second line you are trying to write a float value to a dword
lets fix that by type casting to other types:

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
*(float*)(myEDX) = 99999.0f;
now thats better but still a problem.. what if the pointer myEDX is not valid?
it will cause the game to crash so we will add a check of NULL pointer

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
if (myEDX)
{
    *(float*)(myEDX) = 99999.0f;
}
almost correct! there is only one problem
cshell is loaded at 0x10000000 (press alt + E in ollydbg to check) .. but when the game loads it .. it will probably go to different address
so the easiest way is to convert the address 0x10B740F8 to offset by subtracting 0x10000000 (the result is 0xB740F8)
then convert it back to an address ingame

if you already read about GetModuleHandle, you would have known it takes module name as a parameter and returns base address as HMODULE on success

again, we will type cast the result to DWORD so we can add it to 0xB740F8

so the final code will look like this:

Code:
DWORD CShell = (DWORD)GetModuleHandle(L"CShell.dll");
if (CShell)
{
    DWORD myEDX = *(DWORD*)(0x10B740F8);
    if (myEDX)
    {
        *(float*)(myEDX) = 99999.0f;
    }
}
if you have any problem in any of this steps tell me through pm or in msn

good luck
Quote Originally Posted by giniyat101 View Post
i will give some tips here which could help :

1- learn using some winapis .. learning what LoadLibrary and GetModuleHandle do is a good idea

2- learn basics of assembly.. you will need some of them which iam going to explain:

registers : acts like variables in coding , but they are stored in the cpu not the ram
in x86 there is 9 32 bit registers : EAX, EBX, ECX, EDX, ESI, EDI, ESP, EBP, EIP
a 16 bit version of them is also available (without the E)
and AX, BX, CX, DX is formed of two 8 bit registers (replacing the X with either L or H)

MOV dest, source command: copies the value of source to dest can appear in different forms like :
MOV [dest], source : copies the value of source to the variable stored in address dest
MOV dest, [source] : copies the value stored in address source to dest
the signs + and * can also appear, only with the []

examples:
mov eax, eax ; nothing happens
mov eax, 100 ; eax equals 0x100 after this operation
mov [40EA00], eax ;value at 0x40EA00 becomes 0x100 after this operation
mov ecx, 40EA00 ;ecx will equal 0x40EA00
mov edx, [ecx] ;edx will equal 0x100

lea dest, [source] command :
almost like mov, but the difference it calculates source expression but without reading a value from it
example:

lea esi, [ecx+edx*2] ; esi equals 0x40EA00 + 0x100 * 2 = 0x40EC00
lea eax, [eax] ; nothing will happen ofc

fld [source] and fstp [dest] :
acts like mov but with floats.

3- download and try to practice ollydbg
OllyDbg v1.10

after finishing these steps get latest unpacked cshell.dll from here
http://www.mpgh.net/forum/242-crossf...-7-2012-a.html

and try to load it in ollydbg .. the stats bar should say "entry point of debugged dll"
if it doesnt say that try making a program that loads the unpacked cshell (if you read info about LoadLibrary you will find it easy!)

make sure you are viewing cshell by right click -> view -> module cshell_whatever

try to search common string refrences used in cshell.. to do that right click then pick search for -> all refrenced text strings
then right click in the new window and pick find then type a string.. u may use these:

ReloadAnimRatio : no reload delay
ChangeWeaponAnimRatio : no change delay
AmmoDamage : no need to explain
CharacterHiddenAlpha / CharacterHiddenWalkAlpha / CharacterHiddenRunAlpha : see ghosts
DistFallDamageStartFrom /DamagePerMeter : no fall damage

for example iam going to DistFallDamageStartFrom as its very easy
so u type DistFallDamageStartFrom in the search box and press enter twice to go to the code

you would see something like this :



there is two useful commands here

MOV EDX,DWORD PTR DS:[10B740F8]
FSTP DWORD PTR DS:[EDX]

translating to c++ will give something like that:

Code:
DWORD myEDX = *(0x10B740F8);
*(myEDX) = something; // (lets say 99999.0f)
correct? no it isnt because in first line you are trying to read from a dword
and in the second line you are trying to write a float value to a dword
lets fix that by type casting to other types:

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
*(float*)(myEDX) = 99999.0f;
now thats better but still a problem.. what if the pointer myEDX is not valid?
it will cause the game to crash so we will add a check of NULL pointer

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
if (myEDX)
{
    *(float*)(myEDX) = 99999.0f;
}
almost correct! there is only one problem
cshell is loaded at 0x10000000 (press alt + E in ollydbg to check) .. but when the game loads it .. it will probably go to different address
so the easiest way is to convert the address 0x10B740F8 to offset by subtracting 0x10000000 (the result is 0xB740F8)
then convert it back to an address ingame

if you already read about GetModuleHandle, you would have known it takes module name as a parameter and returns base address as HMODULE on success

again, we will type cast the result to DWORD so we can add it to 0xB740F8

so the final code will look like this:

Code:
DWORD CShell = (DWORD)GetModuleHandle(L"CShell.dll");
if (CShell)
{
    DWORD myEDX = *(DWORD*)(0x10B740F8);
    if (myEDX)
    {
        *(float*)(myEDX) = 99999.0f;
    }
}
if you have any problem in any of this steps tell me through pm or in msn

good luck
Thank You .. You really helped me
Quote Originally Posted by giniyat101 View Post
i will give some tips here which could help :

1- learn using some winapis .. learning what LoadLibrary and GetModuleHandle do is a good idea

2- learn basics of assembly.. you will need some of them which iam going to explain:

registers : acts like variables in coding , but they are stored in the cpu not the ram
in x86 there is 9 32 bit registers : EAX, EBX, ECX, EDX, ESI, EDI, ESP, EBP, EIP
a 16 bit version of them is also available (without the E)
and AX, BX, CX, DX is formed of two 8 bit registers (replacing the X with either L or H)

MOV dest, source command: copies the value of source to dest can appear in different forms like :
MOV [dest], source : copies the value of source to the variable stored in address dest
MOV dest, [source] : copies the value stored in address source to dest
the signs + and * can also appear, only with the []

examples:
mov eax, eax ; nothing happens
mov eax, 100 ; eax equals 0x100 after this operation
mov [40EA00], eax ;value at 0x40EA00 becomes 0x100 after this operation
mov ecx, 40EA00 ;ecx will equal 0x40EA00
mov edx, [ecx] ;edx will equal 0x100

lea dest, [source] command :
almost like mov, but the difference it calculates source expression but without reading a value from it
example:

lea esi, [ecx+edx*2] ; esi equals 0x40EA00 + 0x100 * 2 = 0x40EC00
lea eax, [eax] ; nothing will happen ofc

fld [source] and fstp [dest] :
acts like mov but with floats.

3- download and try to practice ollydbg
OllyDbg v1.10

after finishing these steps get latest unpacked cshell.dll from here
http://www.mpgh.net/forum/242-crossf...-7-2012-a.html

and try to load it in ollydbg .. the stats bar should say "entry point of debugged dll"
if it doesnt say that try making a program that loads the unpacked cshell (if you read info about LoadLibrary you will find it easy!)

make sure you are viewing cshell by right click -> view -> module cshell_whatever

try to search common string refrences used in cshell.. to do that right click then pick search for -> all refrenced text strings
then right click in the new window and pick find then type a string.. u may use these:

ReloadAnimRatio : no reload delay
ChangeWeaponAnimRatio : no change delay
AmmoDamage : no need to explain
CharacterHiddenAlpha / CharacterHiddenWalkAlpha / CharacterHiddenRunAlpha : see ghosts
DistFallDamageStartFrom /DamagePerMeter : no fall damage

for example iam going to DistFallDamageStartFrom as its very easy
so u type DistFallDamageStartFrom in the search box and press enter twice to go to the code

you would see something like this :



there is two useful commands here

MOV EDX,DWORD PTR DS:[10B740F8]
FSTP DWORD PTR DS:[EDX]

translating to c++ will give something like that:

Code:
DWORD myEDX = *(0x10B740F8);
*(myEDX) = something; // (lets say 99999.0f)
correct? no it isnt because in first line you are trying to read from a dword
and in the second line you are trying to write a float value to a dword
lets fix that by type casting to other types:

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
*(float*)(myEDX) = 99999.0f;
now thats better but still a problem.. what if the pointer myEDX is not valid?
it will cause the game to crash so we will add a check of NULL pointer

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
if (myEDX)
{
    *(float*)(myEDX) = 99999.0f;
}
almost correct! there is only one problem
cshell is loaded at 0x10000000 (press alt + E in ollydbg to check) .. but when the game loads it .. it will probably go to different address
so the easiest way is to convert the address 0x10B740F8 to offset by subtracting 0x10000000 (the result is 0xB740F8)
then convert it back to an address ingame

if you already read about GetModuleHandle, you would have known it takes module name as a parameter and returns base address as HMODULE on success

again, we will type cast the result to DWORD so we can add it to 0xB740F8

so the final code will look like this:

Code:
DWORD CShell = (DWORD)GetModuleHandle(L"CShell.dll");
if (CShell)
{
    DWORD myEDX = *(DWORD*)(0x10B740F8);
    if (myEDX)
    {
        *(float*)(myEDX) = 99999.0f;
    }
}
if you have any problem in any of this steps tell me through pm or in msn

good luck
how do you learnt c++ in egypt ? book or course ?
Quote Originally Posted by giniyat101 View Post
i will give some tips here which could help :

1- learn using some winapis .. learning what LoadLibrary and GetModuleHandle do is a good idea

2- learn basics of assembly.. you will need some of them which iam going to explain:

registers : acts like variables in coding , but they are stored in the cpu not the ram
in x86 there is 9 32 bit registers : EAX, EBX, ECX, EDX, ESI, EDI, ESP, EBP, EIP
a 16 bit version of them is also available (without the E)
and AX, BX, CX, DX is formed of two 8 bit registers (replacing the X with either L or H)

MOV dest, source command: copies the value of source to dest can appear in different forms like :
MOV [dest], source : copies the value of source to the variable stored in address dest
MOV dest, [source] : copies the value stored in address source to dest
the signs + and * can also appear, only with the []

examples:
mov eax, eax ; nothing happens
mov eax, 100 ; eax equals 0x100 after this operation
mov [40EA00], eax ;value at 0x40EA00 becomes 0x100 after this operation
mov ecx, 40EA00 ;ecx will equal 0x40EA00
mov edx, [ecx] ;edx will equal 0x100

lea dest, [source] command :
almost like mov, but the difference it calculates source expression but without reading a value from it
example:

lea esi, [ecx+edx*2] ; esi equals 0x40EA00 + 0x100 * 2 = 0x40EC00
lea eax, [eax] ; nothing will happen ofc

fld [source] and fstp [dest] :
acts like mov but with floats.

3- download and try to practice ollydbg
OllyDbg v1.10

after finishing these steps get latest unpacked cshell.dll from here
http://www.mpgh.net/forum/242-crossf...-7-2012-a.html

and try to load it in ollydbg .. the stats bar should say "entry point of debugged dll"
if it doesnt say that try making a program that loads the unpacked cshell (if you read info about LoadLibrary you will find it easy!)

make sure you are viewing cshell by right click -> view -> module cshell_whatever

try to search common string refrences used in cshell.. to do that right click then pick search for -> all refrenced text strings
then right click in the new window and pick find then type a string.. u may use these:

ReloadAnimRatio : no reload delay
ChangeWeaponAnimRatio : no change delay
AmmoDamage : no need to explain
CharacterHiddenAlpha / CharacterHiddenWalkAlpha / CharacterHiddenRunAlpha : see ghosts
DistFallDamageStartFrom /DamagePerMeter : no fall damage

for example iam going to DistFallDamageStartFrom as its very easy
so u type DistFallDamageStartFrom in the search box and press enter twice to go to the code

you would see something like this :



there is two useful commands here

MOV EDX,DWORD PTR DS:[10B740F8]
FSTP DWORD PTR DS:[EDX]

translating to c++ will give something like that:

Code:
DWORD myEDX = *(0x10B740F8);
*(myEDX) = something; // (lets say 99999.0f)
correct? no it isnt because in first line you are trying to read from a dword
and in the second line you are trying to write a float value to a dword
lets fix that by type casting to other types:

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
*(float*)(myEDX) = 99999.0f;
now thats better but still a problem.. what if the pointer myEDX is not valid?
it will cause the game to crash so we will add a check of NULL pointer

Code:
DWORD myEDX = *(DWORD*)(0x10B740F8);
if (myEDX)
{
    *(float*)(myEDX) = 99999.0f;
}
almost correct! there is only one problem
cshell is loaded at 0x10000000 (press alt + E in ollydbg to check) .. but when the game loads it .. it will probably go to different address
so the easiest way is to convert the address 0x10B740F8 to offset by subtracting 0x10000000 (the result is 0xB740F8)
then convert it back to an address ingame

if you already read about GetModuleHandle, you would have known it takes module name as a parameter and returns base address as HMODULE on success

again, we will type cast the result to DWORD so we can add it to 0xB740F8

so the final code will look like this:

Code:
DWORD CShell = (DWORD)GetModuleHandle(L"CShell.dll");
if (CShell)
{
    DWORD myEDX = *(DWORD*)(0x10B740F8);
    if (myEDX)
    {
        *(float*)(myEDX) = 99999.0f;
    }
}
if you have any problem in any of this steps tell me through pm or in msn

good luck
blalbalbalalbalbalbalbalbalbalblablalbalbalbalbalb kosomak ya mtnak men 7y2ra2a kol dah y bn l wth5a
Quote Originally Posted by [N.O]N.A.M.E View Post
blalbalbalalbalbalbalbalbalbalblablalbalbalbalbalb kosomak ya mtnak men 7y2ra2a kol dah y bn l wth5a
ana katbo 3shan yt7at fi kesak msh 3shan yt2ra
Quote Originally Posted by giniyat101 View Post
ana katbo 3shan yt7at fi kesak msh 3shan yt2ra
sorry , but i don't have a kes , but you got dual keses one beside your ass and one in your mind so i can neek afkarak
Quote Originally Posted by [N.O]N.A.M.E View Post
sorry , but i don't have a kes , but you got dual keses one beside your ass and one in your mind so i can neek afkarak
and you have 4 kyas (gm3 kees)
1 mkan bta3ak
1 mkan tezak
2 mkan bdanak
Quote Originally Posted by giniyat101 View Post
and you have 4 kyas (gm3 kees)
1 mkan bta3ak
1 mkan tezak
2 mkan bdanak
you son of 3'abaiah /bitch

how you know that they are insted of my dick balls ?? cuz you know that i have em so prove that you are ebn mara fash5
you are talking about yournafasak you are such a mtnak son of وثخه you can fap 7 w nos from your mind kes and you will get pergenet in your mind , you will got a babay bside your fola brain and when your son ask you , where i was before i get porn you will say in my mindkes he will tell you who is your my father you will tell him my soba3 which got sperms from me and 7 w nosed fmo5ak amtnak eh l habl bn l fashe5a ely bktbo dah yalahway bed 3'anam 2a2ra3 w negs w bydrab 3ashara f bo2oh yaC'ata fash5 16 like f ess ya mtnaken m7dsh y3rf ygebaha ya wlad l وثخه ya m3rثen
A pointer is just an variable that points to a location in the proccess memory. If you want to access data of a pointer then you use * for that.

Code:
int a = 0;
int * b = &a;
*b = 2;
Now you edit a to 2, you get the address of a varible by using &.

That was it, btw an address is 4 bytes, its an unsigned long ( DWORD ).
You also can point to a function or a class.
I think by random numbers, you mean hex decimals
google Hex Decimals, thats how i learned about them
Quote Originally Posted by DaRk View Post
I think by random numbers, you mean hex decimals
google Hex Decimals, thats how i learned about them
no he means random number generating
like rand()%100+1 for example generates a random number between 1 and 100
Posts 1–15 of 23 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us