using ASM

Posts 1–15 of 21 · Page 1 of 2
using ASM
so, using the CE debugger, i found the instruction(s) that decrease my smg ammo in a game. here is a picture of the complete function.



the highlighted instruction is the specific part that changes my ammo by -1. i have a few questions
1. how can i apply this to c++ to NOP or modify it?
2. what is the instruction to increase [esi] by 1?
I think it's something like:

Code:
__asm {mov esi, YOURADDIE}:
But I'm not sure



So @Hell_Demon.
He'll know.

Edit: oh and I think you need to include something. It studio.h I think.
ive never used asm in c++ before, so if i inject that code into the process how do i know that the esi register will be the same as it is in this exerpt?
thanks for the help tho
Quote Originally Posted by kibbles18 View Post
ive never used asm in c++ before, so if i inject that code into the process how do i know that the esi register will be the same as it is in this exerpt?
thanks for the help tho
I' sorry I can't help more, but I'm not really a hacker. I just know quite some C++
you could do a code cave. Here is an example of how your code might be if you wanted to nop the addie that subtracts one from the ammo count:


Code:
  #include <windows.h>
#include <detours.h>

unsigned long return_address = youraddie + how many bits the call is //you can find this out by looking at the OP codes and counting how many pairs of two

// use a naked function so that there is no prolog or epilog and you can right pure asm


__declspec (naked) void Hack()


            __asm
              {
                 NOP                      // This obviously is a nop
                 ret return_address   // This return to the place in memory after the nop
              }
} 

  void Main_Hack()
{
    DetourFunction((BYTE*)addie, (BYTE*)Hack);  //This is to basically detour the function that makes your smg count go down.
}

bool __stdcall DllMain(HINSTANCE hInst,unsigned long ulReason, void* lpUseless) //this is the entry point of a dll
{
    if(ulReason == DLL_PROCESS_ATTACH) // We are saying that if the dll is attatched to the game then do this:
    {
        CreateThread(0,0,(LPTHREAD_START_ROUTINE)Hack_Main,0,0,0); // This starts our hack thread or function
    }
    return true;
} 
 // Hopefully you learned something and not just copying and pasting
If you have any questions feel free to ask.
The above code will not work because of the return instruction (return should not be used, instructions overwritten are not executed, and incorrect syntax for ret). It is also unnecessary to detour your code.

There are two ways you can approach this. The first is to simply nop the instruction. Replace mov dword ptr ds:[esi], edi with two nops.

Code:
inc dword ptr ds:[esi]
You can also replace mov dword ptr ds:[esi], edi with the above instruction, which luckily for you is also two bytes in length (FF 06).

Use WriteProcessMemory or direct memory access via casting addresses to pointers and dereferencing.
my method works, i have used it many times. It is meant to be an injected dll. Your method is an exe that edits the game. Two totally different things.
@258456 why do we have to ret(urn) anything after the NOP? and (BYTE*)(addie) is the address of mov [esi], edi ? or what? wouldnt it be jmp long return_address ?
@Fovea how would i replace the instruction? i have direct memory access.
Quote Originally Posted by kibbles18 View Post
@258456 why do we have to ret(urn) anything after the NOP? and (BYTE*)(addie) is the address of mov [esi], edi ? or what? wouldnt it be jmp long return_address ?
@Fovea how would i replace the instruction? i have direct memory access.
it would be the address of: sub edx, eax , because it is subtracting from your gun ammo.


When you are detouring you are making the code jump to your module/dll that was injected and it is running that code. So when we are done running our code we must return to the point in the code that is after our nop so that the game runs normally, if you don't return then i think the game crashes. Try it and you will see, i am not so sure, but it's not such a big deal.



don't forget to reply back if it worked.
Just overwrite it with the new instruction.
Code:
char *pInstr = "\xFF\x06";
memcpy(dest, pInstr, 2);
Quote Originally Posted by Hell_Demon View Post
Just overwrite it with the new instruction.
how did u get "\xFF\x06" ?
and dest is 0x61DC4FCF ?
Quote Originally Posted by kibbles18 View Post
how did u get "\xFF\x06" ?
and dest is 0x61DC4FCF ?
This:
Quote Originally Posted by Fovea
You can also replace mov dword ptr ds:[esi], edi with the above instruction, which luckily for you is also two bytes in length (FF 06).
0xFF, 0x06 -> "\xFF\x06" as char string :3
Code:
#include <windows.h>
#include "detours.h"
#pragma comment(lib, "detours.lib")

// use a naked function so that there is no prolog or epilog and you can right pure asm

__declspec (naked) void Hack()
{
            __asm
              {
                NOP
              }
} 

void thread()
{
    DetourFunction((BYTE*)(0x5BF94FCF), (BYTE*)Hack);  //This is to basically detour the function that makes your smg count go down.
}

BOOL WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	if( dwReason == DLL_PROCESS_ATTACH )
	{
		CreateThread( NULL, NULL, (LPTHREAD_START_ROUTINE)thread, NULL, NULL, NULL);
	}
	return TRUE;
}
this is my code...
it crashes once i shoot my bullet.. uploading a video of what im doing

@Hell_Demon
@Void
Your naked routine needs to return where ever you hooked.
Quote Originally Posted by Void View Post
Your naked routine needs to return where ever you hooked.
@Void how do i return to where i hooked? can i do something like JMP 0xaddy + 2
Posts 1–15 of 21 · Page 1 of 2

Post a Reply

Tags for this Thread

None

Talk with us