Code Cave Issues

Posts 1–15 of 27 · Page 1 of 2
Code Cave Issues
Ok I have been working for a while trying to find a section where I can make a codecave in Assault Cube and I have found it this is it:

Code:
0045B756  |. 8B5C24 10      MOV EBX,DWORD PTR SS:[ESP+10]
0045B75A  |. 8910           MOV DWORD PTR DS:[EAX],EDX
0045B75C  |. 8B76 14        MOV ESI,DWORD PTR DS:[ESI+14]
0045B75F     FF0E           DEC DWORD PTR DS:[ESI]
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
0045B765  |. E8 F6E4FFFF    CALL ac_clien.00459C60
This is the original address which decreases your ammo.

I decided to change it to this:

Code:
0045B756  |. 8B5C24 10      MOV EBX,DWORD PTR SS:[ESP+10]
0045B75A  |. 8910           MOV DWORD PTR DS:[EAX],EDX
0045B75C  |. 8B76 14        MOV ESI,DWORD PTR DS:[ESI+14]
0045B75F     FF0E           INC DWORD PTR DS:[ESI]
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
0045B765  |. E8 F6E4FFFF    CALL ac_clien.00459C60
I found a empty area and I implemented it.

JUMP GATE:
Code:
0045B756     E9 F09C0500    JMP ac_clien.004B544B
0045B75B     108B 7614FF0E  ADC BYTE PTR DS:[EBX+EFF1476],CL
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
0045B765  |. E8 F6E4FFFF    CALL ac_clien.00459C60
MODDED CODE:
Code:
004B544B     8B5C24 10      MOV EBX,DWORD PTR SS:[ESP+10]
004B544F     8910           MOV DWORD PTR DS:[EAX],EDX
004B5451     8B76 14        MOV ESI,DWORD PTR DS:[ESI+14]
004B5454     FF06           INC DWORD PTR DS:[ESI]
004B5456     8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
004B545A    ^E9 0663FAFF    JMP ac_clien.0045B765
It works perfectly and everything, now my question is:

How would this translate into C++ coding?
This is what I have so far:

Code:
#include "windows.h"

__declspec(naked) void Machine_Gun_Increase(void)
{
	_asm
      {
      }
}

DWORD WINAPI MainThread(LPVOID)  
{  

return 0;  
}  

BOOL WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID lpReserved )  
{  
DisableThreadLibraryCalls(hDll);  
if ( dwReason == DLL_PROCESS_ATTACH )  
{  
CreateThread(NULL, NULL, MainThread, NULL, NULL, NULL);  
}  
return true;  
}
Any help would be appreciated. If you want to try this code out, it only works for the Assault Rifle. Once, I get this working in C++ I will find the rest and I will release hacks for this game.
Use MS detours 1.5 to detour the instruction to your own.

[Highlight=VB]
unsigned long ulAddress = 0x00001234;

__declspec(naked) void Increase_ammo(void)
{
unsigned long ret = ulAddress + 2; //2 is the length of the dec esi instruction
__asm
{
inc esi
jmp [ret]
}

}

void MainThread()
{
while(!GetModuleHandle("WhateverDllThatinstruction isIn"))
continue;

DetourFunction((BYTE*)ulAddress,(BYTE*)Increase_am mo);
}

dll entry point function blahblah()
{
if(blahblah)
{
CreateRemoteThread(blahblah,MainThread);
}
}
[/Highlight]

Something like that, too lazy to fully code it.
Im trying it out right now I will post if I have any issues

Code:
#include "windows.h"
#include "detours.h"

#pragma comment(lib, "detours.lib")


DWORD address1 = 0x0045B75F;
unsigned long ret = address1 + 2; //2 is the length of the dec esi instruction

__declspec(naked) void Machine_Gun_Increase(void)
{

	_asm
	{
		INC ESI;
		JMP [ret];

	}
}

DWORD WINAPI MainThread(LPVOID)  
{
	int a = 1;
	while(a == 1)
	{
	if(GetAsyncKeyState(VK_INSERT))
	{
	DetourFunction((BYTE*)address1,(BYTE*)Machine_Gun_Increase());
	}
	}
return 0;  
}  

BOOL WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID lpReserved )  
{  
DisableThreadLibraryCalls(hDll);  
if ( dwReason == DLL_PROCESS_ATTACH )  
{  
CreateThread(NULL, NULL, MainThread, NULL, NULL, NULL);  
}  
return true;  
}
Question: What does this do exactly? How did you find the length?

Code:
unsigned long ret = address1 + 2; //2 is the length of the dec esi instruction
Thanks for the help
Dont put the detour on a hotkey o_O You patch it once and its patched for good. Till' you restart the game.

Edit: it puts a jump over that instruction to your own function. In your function, you increase esi.
How I got the bytes? The opcodes in olly told me.
I tried it and the game crashed.

The reason I put it on a Hotkey is because once it works im going to also do the same thing but instead of INC im going to DEC
If my stuff crashes id usually debug in olly to see why, but i cant really do that here. \:
I tried debugging and then my who computer crashed. I had to reboot. Well, the good thing is that it injects perfectly and no crash. I went to the address and it was still the same when I pressed Insert then my whole PC went down.

Do you think its because I dont define ESI?

Did you find the opcodes from this?

The FF06?
Code:
004B5454     FF06           INC DWORD PTR DS:[ESI]

This is my code:
Code:
DWORD address1 = 0x0045B75F;
unsigned long ret = address1 + 2; //2 is the length of the dec esi instruction

__declspec(naked) BYTE Machine_Gun_Increase(void)
{
	
	_asm
	{
		PUSHAD;
		PUSHFD;
		INC DWORD PTR DS:[ESI];
		JMP [ret];

	}
}

DWORD WINAPI MainThread(LPVOID)  
{
	int a = 1;
	while(a == 1)
	{
	if(GetAsyncKeyState(VK_INSERT))
	{
	DetourFunction((BYTE*)address1,(BYTE*)Machine_Gun_Increase());
	}
	}
return 0;  
}  

BOOL WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID lpReserved )  
{  
DisableThreadLibraryCalls(hDll);  
if ( dwReason == DLL_PROCESS_ATTACH )  
{  
CreateThread(NULL, NULL, MainThread, NULL, NULL, NULL);  
}  
return true;  
}
I had to change the void in Machine_Gun_Increase() to a BYTE because I was getting errors when compiling.
why are we trying to detour a single instruction. just NOP it and call it a day.

If it's crashing when you write over it make sure you wrap the code in VirtualProtect() functions to allow READ WRITE and EXECUTION access to that memory region
Wtf you're pushing every register on the stack without removing them? Well.. don't do that >_>;
Quote Originally Posted by why06 View Post
why are we trying to detour a single instruction. just NOP it and call it a day.

If it's crashing when you write over it make sure you wrap the code in VirtualProtect() functions to allow READ WRITE and EXECUTION access to that memory region
Wouldnt I still have to make a codecave because it messes with other instructions?

Quote Originally Posted by Void View Post
Wtf you're pushing every register on the stack without removing them? Well.. don't do that >_>;
I know, that was a typo.
Quote Originally Posted by aanthonyz View Post
Wouldnt I still have to make a codecave because it messes with other instructions?
No, not if you know the instruction sizes. NOP is a 1 byte instruction so it can overwrite any instruction easily because instruction cant be smaller then 1 byte. Your much more likely to cause unwanted problems, by placing a LONG jump, a 5 byte instruction into a 2 byte dec instruction. You would in fact be overwriting half the next line
Code:
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
Which will drastically change that code. It would be much wiser to replace it with an inc instruction which is also 2 bytes or 2 NOP (1 byte each), code caving isn't really necessary when you have dll injection anyway, since you can simple right the function in your own module and don't have to find empty space in the targets code.
Quote Originally Posted by why06 View Post


No, not if you know the instruction sizes. NOP is a 1 byte instruction so it can overwrite any instruction easily because instruction cant be smaller then 1 byte. Your much more likely to cause unwanted problems, by placing a LONG jump, a 5 byte instruction into a 2 byte dec instruction. You would in fact be overwriting half the next line
Code:
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
Which will drastically change that code. It would be much wiser to replace it with an inc instruction which is also 2 bytes or 2 NOP (1 byte each), code caving isn't really necessary when you have dll injection anyway, since you can simple right the function in your own module and don't have to find empty space in the targets code.
Learning how to detour single instructions and using naked routines is still good mang, and this is perfect practice. Dont be a hater ):
Yes, I actually want to learn both ways of doing it. Without code caving to Nop that address would I just use WriteProcessMemory?

Ive tried fixing the problem with the code but still it doesnt work. My computer has rebooted 3 times.
Normally I don't use API's when injected, since the could be monitored, but in Assualtcube I doubt it matters so WPM should work. I never used naked routines, so its just looks weird to me, but both techniques should work, and shouldn't reboot your pc.
I have tried it and nothing. My program keeps running but my hack doesnt work. I opened the game with an injector after the change and I went to the address but it never changed.

Code:
#include "windows.h"
#include "detours.h"

#pragma comment(lib, "detours.lib")


//DWORD address1 = 0x0045B75F;
HANDLE hProcess;
DWORD proccess_ID;
HWND hWnd;
//unsigned long ret = address1 + 2; //2 is the length of the dec esi instruction

bool FindWindow(void)
{
	hWnd = FindWindow("SDL_app", "AssaultCube");
	return true;
	if(hWnd == 0)
	{
    		MessageBox(0, "Error cannot find window.", "Error", MB_OK|MB_ICONERROR);
			return false;
	}
	else
	{
    		GetWindowThreadProcessId(hWnd, &proccess_ID);
    		hProcess = OpenProcess(PROCESS_ALL_ACCESS, FALSE, proccess_ID);
    		if(!hProcess)
		{
      			MessageBox(0, "Could not open the process!", "Error!", MB_OK|MB_ICONERROR);
    		return false;
			} 
		else 
		{
			return true;
		}
	}
}


DWORD WINAPI MainThread(LPVOID)  
{
	FindWindow();
	MessageBox(0, "Injected", "Success!",0);
	WriteProcessMemory(hProcess,(LPVOID)(DWORD)0x45B75F,(LPVOID)0x90, 1, NULL);
	WriteProcessMemory(hProcess,(LPVOID)(DWORD)0x45B760,(LPVOID)0x90, 1, NULL);
	//DetourFunction((BYTE*)address1,(BYTE*)Machine_Gun_Increase());
return 0;  
}  

BOOL WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID lpReserved )  
{  
DisableThreadLibraryCalls(hDll);  
if ( dwReason == DLL_PROCESS_ATTACH )  
{  
CreateThread(NULL, NULL, MainThread, NULL, NULL, NULL);  
}  
return true;  
}
I WPM'ed two addresses because when I NOP'ed 0x45B75F in Ollydbg it also NOP'ed 0x45B760, so I did the same.

I also tried this by just NOPing the first address only and nothing yet.
Posts 1–15 of 27 · Page 1 of 2

Post a Reply

Tags for this Thread

None

Talk with us