2Questions

Posts 1–15 of 17 · Page 1 of 2
2Questions
So I will download Visual Studio to use C++ and to have VB and C# and everything , but I don't know which is better and which i should use?....

The second question is : When I make a dll to write memory process and read it should I use WriteProcessMemory() or what ? because I've seen many tutorials but all of them use WriteProcessMemory() , and give me an example of dll....

Thanks for reading...
Quote Originally Posted by [D]opeDog View Post
So I will download Visual Studio to use C++ and to have VB and C# and everything , but I don't know which is better and which i should use?....

The second question is : When I make a dll to write memory process and read it should I use WriteProcessMemory() or what ? because I've seen many tutorials but all of them use WriteProcessMemory() , and give me an example of dll....

Thanks for reading...
1. Pick the language that suits your needs best. Every language is created for a specific purpose, and has its ups and downs. Everyone will have their own opinion on which language is 'best' for anything, and remember it is just their opinion. If you want opinions, I suggest learning C/C++ and avoiding VB.NET entirely. C# is a great managed language to learn as well. If you understand C syntax, moving to C# will be very easy as it is very similar.

2. If you are injected, use memset/memcpy, or direct address access. There is no need to use ReadProcessMemory / WriteProcessMemory when you are injected, it is just overhead to use them.
Quote Originally Posted by atom0s View Post
1. Pick the language that suits your needs best. Every language is created for a specific purpose, and has its ups and downs. Everyone will have their own opinion on which language is 'best' for anything, and remember it is just their opinion. If you want opinions, I suggest learning C/C++ and avoiding VB.NET entirely. C# is a great managed language to learn as well. If you understand C syntax, moving to C# will be very easy as it is very similar.

2. If you are injected, use memset/memcpy, or direct address access. There is no need to use ReadProcessMemory / WriteProcessMemory when you are injected, it is just overhead to use them.
But , can you give me an example of memset and memcpy? so memcpy is read it and memset is write it , but please give me an DLL Code Example with GetModuleHandle
There are plenty of examples of both online. Just look instead of begging for source. Also like I said you can read/write the memory directly (assuming it's not protected) which can be more efficient then memcpy/memset as well.
Quote Originally Posted by atom0s View Post
There are plenty of examples of both online. Just look instead of begging for source. Also like I said you can read/write the memory directly (assuming it's not protected) which can be more efficient then memcpy/memset as well.
That's why I came here , all what I see as an dll example is Write Process Memory ...

Only 1 I found and the method isn't memcpy or memset and It is like that :

Code:
unsigned long address = ClientOffset + pointer;
	if (IsBadReadPtr((void*)address, 4) != NULL) return;// It is already disabled
	address = *(unsigned long*)address + offset1;
	if (IsBadWritePtr((void*)address, 4) != NULL) return;

	// Here you reset the address

	*(int*)address = 0;// int = 4 bytes
And that method would be proper and valid inside a DLL.

(Keep in mind IsBadReadPtr / IsBadWritePtr are insecure and not recommended to be used as well.)
Quote Originally Posted by atom0s View Post
And that method would be proper and valid inside a DLL.

(Keep in mind IsBadReadPtr / IsBadWritePtr are insecure and not recommended to be used as well.)
Isn't it used to avoid crashes?
Yes but they can cause crashes themselves as well as returning invalid results.

As seen on the MSDN page for them:
Important This function is obsolete and should not be used. Despite its name, it does not guarantee that the pointer is valid or that the memory pointed to is safe to use. For more information, see Remarks on this page.
If you absolutely need to test memory locations, learn how to use exceptions to catch faulty reads/writes.
Quote Originally Posted by atom0s View Post
Yes but they can cause crashes themselves as well as returning invalid results.

As seen on the MSDN page for them:


If you absolutely need to test memory locations, learn how to use exceptions to catch faulty reads/writes.
Ok , The code which i posted seems to work with An Injected DLL without IsBadReadPtr , right?
Assuming the memory is readable/writable.

You can use VirtualQuery to determine the access of the memory, then use VirtualProtect to alter the protections if needed.
Quote Originally Posted by atom0s View Post
Assuming the memory is readable/writable.

You can use VirtualQuery to determine the access of the memory, then use VirtualProtect to alter the protections if needed.
Yeah , It is readable and writable so I will use the first code...

Also I need to ask another question : as I can't use Windows.h functions in Windows Form Application , how could I use memcpy If I do not want to use the first code? could you give me an example of using it with this pointer and this offset :
Example : The pointer in Cheat Engine is "AVA.exe" + 0xdaaaaa (anything just as an example ) with one offset which is 0x90 , how it would be in mem cpy?
Do you mean you are using Visual C++ as in managed C++?

If so then use the Marshal class. It has similar methods to memset and memcpy.
Quote Originally Posted by atom0s View Post
Do you mean you are using Visual C++ as in managed C++?

If so then use the Marshal class. It has similar methods to memset and memcpy.
See this : http://www.mpgh.net/forum/31-c-c-pro...plication.html

Some one said in this thread :The best way, in my experience, to use managed and unmanaged code in the same application is by building an unmanaged dll and exporting the functions you need to your managed application. Next you build a wrapper that can cleanly handle the exceptions in the dll and you're set.

I don't know how to build managed and unmanaged , I mean : I don't know what is managed and unmanaged and how i will build a wrapper ...

If you didn't know what I meant :

I want to use in my form application : windows.h to use Open Process and etc .... but I can't use windows.h in it that's why ...
Honesty you should just pick one or the other. Either stick to a managed language, or stick to a native one.
Everything you want to do can be done in pure C++ with no managed requirements.

As for not being able to use Windows.h no idea, without seeing your code/project I can't say why you are having issues.
Quote Originally Posted by atom0s View Post
Honesty you should just pick one or the other. Either stick to a managed language, or stick to a native one.
Everything you want to do can be done in pure C++ with no managed requirements.

As for not being able to use Windows.h no idea, without seeing your code/project I can't say why you are having issues.
I mean I don't know what is managed code and unmanaged code ...

Here is Form.1
Code:
#pragma once
#include "resource.h"
namespace AntiKRA1 {

	using namespace System;
	using namespace System::ComponentModel;
	using namespace System::Collections;
	using namespace System::Windows::Forms;
	using namespace System::Data;
	using namespace System::Drawing;

	/// <summary>
	/// Summary for Form1
	/// </summary>
	public ref class Form1 : public System::Windows::Forms::Form
	{
	public:
		Form1(void)
		{
			InitializeComponent();
			//
			//TODO: Add the constructor code here
			//
		}

	protected:
		/// <summary>
		/// Clean up any resources being used.
		/// </summary>
		~Form1()
		{
			if (components)
			{
				delete components;
			}
		}
	private: System::Windows::Forms::Button^  button1;
	protected: 
	private: System::Windows::Forms::Button^  button2;
	private: System::Windows::Forms::TextBox^  textBox1;
	private: System::Windows::Forms::TextBox^  textBox2;

	private:
		/// <summary>
		/// Required designer variable.
		/// </summary>
		System::ComponentModel::Container ^components;

#pragma region Windows Form Designer generated code
		/// <summary>
		/// Required method for Designer support - do not modify
		/// the contents of this method with the code editor.
		/// </summary>
		void InitializeComponent(void)
		{
			System::ComponentModel::ComponentResourceManager^  resources = (gcnew System::ComponentModel::ComponentResourceManager(Form1::typeid));
			this->button1 = (gcnew System::Windows::Forms::Button());
			this->button2 = (gcnew System::Windows::Forms::Button());
			this->textBox1 = (gcnew System::Windows::Forms::TextBox());
			this->textBox2 = (gcnew System::Windows::Forms::TextBox());
			this->SuspendLayout();
			// 
			// button1
			// 
			this->button1->BackgroundImage = (cli::safe_cast<System::Drawing::Image^  >(resources->GetObject(L"button1.BackgroundImage")));
			this->button1->Location = System::Drawing::Point(0, 0);
			this->button1->Name = L"button1";
			this->button1->Size = System::Drawing::Size(90, 32);
			this->button1->TabIndex = 0;
			this->button1->Text = L"Start - HOME";
			this->button1->UseVisualStyleBackColor = true;
			this->button1->Click += gcnew System::EventHandler(this, &Form1::button1_Click);
			// 
			// button2
			// 
			this->button2->BackgroundImage = (cli::safe_cast<System::Drawing::Image^  >(resources->GetObject(L"button2.BackgroundImage")));
			this->button2->Location = System::Drawing::Point(274, 0);
			this->button2->Name = L"button2";
			this->button2->Size = System::Drawing::Size(89, 32);
			this->button2->TabIndex = 1;
			this->button2->Text = L"Stop - END";
			this->button2->UseVisualStyleBackColor = true;
			this->button2->Click += gcnew System::EventHandler(this, &Form1::button2_Click);
			// 
			// textBox1
			// 
			this->textBox1->BackColor = System::Drawing::Color::LightSkyBlue;
			this->textBox1->Enabled = false;
			this->textBox1->ForeColor = System::Drawing::Color::Cyan;
			this->textBox1->Location = System::Drawing::Point(22, 177);
			this->textBox1->Name = L"textBox1";
			this->textBox1->Size = System::Drawing::Size(191, 21);
			this->textBox1->TabIndex = 2;
			this->textBox1->Text = L"Coded by [D]opeDog - MPGH.net";
			// 
			// textBox2
			// 
			this->textBox2->BackColor = System::Drawing::Color::Crimson;
			this->textBox2->Enabled = false;
			this->textBox2->ForeColor = System::Drawing::Color::Orange;
			this->textBox2->Location = System::Drawing::Point(255, 177);
			this->textBox2->Name = L"textBox2";
			this->textBox2->Size = System::Drawing::Size(100, 21);
			this->textBox2->TabIndex = 3;
			this->textBox2->Text = L"Long Live Egypt";
			// 
			// Form1
			// 
			this->AutoScaleDimensions = System::Drawing::SizeF(7, 13);
			this->AutoScaleMode = System::Windows::Forms::AutoScaleMode::Font;
			this->BackgroundImage = (cli::safe_cast<System::Drawing::Image^  >(resources->GetObject(L"$this.BackgroundImage")));
			this->ClientSize = System::Drawing::Size(367, 199);
			this->Controls->Add(this->textBox2);
			this->Controls->Add(this->textBox1);
			this->Controls->Add(this->button2);
			this->Controls->Add(this->button1);
			this->Font = (gcnew System::Drawing::Font(L"Tahoma", 8.25F, System::Drawing::FontStyle::Bold, System::Drawing::GraphicsUnit::Point, 
				static_cast<System::Byte>(0)));
			this->ForeColor = System::Drawing::Color::Lime;
			this->Icon = (cli::safe_cast<System::Drawing::Icon^  >(resources->GetObject(L"$this.Icon")));
			this->Name = L"Form1";
			this->Text = L"AVA-Hacks Pack v1.0";
			this->ResumeLayout(false);
			this->PerformLayout();

		}
#pragma endregion
	private: System::Void button1_Click(System::Object^  sender, System::EventArgs^  e) {

			 }
private: System::Void button2_Click(System::Object^  sender, System::EventArgs^  e) {
		 }
};
}

Anti-KRA1.cpp
Code:
// Anti-KRA1.cpp : main project file.

#include "stdafx.h"
#include "Form1.h"

using namespace AntiKRA1;

[STAThreadAttribute]
int main(array<System::String ^> ^args)
{
	// Enabling Windows XP visual effects before any controls are created
	Application::EnableVisualStyles();
	Application::SetCompatibleTextRenderingDefault(false); 
	// Create the main window and run it
	Application::Run(gcnew Form1());
	return 0;
}

So ... I gave you the code ... what I need?
1-A method to write to memory address and to read it...
2-and the pointer is : "AVA.exe" + 0x0000000 (as an example) and the offset is 0x90...
3-How will i do that?


---------- Post added 06-25-2013 at 12:48 AM ---------- Previous post was 06-24-2013 at 11:27 PM ----------

So I maid it in dll using the first code :


Code:
#include <windows.h>
#define pointer 0x00FA2510
#define offset 0x90
unsigned long ClientOffset;
void MemoryWrite(DWORD xAddress, int Value)//Write the integer value
{
  *(int*)xAddress = Value;
}
bool activated = false;

void TheThread()
{
	ClientOffset = (unsigned long)GetModuleHandleA("AVA.exe");
	unsigned long address = ClientOffset + pointer;
	address = *(unsigned long*)address + offset;
   while(true)//Keep the thread alive
   {
	   if(GetAsyncKeyState(VK_HOME)&0x8000) //The Hotkey to enable the function
	   {
       if(activated = false)
       {
           MemoryWrite(address, 5);//Memory write
		   activated = true;
       }
       Sleep(50);//Stop the loop from chewing the cpu
   }
	   else if(GetAsyncKeyState(VK_END)&0x8000){
		   if(activated = true)
		   {
		    MemoryWrite(address, 6);//Memory write 
		   activated = false;
		   }
	   }
	   }
}

BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved)
{
		DisableThreadLibraryCalls(hinstDLL);
   if (fdwReason == DLL_PROCESS_ATTACH)
   {
	   if(CreateThread(NULL, 0, (LPTHREAD_START_ROUTINE)TheThread, NULL, 0, NULL) == NULL)//Creates the thread
	   {
		   MessageBoxA(NULL , "Couldn't create a thread.", "Error", MB_OK | MB_ICONERROR);
		   return false;
	   }
   }
	   else if (fdwReason == DLL_PROCESS_DETACH)
	   {

	   }
    return TRUE;
}
But It isn't writing the value.... , but in the console application which uses WriteProcessMemory It works 100 %
Posts 1–15 of 17 · Page 1 of 2

Post a Reply

Tags for this Thread

None

Talk with us