HelpWhats wrong with this code?

Posts 1–11 of 11 · Page 1 of 1
Whats wrong with this code?
Hi.

I have a 2 offsetpointer.
The pointer is 100% working.
I try to change the value in CE (2Bytes). But the Game is Crashing while calling the function.
Whats wrong?

Code:
//////////////SPEED//////////////
#define BasePointer1 0x6C4F24
#define Points6 0x00000004
#define Points7 0x0000066e


DWORD val2 = 0;

bool State2 = false;   

void SetSpeedhack(){
	HANDLE hProc = OpenProcess(((0x000F0000L) | (0x00100000L) | 0xFFFF), 0xFFFFFF, (unsigned int)GetCurrentProcessId());

	DWORD wert1 = 0;
				RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)((int*)((BasePointer1))), sizeof((PDWORD)(BasePointer1))); 
				if(wert1 > 0){
				wert1+= Points6;
				RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)&(*(_Uint32t*)(wert1)), sizeof((PDWORD)(wert1)));
				wert1+= Points7;
				RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)&(*(_Uint32t*)(wert1)), sizeof((PDWORD)(wert1)));
	
			
				
				DWORD val1 = 16666;

				memcpy((PVOID*)(*(int*)(&wert1)), (PWORD*)((void*)&(*(_Uint32t*)&val1)), 2);
				}
				
}
Thank you really much!

Regards, SawMister
Quote Originally Posted by SawMister View Post
...
1) Is this being injected as a .dll?? I see you call OpenProcess(), but don't use the Handle returned.

The pointer is 100% working.
2)You mean wert1 is correct before the call to memcpy() ??

Code:
DWORD val1 = 16666;
memcpy((PVOID*)(*(int*)(&wert1)), (PWORD*)((void*)&(*(_Uint32t*)&val1)), 2);
Code:
WORD val1 = 16666; // WORD = 2 bytes, DWORD = 4 (for microsoft)
*(WORD*)wert1 = val1;
It still not working.
The code which was working with my other pointer (5 Offsets):


Code:
#define BasePointer 0x6EBE1C  
#define Points0 0x00000008  
#define Points1 0x000005dc
#define Points2 0x000002d8
#define Points3 0x00000000
#define Points4 0x0000018c

DWORD val = 0;

bool State = false;   

void punkte()    
{
    if(State)
    {
        DWORD wert = 0;
				
				HANDLE hProc = OpenProcess(((0x000F0000L) | (0x00100000L) | 0xFFFF), 0xFFFFFF, (unsigned int)GetCurrentProcessId());

				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)((int*)((BasePointer))), sizeof((PDWORD)(BasePointer))); 
					if(wert > 0){
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)((int*)((BasePointer))), sizeof((PDWORD)(BasePointer)));
					wert += Points0;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
					wert += Points1;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
					wert += Points2;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert))); 
					wert += Points3;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
					wert += Points4;
					memcpy((PVOID*)(*(int*)(&wert)), (PWORD*)((void*)&(*(_Uint32t*)&val)), 4);}

    }
}

DWORD WINAPI HackThread(LPVOID unused)
{
   
    for(; ;)  
    {
        punkte();  
        if(GetAsyncKeyState(VK_F2)){
			if(State){ State = false; }
			else{
				State = true;
				HANDLE hProc = OpenProcess(((0x000F0000L) | (0x00100000L) | 0xFFFF), 0xFFFFFF, (unsigned int)GetCurrentProcessId());

				DWORD wert = 0;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)((int*)(BasePointer)), sizeof((PDWORD)(BasePointer)));
				if(wert > 0){
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)((int*)(BasePointer)), sizeof((PDWORD)(BasePointer)));
				wert += Points0;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
				wert += Points1;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
				wert += Points2;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
				wert += Points3;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert)));
				wert += Points4;
				RtlCopyMemory((LPVOID)((void*)(&wert)), (PVOID*)&(*(_Uint32t*)(wert)), sizeof((PDWORD)(wert))); 
				val = wert;}
			}
		} 
        Sleep(2);
    }
}
I tried to get this working with my new pointer (2 offsets)..
Thank you.
Regards, SawMister
Is wert1 correct, or not? Apparently not, I tested the code.

^^Of course that's for my program's local memory, but same thing.

And How is it "not working"? ...If you don't have the correct baseAddress, and offsets, I can't help you. If it is correct, can you read 1...2...3..4.5 or however many, levels of pointers to get the final address? If you do, then the code example I posted will work. If you have the correct address :/

Are you injecting code or not? If not, that's 99% of the problem.


-------
edit: Got it to work with memcpy() also. Assuming you have the correct address in wert1..
"Attachment Pending APproval" . See you tomorrow or 2 days : p
No here:
img4 .fot os-hochladen. n et/uploads/cppyutdqsn2hw.png
Quote Originally Posted by SawMister View Post
...
 
img


Are you injecting code via a .dll file, or not ??? :|
Yes its a .net DLL.
So i have a form in it.
Quote Originally Posted by SawMister View Post
...


Code:
//////////////SPEED//////////////
#define BasePointer1 0x6C4F24
#define Points6 0x00000004
#define Points7 0x0000066e

WORD val2 = 16666; 
  

void SetSpeedhack(){
	//HANDLE hProc = OpenProcess(((0x000F0000L) | (0x00100000L) | 0xFFFF), 0xFFFFFF, (unsigned int)GetCurrentProcessId()); // is this even used? remove comment lines if so.

       DWORD wert1 = *(DWORD*)BasePointer1; // read 6C4F24 --> gives us some ######
       wert1 = *(DWORD*)(wert1 + Points6); // add Points6 to ######, then read that location
       wert1 = *(DWORD*)(wert1 + Points7); // add Points7 to ######, then read that location
edit: ... one second. I just de-referenced 3 pointers. Read up 3 levels. But looking at the picture, we should only read up 2 levels! The top expression doesn't have [ ]'s around it! We simply need to add 66e, and done, don't read it 1 last time. ! I think?

1. Read the constant 0x6c4F24
2. Add 4 to the value from #1
3. Read that new number (at this point our value is VERY close to correct_address)
4. Add 0x66e to value from #3
5. Done.

I kept trying to go up an extra level. I think that was your problem too? Anyway, code.
Code:
//////////////SPEED//////////////
#define BasePointer1 0x6C4F24
#define Points6 0x00000004
#define Points7 0x0000066e
const WORD NewValue16 = 16666; 
  

void SetSpeedhack(){

     DWORD wert1 = *(DWORD*)BasePointer1; // read 6C4F24 --> gives us some ######
     if(wert1 > 0){
       wert1 = *(DWORD*)(wert1 + Points6); // add Points6 to ######, then read that location
       wert1 += Points7;

       *(WORD*)wert1 = NewValue16 ; // change value to 16666
    }
}
// ^^ there is a syntax to de-reference several pointers + offsets in 1 line of code. However, this way is more clear.
 
checked your code again(from first post)

Code:
	RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)((int*)((BasePointer1))), sizeof((PDWORD)(BasePointer1))); 
	if(wert1 > 0){
		wert1+= Points6;
		RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)&(*(_Uint32t*)(wert1)), sizeof((PDWORD)(wert1)));
		wert1+= Points7;
		RtlCopyMemory((LPVOID)((void*)(&wert1)), (PVOID*)&(*(_Uint32t*)(wert1)), sizeof((PDWORD)(wert1)));

		DWORD val1 = 16666;
		memcpy((PVOID*)(*(int*)(&wert1)), (PWORD*)((void*)&(*(_Uint32t*)&val1)), 2);
	}
Although I don't like C++ pointer dereference syntax, the way you did it especially confuses me So many (casts).
But since all 3 calls to RtlCopyMemory() look the same, I think you were trying to go up 3 levels like I was. ?

Maybe.


maybe?
It works brilliant!
Thank you sooo much!
Regards, Sawmister
Posts 1–11 of 11 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us