Messing with Addresses

Posts 1–15 of 34 · Page 1 of 3
Messing with Addresses
Would I manipulate both of these in the same way?

0x94E7A5
0xF3A


I have seen source code hacks that contain numbers like 0xF3A, but I dont understand how people manipulate them.

Lets say 0xF3A is AmmoDamage for a certain game. How would I change this to do no damage or MEGA FALCON PAWWNNNCHH damage?

I know that for something like 0x94E7A5, I would just use WriteProcessMemory and then insert my value.
For a second I thought I must be skipping time or something, because I could have sworn I answered that exact same question. So I searched and found the post: http://www.mpgh.net/forum/31-c-c/261...ml#post3624551 whew... I'm not losing my mind.

You replied to it too I see, you just got what I said completely wrong. You can't assign the numbers themselves values, I was just showing you what those numbers were equal to in decimal. I just opened up calc.exe and typed it in =/

The point was to get you to realize they are just numbers. And the C++ compiler is just gonna treat them like numbers, and they don't do anything numbers cant do. It's just a way of writing numbers. Do you get that they are numbers?

Okay moving on. Adresses are just locations in memory. These location go from 0x00000000 to 0xFFFFFFFF, not that all that memory is ever actually used, unless your running some kind of AI or VM, and then you might need to use 64bit addresses, not that I'm sure how that would work. Back to Addys...

So do you get Addys are just locations in memory? What's important is understanding what's at those locations, which could be values, pointers, code. The second thing is understanding how it gets there and why its there. Memory is the Wild wild west. There's no laws or rules. It's completely unstructured. Data could be code, code could be data. So understanding how Programs are loaded and run in memory is pretty important.

I can go into a huge fucking book like description, but I realized that would take to long. Just know that addys are not important. Data is important. Data is like a book on the shelf, while Addy's are the shelf. The librarian can tell you a book is on a shelf, but that book, that valuable information can truly be anywhere, even take off the shelf.

So when we as hackers look for Addys and find addys, what we are really searching for is data. We can search specific modules, or the whole library (all of memory) for specific data. When we find that data it is stored in a location, an address.

When that address is always the same, we tend to use 0x76443B92, all 8 digits to describe its location, when it is not static, or an offset, from another location we tend to use smaller numbers, since offsets are well... offsets from another location. 0xF3A is likely an offset from some other kind of addresss. Now We can have offsets of offsets of offsets of etc... but always an offset relies on some static location ( A location that doesn't change every time the application is loaded).

I've seen too many scriptkiddies come through obsessed with Addy's yet have no idea what they are or what they do. They are just addresses, locations, zip codes, postal addresses, by which we reference data. Their only point is to provide a way to find or locate some data in memory.

Now about the specifics of actually using an offset vs. an address, that depends completely on what kind of data we are talking about. So I could give you a specific example, but you have to understand it in no way covers every possibility, so I rather explained the general idea. Someone else can give you an example if you would like, my fingers are tired.
Quote Originally Posted by why06 View Post
For a second I thought I must be skipping time or something, because I could have sworn I answered that exact same question. So I searched and found the post: http://www.mpgh.net/forum/31-c-c/261...ml#post3624551 whew... I'm not losing my mind.

You replied to it too I see, you just got what I said completely wrong. You can't assign the numbers themselves values, I was just showing you what those numbers were equal to in decimal. I just opened up calc.exe and typed it in =/

The point was to get you to realize they are just numbers. And the C++ compiler is just gonna treat them like numbers, and they don't do anything numbers cant do. It's just a way of writing numbers. Do you get that they are numbers?

Okay moving on. Adresses are just locations in memory. These location go from 0x00000000 to 0xFFFFFFFF, not that all that memory is ever actually used, unless your running some kind of AI or VM, and then you might need to use 64bit addresses, not that I'm sure how that would work. Back to Addys...

So do you get Addys are just locations in memory? What's important is understanding what's at those locations, which could be values, pointers, code. The second thing is understanding how it gets there and why its there. Memory is the Wild wild west. There's no laws or rules. It's completely unstructured. Data could be code, code could be data. So understanding how Programs are loaded and run in memory is pretty important.

I can go into a huge fucking book like description, but I realized that would take to long. Just know that addys are not important. Data is important. Data is like a book on the shelf, while Addy's are the shelf. The librarian can tell you a book is on a shelf, but that book, that valuable information can truly be anywhere, even take off the shelf.

So when we as hackers look for Addys and find addys, what we are really searching for is data. We can search specific modules, or the whole library (all of memory) for specific data. When we find that data it is stored in a location, an address.

When that address is always the same, we tend to use 0x76443B92, all 8 digits to describe its location, when it is not static, or an offset, from another location we tend to use smaller numbers, since offsets are well... offsets from another location. 0xF3A is likely an offset from some other kind of addresss. Now We can have offsets of offsets of offsets of etc... but always an offset relies on some static location ( A location that doesn't change every time the application is loaded).

I've seen too many scriptkiddies come through obsessed with Addy's yet have no idea what they are or what they do. They are just addresses, locations, zip codes, postal addresses, by which we reference data. Their only point is to provide a way to find or locate some data in memory.

Now about the specifics of actually using an offset vs. an address, that depends completely on what kind of data we are talking about. So I could give you a specific example, but you have to understand it in no way covers every possibility, so I rather explained the general idea. Someone else can give you an example if you would like, my fingers are tired.
TL;DR: Addresses change so we use distance to find data from a specific location.
Quote Originally Posted by Void View Post
TL;DR: Addresses change so we use distance to find data from a specific location.
Or basically what he said.

FML
I understand the post completely. I did learn something new. I thought offsets were mini-addresses. I know how to mess with normal static addresses and how to find them. I was just completely lost with the mini ones. You answered my questions 98% thanks!

My last 2% is an example on how to change offsets?
Any help with that?
Changing an offset would be like changing any other data at a static address. Where you might use an offset is when your referencing data in a class.

If 0x88888888 was the Player class. Offset 0x2F might be Health, so to change a players health. I would do something like
Code:
LPVOID PlayerClass = 0x88888888;
LPVOID Health = (PlayerClass + 0x2F);
*(int*)Health = 100;
Atleast I think so, that casting may not work. My coding is a little rusty since I've been focusing on reversing lately, but I'm starting to pick it back up again, so I should get back up to speed soon.
Quote Originally Posted by why06 View Post
Changing an offset would be like changing any other data at a static address. Where you might use an offset is when your referencing data in a class.

If 0x88888888 was the Player class. Offset 0x2F might be Health, so to change a players health. I would do something like
Code:
LPVOID PlayerClass = 0x88888888;
LPVOID Health = (PlayerClass + 0x2F);
*(int*)Health = 100;
Atleast I think so, that casting may not work. My coding is a little rusty since I've been focusing on reversing lately, but I'm starting to pick it back up again, so I should get back up to speed soon.
well so you are telling me that I can change the value of a specific game without losing time to write in it? If so can u make a advanced tutorial here.
So just to ask if I do:
Code:
DWORD *CG = (DWORD*)0x000000; //Blah fail addy ;)

DWORD Fps = *(DOWRD*)CG + 0x00; //Still fail

*(DWORD*)Fps = 1;
Will set the FPS Address Value to 1 and set the cg_fps variable to 1?
PS:
I used for example modern warfare 2. CG is the main class of mw2, or something like that.
Quote Originally Posted by user590177 View Post

Code:
DWORD *CG = (DWORD*)0x000000; //Blah fail addy ;)

DWORD Fps = *(DOWRD*)CG + 0x00; //Still fail

*(DWORD*)Fps = 1;
Will set the FPS Address Value to 1 and set the cg_fps variable to 1?
No it won't. but this will:
Code:
DWORD *CG = (DWORD*)0x000000; //Blah fail addy ;)

DWORD* Fps = (CG + 0x00); //Still fail

*Fps = 1;
Why will this change Fps's value:
Code:
DWORD *CG = (DWORD*)0x000000; //Blah fail addy ;)

DWORD* Fps = (CG + 0x00); //Still fail

*Fps = 1;
But this one wont?:
Code:
DWORD *CG = (DWORD*)0x000000; //Blah fail addy ;)

DWORD Fps = *(DOWRD*)CG + 0x00; //Still fail

*(DWORD*)Fps = 1;

What is the difference between these lines?
Code:
*(DWORD*)Fps = 1;
Code:
*Fps = 1;
Thank you. Im going to try this out...with an outdated game.
Yup @ why ^^

Also my new avatar is smexy ;o
Quote Originally Posted by Hell_Demon View Post
Yup @ why ^^

Also my new avatar is smexy ;o
Lol. Omg, that's only the second time I've ever seen you change your avatar HD. o_O
FUUUUUUUUUUCK! This language is like dreamed. I mean it writes itself the value to the memory, without losing time to write lines of coding for a memory writing function... :O
It's not the third line so much as the second line
Code:
DWORD Fps = *(DOWRD*)CG + 0x00; //Still fail
That gets the Fps, but it doesn't get the address of the Fps, so there's no way you can set the Fps to anything else, because Fps doesn't point to that address.

Also good programming practices, don't use any more advanced casting then what you can understand. A several Simpler cast is always better the a complex one-liner. also always use () around math stuff: when ur +,-,*,/, etc. This might work, *(DOWRD*)CG + 0x00, but unless you know the C++ order of operations by heart, I would type it like this instead *(DOWRD*)(CG + 0x00)
Ahh, I understand now. Thanks.
Posts 1–15 of 34 · Page 1 of 3

Post a Reply

Tags for this Thread

None

Need help?