The only scripts in rez files are .NUT which I decrypted and it's kinda useless. There's nothing to do with it.
Undetected Memory Wallhack
Ty for helping..
May i ask more questions ..
It mat sounds dump😂 but anyway😂
Why do we need to hook functions like endscene for ex to call functions like drawenginetext ? But ingame msgbox we dont need to ?? That's confusing..
I am actually having trouble getting my base to be undetected now.. last time i had the game was with xtrap 😅
(Before they removed the xtrap keep alive packet ofc 😂 LoL..)
and it was working ... now even without hook my dll get detected after 5 min or so (dc + ban)
And how to find a good place to hook for a start .. or should i try another method than byte patching ??
A skype or pm could help me alot with the detection problem... ty
May i ask more questions ..
It mat sounds dump😂 but anyway😂
Why do we need to hook functions like endscene for ex to call functions like drawenginetext ? But ingame msgbox we dont need to ?? That's confusing..
I am actually having trouble getting my base to be undetected now.. last time i had the game was with xtrap 😅
(Before they removed the xtrap keep alive packet ofc 😂 LoL..)
and it was working ... now even without hook my dll get detected after 5 min or so (dc + ban)
And how to find a good place to hook for a start .. or should i try another method than byte patching ??
A skype or pm could help me alot with the detection problem... ty

@I2espect EndScene is the last function before drawing the screen you need to be in sync with the scene for it to be drawn if you aren't in the scene it won't draw. You can also draw in Present aswell because it's called before EndScene.
As for ingame messagebox it shouldn't be D3D9 it should be DirectDraw I guess. GUI stuff are better in DirectDraw because it's simple 2D.
As for ingame messagebox it shouldn't be D3D9 it should be DirectDraw I guess. GUI stuff are better in DirectDraw because it's simple 2D.
how to bypass it !? and how u find an undetected place to hook d3d ??
okay,, now i get it ,, so it's about the order of this functions,, i need to sync my d3d menu before (the scene end) and after (the scene begin),, ty all
so for drawenginetext ?? it's a d3d draw too and follow the same rules..
//
now i am having trouble with the cshell.dll ,, it's unimportant now as my dll is detected anyway,, i just wanted to update some patterns..
i find a load library that can actually load cshell.dll into its memory,, and from there i tried :
1-dumping it with petools ,, worked before xigncode, now it dump the dll but cant open it in ollydbg after that
2-attaching ollydbg to load library itself and work from there ,, which caused exceptions..(privilege instruction + access violation
// note :
i tried to dump cshell from crossfire itself ,, but the process is somehow hidden !
i cant find it in petools... it appears for just a sec and then cant find it again ..my os : 8.1 - 64bit
there was a game called s4 league that did the same on 64 bit (and guess what xigncode again),, is that the case for cf ??
okay,, now i get it ,, so it's about the order of this functions,, i need to sync my d3d menu before (the scene end) and after (the scene begin),, ty all
so for drawenginetext ?? it's a d3d draw too and follow the same rules..
//
now i am having trouble with the cshell.dll ,, it's unimportant now as my dll is detected anyway,, i just wanted to update some patterns..
i find a load library that can actually load cshell.dll into its memory,, and from there i tried :
1-dumping it with petools ,, worked before xigncode, now it dump the dll but cant open it in ollydbg after that
2-attaching ollydbg to load library itself and work from there ,, which caused exceptions..(privilege instruction + access violation
// note :
i tried to dump cshell from crossfire itself ,, but the process is somehow hidden !
i cant find it in petools... it appears for just a sec and then cant find it again ..my os : 8.1 - 64bit
there was a game called s4 league that did the same on 64 bit (and guess what xigncode again),, is that the case for cf ??
use the bypass for xigncode3 that is here on mpgh, then use PETools or Scylla Dumper to get the DLL.
https://www.mpgh.net/forum/showthread.php?t=1096105
PS: it will DC you (or ban, dunno), so don't play with it.
https://www.mpgh.net/forum/showthread.php?t=1096105
PS: it will DC you (or ban, dunno), so don't play with it.
working flawless
Actually the function sets the text to write in the endscene and the message is drawn because it changes the currently displayed popup id on the screen which draws a message box if the id is corresponding the message box. When playing around with this ID you can even use other message boxes such as the save replay or anything that acts as a popup. You could also watch the replay when on login screen for example.
It's beautiful code but it's more simples do that:
Code:
#define ADDR_TEXTURES 0x0119AD20
/*
55 56 57 8B F8 8B F1 75 ?? // luizimloko reference
00476680 /$ 81EC C0040000 SUB ESP,4C0
00476686 |. F605 C8AE1901 >TEST BYTE PTR DS:[119AEC8],1
0047668D |. 55 PUSH EBP
0047668E |. 56 PUSH ESI
0047668F |. 57 PUSH EDI
00476690 |. 8BF8 MOV EDI,EAX
00476692 |. 8BF1 MOV ESI,ECX
00476694 |. 75 11 JNZ SHORT crossfir.004766A7
00476696 |. 830D C8AE1901 >OR DWORD PTR DS:[119AEC8],1
0047669D |. B8 20AD1901 MOV EAX,crossfir.0119AD20 //ADDR_TEXTURE
004766A2 |. E8 79840700 CALL crossfir.004EEB20
004766A7 |> 8B06 MOV EAX,DWORD PTR DS:[ESI]
004766A9 |. 8B50 18 MOV EDX,DWORD PTR DS:[EAX+18]
004766AC |. 8D4C24 58 LEA ECX,DWORD PTR SS:[ESP+58]
004766B0 |. 51 PUSH ECX
004766B1 |. 57 PUSH EDI
*/
class cTextures// Have more textures like Chams,etc..
{
public:
char pad_0000[16]; //0x0000
int32_t FullBright; //0x0010
char pad_0014[144]; //0x0014
int32_t WallHack; //0x00A4
char pad_00A8[16]; //0x00A8
int32_t SeeGhost; //0x00B8
}; //Size: 0x00BC
cTextures *pTexture;
void CALL_FUNCTION()
{
pTexture = (cTextures *)(ADDR_TEXTURES);
if (pTexture != NULL) {
pTexture->FullBright = 6;//Original value is 5
pTexture->WallHack = 0;//Original value is 16777217
pTexture->SeeGhost = 3;//Original value is 5
}
}
Similar Threads
CrossFire Hack Coding / Programming / Source CodeUndetected memory wallhack !! 33 Crossfire Coding Help & DiscussionHow to find Memory wallhack undetect.
19 Soldier Front Hacks[TUT] HOW TO UNDETECTED ALL WALLHACKNI 1 Alliance of Valiant Arms (AVA) Hacks & Cheats[Release] Undetected Memory Hacking Software(MHS)
56 Soldier Front HacksUNDETECTED wireframe wallhack 6/25/09FI 5
