Code Cave Issues

Posts 16–27 of 27 · Page 2 of 2
I'll try it out when I get home, on my phone at the moment.

Very weird..
I know this is the first time I have issues with WriteProcessMemory. I can mess with the Calculator program,Pinball and everything else but im having trouble with this.

Im currently trying this code:
Code:
#include "windows.h"
#include "detours.h"

#pragma comment(lib, "detours.lib")
DWORD pReturn = 0x45B765;

__declspec(naked) void Machine_Gun_Increase(void)
{
	_asm
      {
		  MOV EBX,DWORD PTR SS:[ESP+10]
		  MOV DWORD PTR DS:[EAX],EDX
		  MOV ESI,DWORD PTR DS:[ESI+14]
		  INC DWORD PTR DS:[ESI]
		  LEA ESI,DWORD PTR SS:[ESP+24]
		  JMP pReturn
      }
}

DWORD WINAPI MainThread(LPVOID)  
{
DetourFunction((BYTE*)0x45B756,(BYTE*)Machine_Gun_Increase);

return 0;  
}  

BOOL WINAPI DllMain ( HMODULE hDll, DWORD dwReason, LPVOID lpReserved )  
{  
DisableThreadLibraryCalls(hDll);  
if ( dwReason == DLL_PROCESS_ATTACH )  
{  
CreateThread(NULL, NULL, MainThread, NULL, NULL, NULL);  
}  
return true;  
}
Maybe it will work. I dont know yet.
I dont wanna bump but can anyone help?
Reason your crashing: Detouring an instruction that is only 2 bytes long ( overwriting something thats 2 bytes long with a 5 byte instruction ). Meaning you're overwriting the instruction that comes next which completely changes everything. Edit: why06 explained this part better than I did, sorry why. ):

Fix: NOP the last byte of the second instruction so that your jump doesn't cause any failure and just execute the instruction in your own function.

Code: ( I tested it, it works for me. My ammo goes up. )
[Highlight=VB]
#include <windows.h>
#include <detours.h>

unsigned long ret = 0x0045B75F+6;

__declspec(naked) void Inc_ammo()
{
__asm
{
inc [esi]
lea esi,dword ptr ss:[esp+0x24]
jmp [ret]
}
}

void MainThread()
{
unsigned long old;
VirtualProtect((void*)0x0045B75F,sizeof(unsigned long),PAGE_EXECUTE_READWRITE,&old);

DetourFunction((BYTE*)0x0045B75F,(BYTE*)Inc_ammo);
*(BYTE*)(0x0045B75F+5) = 0x90;

}

bool __stdcall DllMain(HINSTANCE hInst,unsigned long ulReason, void* lpUseless)
{
if(ulReason == DLL_PROCESS_ATTACH)
{
CreateThread(0,0,(LPTHREAD_START_ROUTINE)MainThrea d,0,0,0);
}
return true;
}
[/Highlight]


You're welcome.
Thank you soo much!

Now just a couple of questions to wrap up this topic, so I end up learning something and not just copy and pasting.

Code:
unsigned long ret = 0x0045B75F+6;
Did you get the 6 because you took over 6 bytes?


Code:
    unsigned long old;

    VirtualProtect((void*)0x0045B75F,sizeof(unsigned long),PAGE_EXECUTE_READWRITE,&old);
    DetourFunction((BYTE*)0x0045B75F,(BYTE*)Inc_ammo);
    *(BYTE*)(0x0045B75F+5) = 0x90;
What is this for?
Code:
0045B75F  |. FF0E           DEC DWORD PTR DS:[ESI]
0045B761  |. 8D7424 24      LEA ESI,DWORD PTR SS:[ESP+24]
6 because overwriting 5 would leave one byte all by itself, so we NOP that so it doesn't get in the way. Since we overwrote those 2 instructions, those are the ones we call/modify in our function. So yes, 6 because we overwrote 6 bytes and we want to jump passed them. :P

Code:
 VirtualProtect((void*)0x0045B75F,sizeof(unsigned long),PAGE_EXECUTE_READWRITE,&old);
This let's us write to memory.

Code:
DetourFunction((BYTE*)0x0045B75F,(BYTE*)Inc_ammo);
This puts the jump from the instruction to our function.

Code:
*(BYTE*)(0x0045B75F+5) = 0x90;
This NOP's the 6th byte in our 2 instructions.
Yay. Im learning!
Thanked and +Rep

All my AssaultCube hacks will have credits to me, you, and why06. Both of you helped me, so I wouldnt be able to make them without you guys. Thanks again.

My last question on this subject:
Do I need VirtualProtect()?
Quote Originally Posted by aanthonyz View Post
Yay. Im learning!
Thanked and +Rep

All my AssaultCube hacks will have credits to me, you, and why06. Both of you helped me, so I wouldnt be able to make them without you guys. Thanks again.

My last question on this subject:
Do I need VirtualProtect()?
If the page you're trying to write to is protected then yes, you need VirtualProtect.
wow, this game is so fun to hack. I code caved health but it turns out that i gave the computer bot unlimited health also, lol.
Quote Originally Posted by aanthonyz View Post
The issue I have with those is that you can only use them if you have the source code. I want to practice without the source.
no no, clienthookin #1 and #2 have disassembly, look through my started threads, posted info about clienthooking in cube2 without source somewhere.
Posts 16–27 of 27 · Page 2 of 2

Post a Reply

Tags for this Thread

None

Talk with us