Undetected Memory Wallhack

Posts 1–15 of 48 · Page 1 of 4
Undetected Memory Wallhack
Code:
#include <windows.h>
#include <stdio.h>
#include <stdlib.h>

BYTE bWHShellCode[ ]
{
	0x55,
	0x56,
	0x57,
	0x8B, 0xF8,
	0x60,
	0xA1, 0x00, 0x00, 0x00, 0x00,
	0xC7, 0x00, 0x00, 0x00, 0x00, 0x00,
	0x61,
	0xE9, 0x00, 0x00, 0x00, 0x00,
	0x00, 0x00,
	0x00, 0x00,
};

const bool bDataCompare( const BYTE *pData, const BYTE *bMask, const char *szMask )
{
	for( ; *szMask; ++szMask, ++pData, ++bMask )
		if( *szMask == 'x' && *pData != *bMask )
			return 0;
	return ( *szMask ) == NULL;
}

DWORD FindPattern( DWORD dwModule, DWORD dwLen, BYTE *bMask, char *szMask )
{
	for( DWORD i = 0; i < dwLen; i++ )
		if( bDataCompare( ( BYTE * ) ( dwModule + i ), bMask, szMask ) )
			return ( DWORD ) ( dwModule + i );
	return EXIT_SUCCESS;
}

DWORD WINAPI dwStartRoutine( void *lpReserved )
{
	DWORD ADDR_MID_HOOK		= NULL,
		  ADDR_SHELLCODE	= NULL,
		  ADDR_WALLHACK		= NULL,
		  ADDR_RETURN		= NULL;

	while( !GetModuleHandle( L"ClientFX.fxd" ) )
		Sleep( 1 );

	ADDR_MID_HOOK = FindPattern( 0x400000, 0x1154000,
		( PBYTE ) "\x55\x56\x57\x8B\xF8\x8B\xF1\x75\x00", ( char * ) "xxxxxxxx?" );

	ADDR_SHELLCODE = ( DWORD ) VirtualAlloc( 0, sizeof( bWHShellCode ), MEM_COMMIT, PAGE_EXECUTE_READWRITE );

	ADDR_WALLHACK = ( ADDR_MID_HOOK + 0x10 );
	ADDR_WALLHACK = *( DWORD * ) ( ADDR_WALLHACK + 0x01 );
	ADDR_WALLHACK += 0xA4;

	ADDR_RETURN = ( ADDR_MID_HOOK + 0x05 );

	//Shellcode Midfunction.
	DWORD lpflOldProtect = NULL;
	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	memcpy( ( PVOID ) ADDR_SHELLCODE, bWHShellCode, sizeof( bWHShellCode ) );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x07 )	= ( DWORD ) ( ADDR_SHELLCODE + 0x17 );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x17 )	= ( DWORD ) ADDR_WALLHACK;
	*( ( DWORD * ) ( ADDR_SHELLCODE + 0x13 ) )	= ( DWORD ) ( ADDR_RETURN - ( DWORD ) ( ADDR_SHELLCODE + 0x12 ) ) - 5;

	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), lpflOldProtect, &lpflOldProtect );

	//Org. function jmp.
	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	*( BYTE  * ) ( ADDR_MID_HOOK + 0x00 ) = 0xE9;
	*( DWORD * ) ( ADDR_MID_HOOK + 0x01 ) = ( DWORD ) ( ADDR_SHELLCODE - ADDR_MID_HOOK ) - 5;

	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, lpflOldProtect, &lpflOldProtect );

	return EXIT_SUCCESS;
}

BOOL APIENTRY DllMain( HMODULE hModule, DWORD  ul_reason_for_call, LPVOID lpReserved )
{
	switch( ul_reason_for_call )
	{
	case DLL_PROCESS_ATTACH:
		CreateThread( 0, 0, &dwStartRoutine, 0, 0, 0 );
		break;
	case DLL_THREAD_ATTACH:
	case DLL_THREAD_DETACH:
	case DLL_PROCESS_DETACH:
		break;
	}

	return TRUE;
}
Quote Originally Posted by luizimloko View Post
Code:
#include <windows.h>
#include <stdio.h>
#include <stdlib.h>

BYTE bWHShellCode[ ]
{
	0x55,
	0x56,
	0x57,
	0x8B, 0xF8,
	0x60,
	0xA1, 0x00, 0x00, 0x00, 0x00,
	0xC7, 0x00, 0x00, 0x00, 0x00, 0x00,
	0x61,
	0xE9, 0x00, 0x00, 0x00, 0x00,
	0x00, 0x00,
	0x00, 0x00,
};

const bool bDataCompare( const BYTE *pData, const BYTE *bMask, const char *szMask )
{
	for( ; *szMask; ++szMask, ++pData, ++bMask )
		if( *szMask == 'x' && *pData != *bMask )
			return 0;
	return ( *szMask ) == NULL;
}

DWORD FindPattern( DWORD dwModule, DWORD dwLen, BYTE *bMask, char *szMask )
{
	for( DWORD i = 0; i < dwLen; i++ )
		if( bDataCompare( ( BYTE * ) ( dwModule + i ), bMask, szMask ) )
			return ( DWORD ) ( dwModule + i );
	return EXIT_SUCCESS;
}

DWORD WINAPI dwStartRoutine( void *lpReserved )
{
	DWORD ADDR_MID_HOOK		= NULL,
		  ADDR_SHELLCODE	= NULL,
		  ADDR_WALLHACK		= NULL,
		  ADDR_RETURN		= NULL;

	while( !GetModuleHandle( L"ClientFX.fxd" ) )
		Sleep( 1 );

	ADDR_MID_HOOK = FindPattern( 0x400000, 0x1154000,
		( PBYTE ) "\x55\x56\x57\x8B\xF8\x8B\xF1\x75\x00", ( char * ) "xxxxxxxx?" );

	ADDR_SHELLCODE = ( DWORD ) VirtualAlloc( 0, sizeof( bWHShellCode ), MEM_COMMIT, PAGE_EXECUTE_READWRITE );

	ADDR_WALLHACK = ( ADDR_MID_HOOK + 0x10 );
	ADDR_WALLHACK = *( DWORD * ) ( ADDR_WALLHACK + 0x01 );
	ADDR_WALLHACK += 0xA4;

	ADDR_RETURN = ( ADDR_MID_HOOK + 0x05 );

	//Shellcode Midfunction.
	DWORD lpflOldProtect = NULL;
	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	memcpy( ( PVOID ) ADDR_SHELLCODE, bWHShellCode, sizeof( bWHShellCode ) );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x07 )	= ( DWORD ) ( ADDR_SHELLCODE + 0x17 );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x17 )	= ( DWORD ) ADDR_WALLHACK;
	*( ( DWORD * ) ( ADDR_SHELLCODE + 0x13 ) )	= ( DWORD ) ( ADDR_RETURN - ( DWORD ) ( ADDR_SHELLCODE + 0x12 ) ) - 5;

	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), lpflOldProtect, &lpflOldProtect );

	//Org. function jmp.
	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	*( BYTE  * ) ( ADDR_MID_HOOK + 0x00 ) = 0xE9;
	*( DWORD * ) ( ADDR_MID_HOOK + 0x01 ) = ( DWORD ) ( ADDR_SHELLCODE - ADDR_MID_HOOK ) - 5;

	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, lpflOldProtect, &lpflOldProtect );

	return EXIT_SUCCESS;
}

BOOL APIENTRY DllMain( HMODULE hModule, DWORD  ul_reason_for_call, LPVOID lpReserved )
{
	switch( ul_reason_for_call )
	{
	case DLL_PROCESS_ATTACH:
		CreateThread( 0, 0, &dwStartRoutine, 0, 0, 0 );
		break;
	case DLL_THREAD_ATTACH:
	case DLL_THREAD_DETACH:
	case DLL_PROCESS_DETACH:
		break;
	}

	return TRUE;
}
you can also do this tho ^^[QUOTE]//WallHack
if (GetAsyncKeyState(VK_F2) & 1) WallHack = (!WallHack); //F2 Hotkey for WallHack
if(WallHack)
{
memcpy((PVOID)(WallArray + 0xA4), (PBYTE)"\x00\x00\x00\x00\x00\x00\x90\x90\x90\x90\x 90\x90\x90\x90\x90\x90\x90\x90\x90", 19);
}
else
{
memcpy((PVOID)(WallArray + 0xA4), (PBYTE) "\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90", 19);
}[QUOTE]

- - - Updated - - -

Guys you can also do this ^^ for cfph

//WallHack
if (GetAsyncKeyState(VK_F2) & 1) WallHack = (!WallHack); //F2 Hotkey for WallHack
if(WallHack)
{
memcpy((PVOID)(WallArray + 0xA4), (PBYTE)"\x00\x00\x00\x00\x00\x00\x90\x90\x90\x90\x 90\x90\x90\x90\x90\x90\x90\x90\x90", 19);
}
else
{
memcpy((PVOID)(WallArray + 0xA4), (PBYTE) "\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\x90\ x90\x90\x90\x90\x90\x90\x90", 19);
}
ClientFX.fxd :O wallhack, you guys started doing some really cool stuff
Quote Originally Posted by kmanev073 View Post
ClientFX.fxd :O wallhack, you guys started doing some really cool stuff
his address in crossfire.exe itself not clientfx
0x400000 // crossfire.exe

clientfx.fxd is just a loop to check for game being ready,, am i right ??
Quote Originally Posted by I2espect View Post
his address in crossfire.exe itself not clientfx
0x400000 // crossfire.exe

clientfx.fxd is just a loop to check for game being ready,, am i right ??
You must be as the handle for clientfx is never used...
Quote Originally Posted by I2espect View Post
his address in crossfire.exe itself not clientfx
0x400000 // crossfire.exe

clientfx.fxd is just a loop to check for game being ready,, am i right ??
yeah
/msgshort
Quote Originally Posted by dreek1 View Post
yeah
/msgshort
so what does this mean XD ?

Quote Originally Posted by kmanev073 View Post
ClientFX.fxd :O wallhack, you guys started doing some really cool stuff
//

btw another question
how do u even reverse engineer this kind of hacks
cuz there is no actual string that can help u get the address and trace the asm to find what u want
i dont mean the part where u bypass the xtrap ...
just how to track an address for a wall hack or any d3d stuff for any game in general
and get it in memory not with the basic dip hook ( zbuffer =false )
Quote Originally Posted by I2espect View Post
so what does this mean XD ?



//

btw another question
how do u even reverse engineer this kind of hacks
cuz there is no actual string that can help u get the address and trace the asm to find what u want
i dont mean the part where u bypass the xtrap ...
just how to track an address for a wall hack or any d3d stuff for any game in general
and get it in memory not with the basic dip hook ( zbuffer =false )
(My bad I didn't look much at the souce) The hack is just waiting for the clientfx to be loaded as it loads only ingame.

Maybe the checked the engine source, or they placed a breakpoint on the DIP function, saw where it returns to and just reversed engineered the game.
Quote Originally Posted by luizimloko View Post
Code:
#include <windows.h>
#include <stdio.h>
#include <stdlib.h>

BYTE bWHShellCode[ ]
{
	0x55,
	0x56,
	0x57,
	0x8B, 0xF8,
	0x60,
	0xA1, 0x00, 0x00, 0x00, 0x00,
	0xC7, 0x00, 0x00, 0x00, 0x00, 0x00,
	0x61,
	0xE9, 0x00, 0x00, 0x00, 0x00,
	0x00, 0x00,
	0x00, 0x00,
};

const bool bDataCompare( const BYTE *pData, const BYTE *bMask, const char *szMask )
{
	for( ; *szMask; ++szMask, ++pData, ++bMask )
		if( *szMask == 'x' && *pData != *bMask )
			return 0;
	return ( *szMask ) == NULL;
}

DWORD FindPattern( DWORD dwModule, DWORD dwLen, BYTE *bMask, char *szMask )
{
	for( DWORD i = 0; i < dwLen; i++ )
		if( bDataCompare( ( BYTE * ) ( dwModule + i ), bMask, szMask ) )
			return ( DWORD ) ( dwModule + i );
	return EXIT_SUCCESS;
}

DWORD WINAPI dwStartRoutine( void *lpReserved )
{
	DWORD ADDR_MID_HOOK		= NULL,
		  ADDR_SHELLCODE	= NULL,
		  ADDR_WALLHACK		= NULL,
		  ADDR_RETURN		= NULL;

	while( !GetModuleHandle( L"ClientFX.fxd" ) )
		Sleep( 1 );

	ADDR_MID_HOOK = FindPattern( 0x400000, 0x1154000,
		( PBYTE ) "\x55\x56\x57\x8B\xF8\x8B\xF1\x75\x00", ( char * ) "xxxxxxxx?" );

	ADDR_SHELLCODE = ( DWORD ) VirtualAlloc( 0, sizeof( bWHShellCode ), MEM_COMMIT, PAGE_EXECUTE_READWRITE );

	ADDR_WALLHACK = ( ADDR_MID_HOOK + 0x10 );
	ADDR_WALLHACK = *( DWORD * ) ( ADDR_WALLHACK + 0x01 );
	ADDR_WALLHACK += 0xA4;

	ADDR_RETURN = ( ADDR_MID_HOOK + 0x05 );

	//Shellcode Midfunction.
	DWORD lpflOldProtect = NULL;
	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	memcpy( ( PVOID ) ADDR_SHELLCODE, bWHShellCode, sizeof( bWHShellCode ) );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x07 )	= ( DWORD ) ( ADDR_SHELLCODE + 0x17 );
	*( DWORD   * ) ( ADDR_SHELLCODE + 0x17 )	= ( DWORD ) ADDR_WALLHACK;
	*( ( DWORD * ) ( ADDR_SHELLCODE + 0x13 ) )	= ( DWORD ) ( ADDR_RETURN - ( DWORD ) ( ADDR_SHELLCODE + 0x12 ) ) - 5;

	VirtualProtect( ( PVOID ) ADDR_SHELLCODE, sizeof( bWHShellCode ), lpflOldProtect, &lpflOldProtect );

	//Org. function jmp.
	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, PAGE_EXECUTE_READWRITE, &lpflOldProtect );

	*( BYTE  * ) ( ADDR_MID_HOOK + 0x00 ) = 0xE9;
	*( DWORD * ) ( ADDR_MID_HOOK + 0x01 ) = ( DWORD ) ( ADDR_SHELLCODE - ADDR_MID_HOOK ) - 5;

	VirtualProtect( ( PVOID ) ADDR_MID_HOOK, 5, lpflOldProtect, &lpflOldProtect );

	return EXIT_SUCCESS;
}

BOOL APIENTRY DllMain( HMODULE hModule, DWORD  ul_reason_for_call, LPVOID lpReserved )
{
	switch( ul_reason_for_call )
	{
	case DLL_PROCESS_ATTACH:
		CreateThread( 0, 0, &dwStartRoutine, 0, 0, 0 );
		break;
	case DLL_THREAD_ATTACH:
	case DLL_THREAD_DETACH:
	case DLL_PROCESS_DETACH:
		break;
	}

	return TRUE;
}
Eu fiz do seguinte modo: Ficou indetectável por cerca de 6 dias.

Code:
// dllmain.cpp : Defines the entry point for the DLL application.
#include <Windows.h>
#include <iostream>
#include <SDKDDKVer.h>
#include "xor.h"

#define WIN32_LEAN_AND_MEAN             // Exclude rarely-used stuff from Windows headers
#define _CRT_SECURE_NO_WARNINGS

#define WallHack 0x0119A1EC
#define SeeGhost 0x0119A200

using namespace std;

void AbrirConsole() {
    AllocConsole();
    freopen("CONIN$", "r", stdin);
    freopen("CONOUT$", "w", stdout);
    freopen("CONOUT$", "w", stderr);
    SetConsoleTitle("Wall/SeeGhost CFAL");
}

DWORD WINAPI IniciarRotina(LPVOID inutil) {
    DWORD ValorWall = 16777217;
    DWORD ValorSeeGhost = 5;
    int receber = 0;
    while (true) {
        if (receber == 0) {
            *(DWORD*)WallHack = ValorWall;
            *(DWORD*)SeeGhost = ValorSeeGhost;
        }
        else if (receber == 1) {
            *(DWORD*)WallHack = 0;
            *(DWORD*)SeeGhost = 7;
        }
        cin >> receber;
    }
    return 0;
}
BOOL APIENTRY DllMain( HMODULE hModule,
                       DWORD  dReason,
                       LPVOID lpReserved
                     )
{
    if (dReason == DLL_PROCESS_ATTACH) {
        AbrirConsole();
        CreateThread(NULL, NULL, IniciarRotina, NULL, NULL, NULL);
    }
    return TRUE;
}
@kmanev073 : Cheat Engine has a break and trace function that is really useful and even better than OllyDbg breakpoint system.
I use both Cheat Engine and OllyDbg mixed now and I'm doing a lot of things.
Quote Originally Posted by UltraPGNoob View Post
@kmanev073 : Cheat Engine has a break and trace function that is really useful and even better than OllyDbg breakpoint system.
I use both Cheat Engine and OllyDbg mixed now and I'm doing a lot of things.
How do you guys bypass the xigncode3 to use cheat engine?
Quote Originally Posted by UltraPGNoob View Post
@kmanev073 : Cheat Engine has a break and trace function that is really useful and even better than OllyDbg breakpoint system.
I use both Cheat Engine and OllyDbg mixed now and I'm doing a lot of things.
Thanks man.
I use a custom client of CF with anticheat bypassed. Btw I don't work on a hack it's just for making tools for managing the client files.
Quote Originally Posted by UltraPGNoob View Post
I use a custom client of CF with anticheat bypassed. Btw I don't work on a hack it's just for making tools for managing the client files.
cool
/msgshort
Quote Originally Posted by I2espect View Post
btw another question
how do u even reverse engineer this kind of hacks
cuz there is no actual string that can help u get the address and trace the asm to find what u want
i dont mean the part where u bypass the xtrap ...
just how to track an address for a wall hack or any d3d stuff for any game in general
and get it in memory not with the basic dip hook ( zbuffer =false )
using the game engine source code ( github link ) , if you read it , u'll be able to understand how the game works .
tho the source code is old but you can manage to understand few things , they only changed the dx version / rez / they added lua to scripts , you can decrypt the rez and the scripts and just change things in there and encrypt , that's called rez edit tho it's fun to do since you can do few things that can't be detected by client if u do it internal/external
Posts 1–15 of 48 · Page 1 of 4

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us