CoolEASY MEMORY CHECK BYPASS !!!

Posts 1–15 of 18 · Page 1 of 2
EASY MEMORY CHECK BYPASS !!!
Hey so finally I got it working without a hook like I released before so it is easier to use... it is not a good signature scan I just did it in a minute but the addy is just for EU and I am also not sure if they use different memory checks in the NA version

just copy this to your source and you can use your memory hacks all the time you will not crash if you start a game or when you respawn

Code:
#define memcheckbreaker 0x379C21D0 //for CA EU !!!
DWORD memcheck = dwFindPattern((DWORD)CShell, 0x900000, (PBYTE)"\xFF\x34\x24\x5B\x81\xC4\x04\x00\x00\x00\xC3", "xxxxxxxxxxx") + 0x04;
MemoryEdit((void *)memcheck, (void *)"\x58\xB8\x01\x00\x00\x00",6);
how it works:
so it is the end of the check function and it has to return true so that you do not crash... so it moves 1 to the eax register like in the hook I released before... in the end of the check function there is an add esp, 4 that takes 6 bytes I replaced the first byte with a pop eax so that the esp increases by 4 and so I got enough place for the instruction mov eax, 1 (5 bytes)

I hope I can help some people with this
Hehe nice1
But a simple hook in function start and return true is easier in my opnion lol

EDIT: How did you found it? My way wasnt really nice
Code:
379C218F   /.  55                            PUSH EBP
I think that this is not the start of the function... so I just checked with a hardware breakpoint where they access the addys and check their bytes, they do it here:
Code:
379C1F8C::  add     al, [ebx]
so the function starts earlier, but I do not hook it in the beginning because many addys and register are changed in this function and when I skip all of them it crashes, but a hook in the end works
Nice find, hopefully this doesn't get detected
Is this for the scan that they do when you die? If so, I tried it and it didn't work.
yes it is and for me it works... are you playing na or eu? ...did you check if the sig scan finds an address?
Quote Originally Posted by BadBurrito View Post
yes it is and for me it works... are you playing na or eu? ...did you check if the sig scan finds an address?
No I didn't. I'm on NA.
hmmm ok I think the sig scan is the problem I just tried it on an old dump of cshell and it did not work, I try to get a working one... the current sig scan obviously just works for the current eu version...

---------- Post added at 12:49 PM ---------- Previous post was at 11:58 AM ----------

So I just checked old dumps and found the address manually but the function changed a lot during the last updates... so I think a signature scan is not senseful I am sorry but this is just working for EU at the moment!!! ...but if someone who plays NA wants to get it I can help but I do not have any NA files sorry...
Scan works fine for me, just logged it for na

Code:
#define RespawnPatch		0x379CEB5F
/Edit, tested and works like a charm
Quote Originally Posted by arun823 View Post
Scan works fine for me, just logged it for na

Code:
#define RespawnPatch		0x379CEB5F
@BadBurrito

/Edit, tested and works like a charm I'll post like a 10 second video of it working.
Yup works for me as well. Really good works. Figured out my error also, scan is working perfect.

Thanks
LOL im Just asking myself how did you debugged CA to get all functions accesing the pointer? o_0

Also your Mask is wrong! Real mask: xxxxxx????x then sig will work lol, why did you failed on making mask?
I just did not care for the mask but thanks ... I just coded a dll that sets hardware breakpoints and then injected it into engine.exe
and thanks arun823 for the NA address
I didn't read whole posts, but if anyone want to know how he get it, he it's probably by attaching cheat engine debugger and seeing what accesses to a VA address in .text section of CShell. When you enter in game, it get accessed by this part of code. I already had it since CA implemented it.
Anyway, good job, atleast someone get it. That's how I do it : (ca eu)

Code:
DWORD addressToPass_CShell;
BYTE CRCBYTE_CSHELL;
DWORD dwCRCCheck_HookStart = 0x379C1F85;
DWORD dwCRCCheck_JMPBack = 0x379C1F8E;
__declspec(naked) void __cdecl hkCRCCheck()
{
__asm mov ebx, 0;
__asm add ebx, edx; //here ebx contain address which is getting scanned
__asm mov addressToPass_CShell, ebx;
__asm pushad; //savin stack
__asm pushfd; //savin also flags

//example..
	if(addressToPass_CShell == dwNameTags1)
	{
		CRCBYTE_CSHELL = NAMETAGS1BYTES[0];
		goto JmpPoint;
	}
//end of example..

__asm popfd;
__asm popad;
__asm add al, byte ptr ds:[ebx];
__asm jmp dwCRCCheck_JMPBack;

JmpPoint:
__asm popfd;
__asm popad;
__asm add al, CRCBYTE_CSHELL;
__asm jmp dwCRCCheck_JMPBack;

}
@ nametagS1BYTES, memcpy inside an array of byte of 2 contains @ nametags first address.

Anyway, this CRC check is not good. Most of assembly operation in this part of code is themidalicense junkcode. Yes, there is code mutation of oreans software. I guess what you would do if there was a virtualmachine
Quote Originally Posted by disav0w_ View Post
I didn't read whole posts, but if anyone want to know how he get it, he it's probably by attaching cheat engine debugger and seeing what accesses to a VA address in .text section of CShell. When you enter in game, it get accessed by this part of code. I already had it since CA implemented it.
Anyway, good job, atleast someone get it. That's how I do it : (ca eu)

Code:
DWORD addressToPass_CShell;
BYTE CRCBYTE_CSHELL;
DWORD dwCRCCheck_HookStart = 0x379C1F85;
DWORD dwCRCCheck_JMPBack = 0x379C1F8E;
__declspec(naked) void __cdecl hkCRCCheck()
{
__asm mov ebx, 0;
__asm add ebx, edx; //here ebx contain address which is getting scanned
__asm mov addressToPass_CShell, ebx;
__asm pushad; //savin stack
__asm pushfd; //savin also flags

//example..
	if(addressToPass_CShell == dwNameTags1)
	{
		CRCBYTE_CSHELL = NAMETAGS1BYTES[0];
		goto JmpPoint;
	}
//end of example..

__asm popfd;
__asm popad;
__asm add al, byte ptr ds:[ebx];
__asm jmp dwCRCCheck_JMPBack;

JmpPoint:
__asm popfd;
__asm popad;
__asm add al, CRCBYTE_CSHELL;
__asm jmp dwCRCCheck_JMPBack;

}
@ nametagS1BYTES, memcpy inside an array of byte of 2 contains @ nametags first address.

Anyway, this CRC check is not good. Most of assembly operation in this part of code is themidalicense junkcode. Yes, there is code mutation of oreans software. I guess what you would do if there was a virtualmachine
Very nice method, this could be an alternative if BadBurrito's method gets detected.
When gamestatus differs from 1, do we have to restore the original bytes?
Posts 1–15 of 18 · Page 1 of 2
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us