HelpAssault Cube Hack!

Posts 1–15 of 16 · Page 1 of 2
Assault Cube Hack!
Hi There MPGH

Im fairly new to the whole coding thing and i thought i would learn some basic things in visual basic!
It started out great i made alot of newbie programs and then i moved on, i succesfully created alot of mw3 trainer features
and i made alot of other stuff

Now i have a problem, i thought i would do some unlimited ammo, unlimited health and that kind of stuff
for Assault Cube. the thing is when i found the static adress for ammunation and i paste it in my coding and then debug
the program and press the button the game gives me an error and crashes?

it works great when i change the value in CE but not in my trainer? you have any idea of what ive could have made wrong?

Here is a picture of my error




Also here is the very simple code!
Code:
Public Class Form1
    Dim AC As New Trainer
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        AC.Hack("ac_client")
        AC.SetInt(&H4DF73C, Value:=1000)
    End Sub
End Class
and the trainer.vb

Code:
Imports System.Runtime.InteropServices

Public Class Trainer
    <Flags()> _
    Public Enum ProcessAccessType
        PROCESS_TERMINATE = (&H1)
        PROCESS_CREATE_THREAD = (&H2)
        PROCESS_SET_SESSIONID = (&H4)
        PROCESS_VM_OPERATION = (&H8)
        PROCESS_VM_READ = (&H10)
        PROCESS_VM_WRITE = (&H20)
        PROCESS_DUP_HANDLE = (&H40)
        PROCESS_CREATE_PROCESS = (&H80)
        PROCESS_SET_QUOTA = (&H100)
        PROCESS_SET_INFORMATION = (&H200)
        PROCESS_QUERY_INFORMATION = (&H400)
    End Enum
    <DllImport("kernel32.dll")> _
    Public Shared Function OpenProcess(ByVal dwDesiredAccess As UInt32, ByVal bInheritHandle As Int32, ByVal dwProcessId As UInt32) As IntPtr
    End Function
    <DllImport("kernel32.dll")> _
    Public Shared Function CloseHandle(ByVal hObject As IntPtr) As Int32
    End Function
    <DllImport("kernel32.dll")> _
    Public Shared Function ReadProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, <[In](), Out()> ByVal buffer As Byte(), ByVal size As UInt32, ByRef lpNumberOfBytesRead As IntPtr) As Int32
    End Function
    <DllImport("kernel32.dll")> _
    Public Shared Function WriteProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As IntPtr, <[In](), Out()> ByVal buffer As Byte(), ByVal size As UInt32, ByRef lpNumberOfBytesWritten As IntPtr) As Int32
    End Function


    Public Function Hack(ByVal Application As String) As Boolean
        Dim pArray As Process() = Process.GetProcessesByName(Application)
        If pArray.Length = 0 Then
            Return True
        End If
        ReadProcess = pArray(0)
        Open()
        Return False
    End Function

    Public Sub SetInt(ByVal Address As Integer, ByVal Value As Integer)
        Dim byteswritten As Integer
        Write(Address, BitConverter.GetBytes(Value), byteswritten)
    End Sub


    Public Sub SetByte(ByVal Address As Integer, ByVal Value As Byte())
        Dim byteswritten As Integer
        Write(Address, Value, byteswritten)
    End Sub


    Private Property ReadProcess() As Process
        Get
            Return m_ReadProcess
        End Get
        Set(ByVal value As Process)
            m_ReadProcess = value
        End Set
    End Property
    Private m_ReadProcess As Process = Nothing
    Private m_hProcess As IntPtr = IntPtr.Zero
    Private Sub Open()
        Dim access As ProcessAccessType
        access = ProcessAccessType.PROCESS_VM_READ Or ProcessAccessType.PROCESS_VM_WRITE Or ProcessAccessType.PROCESS_VM_OPERATION
        m_hProcess = OpenProcess(CUInt(access), 1, CUInt(m_ReadProcess.Id))
    End Sub
    Private Sub CloseHandle()
        Dim iRetValue As Integer
        iRetValue = CloseHandle(m_hProcess)
        If iRetValue = 0 Then
            Throw New Exception("CloseHandle failed")
        End If
    End Sub
    Private Sub Write(ByVal MemoryAddress As IntPtr, ByVal bytesToWrite As Byte(), ByRef bytesWritten As Integer)
        Dim ptrBytesWritten As IntPtr
        WriteProcessMemory(m_hProcess, MemoryAddress, bytesToWrite, CUInt(bytesToWrite.Length), ptrBytesWritten)
        bytesWritten = ptrBytesWritten.ToInt32()
    End Sub

End Class
Thank you for reading, i would realy appriciate if someone could help me!
Thanks
weird.jpg128 KB · 13 downloads
You need to check the Protection (Read_Only, Read_Write, Read_Write_Execute, etc) of the address you're writing to. Basically the process's memory is divided up into chunks, and each chunk has access rights associated with it. If that chunk (all addresses inside the same chunk have to have the same protection rights) isn't Writeable, I'm pretty sure the OS will throw an exception.
Surround the code in a TRY block, and you can easily get a better error message.
For example:
Code:
Try
WriteBytes(hProcess,.......)
Catch ex as Exception 'ex is the variable's name, it can be anything you want. ex is standard.
MsgBox("Hack->WriteBytes ERROR" & Environment.NewLine & ex.Message)
End Try
Anyway, you need the API VirtualQueryEx() to check an address's access rights, and the API VirtualProtectEx() to set the rights to whatever you want. (Warning: Games can totally detect this, be careful, possible ban if they monitor that address. I hightly recommend restoring the original access rights and if possible, original data, when finished.

(if you will restore old rights: ByRef is important. VirtualQueryEx(processHandle,address,BYREF oldAccessRights)

Then you need the enum for possible proteciton values (read_write, execute_r_w, execute_r, etc).

so you check if it's Write-able, and if it's not, there is an API to change the access rights. VirtualProtectEx()

VirtualProtectEx(procesHandle, addr, _newRights) or something close to that. It returns a value, be sure to check that it succeeded! if you're admin, it should.

so now that it's writeable, write to it.
Then change it back to it's original access rights (you don't have to, but I think you should* unless you plan to write to that addr again soon??)

*note. ByRef is important if you want to restore the original rights when you're done. You have to create a variable, and pass it into the VirtualQueryEx() function, and it will set your variable to the old access rights. ByRef is basically a way for functions to returns 2 variables (kind of) - hope you understand byref.

API Declarations
Code:
 Private Declare Function VirtualQueryEx Lib "kernel32.dll" (ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, ByRef regionInfo As MEMORY_BASIC_INFORMATION, ByVal dwLength As UInt32) As Int32
    Private Declare Function VirtualAllocEx Lib "kernel32.dll" (ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, ByVal dwSize As UInt32, ByVal flAllocationType As MemoryAllocationState, ByVal flProtect As MemoryAllocationProtectionType) As IntPtr 'you will use this later probably :)
    Private Declare Function VirtualProtectEx Lib "kernel32.dll" (ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, ByVal dwSize As IntPtr, ByVal flNewProtect As UInt32, ByRef lpfoldProtect As UInt32) As Boolean
Structures / Enums
Code:
    Private Structure MEMORY_BASIC_INFORMATION
        Dim BaseAddress As IntPtr
        Dim AllocationBase As IntPtr
        Dim AllocationProtect As UInt32
        Dim RegionSize As IntPtr
        Dim State As UInt32
        Dim Protect As UInt32
        Dim zType As UInt32 ''renamed from Type because of vb.net keyword naming conflict
    End Structure

    Private Enum MemoryAllocationProtectionType As UInt32 'a bitmask // can store multiple values at once
        PAGE_NOACCESS = &H1
        PAGE_READONLY = &H2
        PAGE_READWRITE = &H4
        PAGE_WRITECOPY = &H8
        PAGE_EXECUTE = &H10
        PAGE_EXECUTE_READ = &H20
        PAGE_EXECUTE_READWRITE = &H40
        PAGE_EXECUTE_WRITECOPY = &H80
        PAGE_GUARD = &H100
        PAGE_NOCACHE = &H200
        PAGE_WRITECOMBINE = &H400
        PAGE_CANREAD = PAGE_READONLY Or PAGE_READWRITE Or PAGE_EXECUTE_READ Or PAGE_EXECUTE_READWRITE
        PAGE_CANEXECUTE = PAGE_EXECUTE Or PAGE_EXECUTE_READ Or PAGE_EXECUTE_READWRITE Or PAGE_WRITECOPY
        PAGE_CANWRITE = PAGE_READWRITE Or PAGE_EXECUTE_READWRITE '
    End Enum
Snippet
Code:
....
Dim _origAccessRights as Uint32 ' because mem_basic_info .Protect is UInt32. remember it's a bitmask.
Dim _mbiSize as int32 = System.Runtime.InteropServices.Marshal.SizeOf(New MEMORY_BASIC_INFORMATION) 'this won't change. you should only call it once (in the class constructor ofc) and save it as a private variable. I include it hear for clarity.
It's the size (in bytes) that a variable (of memory_basic_info) takes up in ram. somewhere around 28 I think. Depends on your computer hardware and OS (32 bit vs 64 bit)
Dim _mbi as MEMORY_BASIC_INFORMATION
VirtualQueryEx(_targetProcessHandle, sourceLoc, _mbi, _mbiSize) ''mbisize: a lot of api needs to know the size/length of data (length of string to copy, size of array, etc) Marshal is very helpful memory class. 
If Not _mbi.Protect and MemoryAllocationprotectionType.Page_CANWRITE Then
'the addr is read-only, we need to make it write-able
If _mbi.Protect And MemoryAllocationProtectionType.PAGE_CANEXECUTE Then
                        'it was originally executaly ram loc, it should remain executable! or target process can/will crash/throw exception. 
                        If VirtualProtectEx(_targetProcessHandle, _mbi.BaseAddress, _mbi.RegionSize, MemoryAllocationProtectionType.PAGE_EXECUTE_READWRITE, _origAccessRights) Then
                            DoOutput("executePatching 0x" & _addr.ToString("X")) 'success
                        Else
                            DoOutput("executePatching 0x" & _addr.ToString("X") & " FAIL?" & Environment.New & "VirtualProtectEx couldn't change access rights on that address. Are you admin account? Program Run as Admin?")
                        End If
                    Else
                        If VirtualProtectEx(_targetProcessHandle, _mbi.BaseAddress, _mbi.RegionSize, MemoryAllocationProtectionType.PAGE_READWRITE, _origAccessRights) Then
                            DoOutput("readPatching 0x" & _mbi.BaseAddress.ToString("X")) 'success
                        Else
                            DoOutput("readPatching 0x" & _mbi.BaseAddress.ToString("X") & " FAIL?" & Environment.New & "VirtualProtectEx couldn't change access rights on that address. Are you administraotr? Program Run as Admin?")
                        End If
                    End If
End If
...
DoOuput is just a public sub on my main form (Form1) that takes a msg and adds it to a txt box on the form (ie. debugging info)
ie. Public Sub DoOput(Byval msg as String)
     txtOutput.AppendLine("[" & date.now.toshortstring & "]" & msg) or something similar.
     ''todo: check .TextLength, if it's too long, it'll be a memory hog, use string split and get ride of the first half (oldest data)
End Sub
you could replace it with MsgBox i guess, or DebugConsole.WriteLine() or something close to that.

to restore original access rights (or, maybe you really do want to leave it execute_read-write? depends on your needs)
it's as simple as
        If _origAccessRights <> 0 Then
            VirtualProtectEx(_targetProcessHandle, _mbi.BaseAddress, _mbi.RegionSize, _origAccessRights, New Int32) ''regionSize can be just 4 or 2 or however many bytes you change. the os knows that all address in a chunk have to have same rights, so it will figure out region size for you. Using it explicitly is better imo.
   'New Int32 is basically saying, create a new variable, but without a name, cuz i'll never use it.
   'because we know it's current rights are execute_read_write (or read_write) and don't really care, we already wrote our bytes to the process. Just restore the rights, and we won't need the _oldAccessRights again. we're basically done. ?
        End If
code snippet is incomplete: if virtualprotect fails, you should somehow exit the sub/function and probably not call writebytes(). maybe.

Hope this helps.

Try some debugging.

1. Check the Protection of the address in question. use msgbox. Is it writeable? Chances are if it's game code, no.
2. If it's not WriteAble, try to call VirtualProtectEx() and be sure to check it's return value.
haha i realy like that your answering in such a developed answer!
i tried to fix it with all the solutions and managed to get no errors in the VB
but still it doesnt work!
it looks pretty advanced, maybe abit to advanced for me!
dont think i should try to make trainers like this!

Thanks anyways mate
Cheers
what is the exception message --> ex.message

Are you done trying then?
Yes thank you sir, im done trying!
Please take the code and make a hack if you want to, im cool with that

By the way? you got skype so we could chat there?
i have some questions and you seem to be a nice guy

Cheers
I don't have skype. Haven't used instant messaging in a while. Tired of working on projects by myself, and wanting to get into new games; if you seriously want to learn to program, yeah I'll help. At some point I won't have the answers, and then I expect your help to do research also haha. but really. Maybe I'll download a chat client soon. It's late here, logging off (relatively) soon.



edit: I misread your post. I assumed the mem address you write to was for patching assembly code, but you're just trying to write a new value to your bullets, so the memory loc is probably writeable, that probably isn't the problem.
The .exe isnt the problem, alteast it wasnt the problem when i made my MW3 Trainers.
Then i used: iwp3
as proccessname

I have no idea what could be the problem, i dont realy get what API means and all that stuff, if you dont bother
you could download Assault Cube (Its 50MB big)
and then add the source code into a visual basic project and test some to get it work?

Cheers
1 more try...

I guess I didn't read most of your source code..here are a few comments/suggestions/things I do:

API
Code:
    Private Declare Function OpenProcess Lib "kernel32.dll" (ByVal dwDesiredAcess As UInt32, ByVal bInheritHandle As Boolean, ByVal dwProcessId As Int32) As IntPtr
Your subs Open and Hack are flawed. You don't actually check that OpenProcess was successful.
Also Hack returns True if the process isn't found :/ is opposite of what is normal/expected.
Also, check how the process name shows up in taskmanager (ctrl+alt+del) maybe you need .exe on the end? Easiest way is the window title (ie. caption, "AssaultCube")

maybe try finding the process by it's Window's Title (this isn't as good when the game is in multiple languages)
for Hack() try this..
Code:
If aProcess.MainWindowTitle. = "AssaultCube" Then
                'found correct process, proceed.
End If
( I misread your post. I assumed the mem address you write to was for patching assembly code, but you're just trying to write a new value to your bullets. so the memory loc is probably writeable, that probably isn't the problem)

your Hack() function is weird: you return true when there is an error. This is the opposite of normal. Normally you return True on success. and false on failure.
was
Code:
   Public Function Hack(ByVal Application As String) As Boolean
        Dim pArray As Process() = Process.GetProcessesByName(Application)
        If pArray.Length = 0 Then
            Return True
        End If
        ReadProcess = pArray(0)
        Open()
        Return False
    End Function
should be
Code:
  ''plz move API's and local variable (ie. m_hProcess and m_ReadProcess to top of class, so we know they exist beforehand. they're important enough :)
 Private Declare Function OpenProcess Lib "kernel32.dll" (ByVal dwDesiredAcess As UInt32, ByVal bInheritHandle As Boolean, ByVal dwProcessId As Int32) As IntPtr ' 

   Public Function Hack(ByVal appWindowTitle As String) As Boolean
        Dim pArray As Process() = Process.GetProcesses()
        For each pp as Process in _pArray
        If pp.MainWindowTitle.ToLower.Contains("assaultcube") Then ''hardcoded string for specific debuggin purposes. ignore appWindowTitle parameter for now
        'found correct process.
        m_ReadProcess = pp 'assume the game can not be running twice. some can/will. you may want another window with the same name!
          m_hProcess = OpenProcess(Convert.ToUInt32(ProcessAccessType.PROCESS_VM_READ Or ProcessAccessType.PROCESS_VM_WRITE Or ProcessAccessType.PROCESS_VM_OPERATION), False, m_ReadProcess.Id)
       If m_hProcess = IntPtr.Zero then
        'open process failed. this is weird and normally doesn't happen. are you admin?
        MessageBox.Show("OpenProcess Failed. Are you admin?")
        return false
       Else
       'success. We can call rpm and wpm now!
          Return True     'if  we get here, OpenProcess worked. We should be ok to call WriteProcessMemory   
       End if               
      Next pp
    ''if we get here, the process wasn't found in the whole array of processes, we should return false
   Return false ''its weird seeing this at the very end of a function. just how the logic is arranged sometimes. This happens when the user ran the hack without the game being open/fully logged in.
End Function
and change
Code:
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        AC.Hack("ac_client")
        AC.SetInt(&H4DF73C, Value:=1000)
    End Sub
to
Code:
    Private Sub Button1_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Button1.Click
        IF AC.Hack("AssaultCube") = True Then
        'OpenProcess call successful. Ready to writebytes.
        AC.SetInt(&H4DF73C, 1000) ' you should also check lpNumberOfBytesWritten to verify WriteProcessMemory wrote enough (all) bytes. it should work if OpenProcess worked
        MessageBox.Show("Hack SUCCESS! bullets now == 1000 ?!")
        Else
        MessageBox.Show("Unable to attach to process. hmmm.") ' lol
        End If

    End Sub
'don't use Value:= when calling a function. I've used < 1 time. It might be some other language feature, not needed for a regular simple function call. Technically SetInt() is a Sub, you might want to rename it to WriteInt32 and make it return a value of success/fail if WriteProcessmemory fails when it's called. Should generally work 99% of the time though.
also, you may need to declare the ProcessAccessType as Uint32, I think default is Int32? maybe not important?
^^I could be wrong for 64 bit OS stuff, I don't have one so I can't test. This only tested on windows xp sp3 32 bit.

edit: In OpenProcess() I'm not 100% sure as to why, but inheritHandle ...ive always seen it set to false. you have 1. that might be important?! Try it as false --> and change the API declaration to expect a boolean, not an Integer

also: not sure if/why its correct, but it works for me: the third parameter of OpenProcess(), You don't have to convert process.Id to Uint. Leave it Int32.


Maybe in those last 2 comments, if you are on 64 bit, it might not be Int32 but just Integer (which for .net, on x64, is 64 bits not int32) Try it as what I have, and we'll go from there. What hardware/os are you on?


assuming this works, we need to add CloseHandle() to prevent a small memory leak cuz the OS thinks we still might use the handle eventually. we'll get to that if this even works for you.

I may download the game just to test if my personal code works haha.

-also, I've heard of some games that have more than 1 process, so sometimes you might not want the one that has a window (seems odd, the game makers do try to confuse us once in a while).
---------- Post added at 02:27 PM ---------- Previous post was at 02:06 PM ----------

changing the control structure a little (does the exact same thing: or should)
Code:
Public Function Hack(ByVal appWindowTitle As String) As Boolean
        Dim pArray As Process() = Process.GetProcesses()
        For each pp as Process in _pArray
        If pp.MainWindowTitle.ToLower.Contains("assaultcube") Then ''hardcoded string for specific debuggin purposes. ignore appWindowTitle parameter for now
        'found correct process.
        m_ReadProcess = pp 'assume the game can not be running twice. some can/will. you may want another window with the same name!
        Exit For 'don't keep checking other processes, we founds our already. Go to end of the loop and continue code execution there. (..loops)       
      Next pp
       
    If m_ReadProcess = Nothing Then
      'process not found.
      Return False
    Else
      m_hProcess = OpenProcess(Convert.ToUInt32(ProcessAccessType.PROCESS_VM_READ Or ProcessAccessType.PROCESS_VM_WRITE Or ProcessAccessType.PROCESS_VM_OPERATION), False, m_ReadProcess.Id)
       If m_hProcess = IntPtr.Zero then
        'open process failed. this is weird and normally doesn't happen. are you admin?
        MessageBox.Show("OpenProcess Failed. Are you admin?")
        return false
       Else
       'OpenProcess success. We can call rpm and wpm now!
          Return True    
       End if  
   End If
End Function
'more readable?
not sure if it matters but also change to this ('type As Uint32 after your struct name)
Code:
Private Enum MemoryAllocationProtectionType As UInt32
        PAGE_NOACCESS = &H1
        PAGE_READONLY = &H2
        PAGE_READWRITE = &H4
        PAGE_WRITECOPY = &H8
        PAGE_EXECUTE = &H10
        PAGE_EXECUTE_READ = &H20
        PAGE_EXECUTE_READWRITE = &H40
        PAGE_EXECUTE_WRITECOPY = &H80
        PAGE_GUARD = &H100
        PAGE_NOCACHE = &H200
        PAGE_WRITECOMBINE = &H400
        PAGE_CANREAD = PAGE_READONLY Or PAGE_READWRITE Or PAGE_EXECUTE_READ Or PAGE_EXECUTE_READWRITE
        PAGE_CANEXECUTE = PAGE_EXECUTE Or PAGE_EXECUTE_READ Or PAGE_EXECUTE_READWRITE Or PAGE_WRITECOPY
        PAGE_CANWRITE = PAGE_READWRITE Or PAGE_EXECUTE_READWRITE
    End Enum

edit: if you can get it to compile and run, and tell me which msgbox() runs, I can maybe help you debug more.

(I downloaded game: ac_client 1.2, started CE, found "current clip count" after 2-3 tries of shot a bullet/update search amount. Found 2 address for 'current clip count.' I went with the first one. (can try second one later maybe)

added a new button to an existing bot project I have (99.99% just like the code I posted above)
Code:
    Private Sub AttachToolStripMenuItem_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles AttachToolStripMenuItem.Click
        If MEMMGR.Attach("AssaultCube") Then
            DoOutput("Attach OK - ready.")
            MEMMGR.WriteInt32(New IntPtr(Integer.Parse("08E5A72C", Globalization.NumberStyles.HexNumber)), 30) '30 is a good clip size
        Else
            DoOutput("Attach FAIL - unable to continue")
        End If
    End Sub
'works. Even if my original clip size was smaller than 30, apparently any int32 value written to that address will auto update-bullet count and max clip size -- No idea what kind of anti-cheat system (if any) the game uses!
^^ basically 2 lines of code: .Attach() and .WriteInt32.

the address will probably change every time the game loads, or probably even between map loads. There are ways to figure out which address it will be at. You also have to deal with aslr if you're on windows > xp. I <3 xp on my 2.8 pentium4 ht, 2g ram.
@akke92
NONONO. you're doing it wrong.

Download the crossfire source code and C++, edit it, you can do far more things.

so far, i've gotten: Unlimited Ammo, walk through walls, no recoil + spread, fly hack, one hit kill (even with that crappy pistol) and i'm currently working on a teleport.
Quote Originally Posted by Raow View Post

C++.... do far more things..
Please elaborate.
Quote Originally Posted by abuckau907 View Post
Please elaborate.
No elaboration needed.
all you have to do is download C++ and edit the Assault cube source code.
Need , "0,14,378" Offset
ok just try this a friend of mine made this it has a unlimited ammo and the unlimited amor doesnt not work online only unlimited ammo have fun http://www.mediaⓘ fire.com/?20yc94o5ed2of2c u need winrar to extract it
Quote Originally Posted by Raow View Post
No elaboration needed.
all you have to do is download C++ and edit the Assault cube source code.
what is a c++ and how can i get twice as much of it?
Posting download links like that is probably against the rules (no Anti Virus scans), but thanks for sharing I guess.
Posts 1–15 of 16 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us