gmcl_debug

Posts 1–15 of 44 · Page 1 of 3
gmcl_debug
Fuck it why not, this module re-implements all of the removed debug functions. Release coming soon



Code:
require("debug")

print(debug.setupvalue)

local function my_isfunction( f )
	return type( f ) == "function" or f == "coolguy"
end

print( debug.setupvalue( hook.Add, 1, my_isfunction ) )

print(debug.upvalueid)

print( type( debug.upvalueid( hook.Add, 1 ) ) )

print(debug.upvaluejoin)

print(debug.setlocal)

local var1 = "Luke, I am not your father."
local var2 = "PMFPMF"

( function()
	print( "Getting the locals now!" )
	PrintTable( { debug.getlocal( 2, 1 ) } )
	PrintTable( { debug.getlocal( 2, 2 ) } )

	print( "\nSetting the locals now!" )
	print( debug.setlocal( 2, 1, "I'm actually your mother." ) )
	print( debug.setlocal( 2, 2, "Chemo-chi" ) )
	print( debug.setlocal( 2, 3, "nil should be returned here!" ) )

	print( "\nHere are the locals after being set!" )
	PrintTable( { debug.getlocal( 2, 1 ) } )
	PrintTable( { debug.getlocal( 2, 2 ) } )
end )()
https://www.virustotal.com/en/file/8...is/1500063380/
https://malwr.com/submission/status/...JhMDkxZjYxNGU/
https://virusscan.jotti.org/en-US/fi...job/ruxmlnti04

gmcl_debug_win32_mpgh.net.zip5 KB · 84 downloads Clean
Whats this xd
yeah, what exactly is this?
Quote Originally Posted by jooshzz View Post
yeah, what exactly is this?
Read the thread maybe???
Certain debug functions were removed from the lua state of gmod due to a memory reading/writing exploit that involved them. This module readds them to the lua state so you can call them to do whatever. Most of the people on this site use it to bypass anticheats, but they have other valid uses.

Code:
lua_getfield(v3[1], -10002, "debug");
lua_pushnil(v3[1]);
lua_setfield(v3[1], -2, "setlocal");
lua_pushnil(v3[1]);
lua_setfield(v3[1], -2, "setupvalue");
lua_pushnil(v3[1]);
lua_setfield(v3[1], -2, "upvalueid");
lua_pushnil(v3[1]);
lua_setfield(v3[1], -2, "upvaluejoin");
lua_settop(v3[1], -2);
Quote Originally Posted by IAmPhage View Post
Fuck it why not, this module re-implements all of the removed debug functions. Release coming soon



Code:
require("debug")

print(debug.setupvalue)

local function my_isfunction( f )
	return type( f ) == "function" or f == "coolguy"
end

print( debug.setupvalue( hook.Add, 1, my_isfunction ) )

print(debug.upvalueid)

print( type( debug.upvalueid( hook.Add, 1 ) ) )

print(debug.upvaluejoin)

print(debug.setlocal)

local var1 = "Luke, I am not your father."
local var2 = "PMFPMF"

( function()
	print( "Getting the locals now!" )
	PrintTable( { debug.getlocal( 2, 1 ) } )
	PrintTable( { debug.getlocal( 2, 2 ) } )

	print( "\nSetting the locals now!" )
	print( debug.setlocal( 2, 1, "I'm actually your mother." ) )
	print( debug.setlocal( 2, 2, "Chemo-chi" ) )
	print( debug.setlocal( 2, 3, "nil should be returned here!" ) )

	print( "\nHere are the locals after being set!" )
	PrintTable( { debug.getlocal( 2, 1 ) } )
	PrintTable( { debug.getlocal( 2, 2 ) } )
end )()
https://www.virustotal.com/en/file/8...is/1500063380/
https://malwr.com/submission/status/...JhMDkxZjYxNGU/
https://virusscan.jotti.org/en-US/fi...job/ruxmlnti04

all functions with the "debug" prefix were removed? when were they removed, recently or a while ago?
Quote Originally Posted by bee_tee_gee View Post
all functions with the "debug" prefix were removed? when were they removed, recently or a while ago?
Very recently, in the latest update. Only the ones I posted got 'removed', but essentially they just overwrite the function to nil.
Quote Originally Posted by bee_tee_gee View Post
all functions with the "debug" prefix were removed? when were they removed, recently or a while ago?
A few functions were removed due to a memory read/write exploit Cdriza stole from swadicalrag and released everywhere.
Code:
local function UInt32ToDouble(num) // credits to cake
	local negative = false
	if num >= 0x80000000 then
		negative = true
		num = num - 0x80000000
	end
	
	local biasedExponent = bit.rshift(bit.band(num, 0x7FF00000), 20)
	local mantissa = (bit.band(num, 0x000FFFFF) * 4294967296 + num) / 2 ^ 52
	local f
	if biasedExponent == 0x0000 then
		f = mantissa == 0 and 0 or math.ldexp(mantissa, -1022)
	elseif biasedExponent == 0x07FF then
		f = mantissa == 0 and math.huge or (math.huge - math.huge)
	else
		f = math.ldexp(1 + mantissa, biasedExponent - 1023)
	end
	
	return negative and -f or f
end

local function __readMemory(address, len)
	local blankName, upFunction = debug.getupvalue(ipairs, 1) // backup ipairsaux
	debug.setupvalue(ipairs, 1, UInt32ToDouble(address - 8)) // set first upvalue to converted address
	local addrFunction = ipairs({}) // lua_pushvalue(L,lua_upvalueindex(1));
	debug.setupvalue(ipairs, 1, upFunction) // return upvalue to ipairsaux
	local fenvAddrNameFN = debug.getfenv(addrFunction)
	local memeAddress = tonumber(string.format("%p", fenvAddrNameFN), 16)
	memeAddress = bit.tohex(memeAddress, 8)
	local memeAddress2 = ""
	for i in memeAddress:gmatch("..") do
		memeAddress2 = string.char(tonumber(i, 16)) .. memeAddress2
	end

	return memeAddress2:sub(1, len or 4)
end

local function readMemory(address, len)
	local returnStr = ""
	for i = 1, len or 1, 4 do
		returnStr = returnStr .. __readMemory(address - 1, math.min(len - (i - 1), 4))
	end

	return returnStr
end

kmem = {}
kmem.util = {}
kmem.read = {}
function kmem.util:address(obj)
	return tonumber(string.format("%p", obj))
end

function kmem.util:hex(num)
	return "0x" .. string.format("%x", tostring(num)):upper()
end

function kmem.read:uint8(addr)
	return readMemory(addr, 1):byte()
end

function kmem.read:uint16(addr)
	local returnStr = ""
	returnStr = returnStr .. string.format("%02x", readMemory(addr + 1, 1):byte())
	returnStr = returnStr .. string.format("%02x", readMemory(addr, 1):byte())
	return tonumber(returnStr, 16)
end

function kmem.read:uint24(addr)
	local returnStr = ""
	returnStr = returnStr .. string.format("%02x", readMemory(addr + 2, 1):byte())
	returnStr = returnStr .. string.format("%02x", readMemory(addr + 1, 1):byte())
	returnStr = returnStr .. string.format("%02x", readMemory(addr, 1):byte())
	return tonumber(returnStr, 16)
end

function kmem.read:uint32(addr)
	local blankName, upFunction = debug.getupvalue(ipairs, 1)
	debug.setupvalue(ipairs, 1, UInt32ToDouble(addr - 8))
	local addrFunction = ipairs({})
	debug.setupvalue(ipairs, 1, upFunction)
	local fenvAddrNameFN = debug.getfenv(addrFunction)
	local memeAddress = tonumber(string.format("%p", fenvAddrNameFN), 16)
	return memeAddress
end
Code:
#include <Windows.h>
extern "C" __declspec(dllexport) int gmod13_open(void* L)
{
	return ((int(*)(void*))(GetProcAddress(GetModuleHandle(L"lua_shared.dll"), "luaopen_debug")))(L);
}
Do I get a cookie?
Quote Originally Posted by Gorzoid View Post
Code:
#include <Windows.h>
extern "C" __declspec(dllexport) int gmod13_open(void* L)
{
	return ((int(*)(void*))(GetProcAddress(GetModuleHandle(L"lua_shared.dll"), "luaopen_debug")))(L);
}
Do I get a cookie?
No, C Style casting is gross.
so can you modify function local values with this? cdriza pls don't call me skid
love seeing meeps code from 2015 rise out of nowhere

- - - Updated - - -

Quote Originally Posted by IAmPhage View Post
No, C Style casting is gross.
^^^ this is a dumb post ^^^
Quote Originally Posted by D3M0L1T10N View Post
love seeing meeps code from 2015 rise out of nowhere

- - - Updated - - -



^^^ this is a dumb post ^^^
"Meeps" code. This is pasted straight out of the Lua 5.2.4 Source. All it does is call exported functions. The SRC is on facepunch if you really want to look. And C Style casting is retarded, have fun with undefined behavior.
Quote Originally Posted by IAmPhage View Post
"Meeps" code. This is pasted straight out of the Lua 5.2.4 Source. All it does is call exported functions. The SRC is on facepunch if you really want to look. And C Style casting is retarded, have fun with undefined behavior.
It is meeps code he invented L.U.A you nut
Posts 1–15 of 44 · Page 1 of 3

Post a Reply

Tags for this Thread

None

Talk with us