[Possivel][Maybe] Aimbot ...
SIR ...A MPGH ta tão impolgante que agora até me deu vontade de ir assistir CSI Miami 

Code:
typedef struct _Object* (__thiscall *lpGetCameraObject)(unsigned long ulCLTClientShell); lpGetCameraObject GetCameraObject; typedef int (__thiscall *lpGetMeIdxInPlayerInfoList)(unsigned long ulCLTClientShell); lpGetMeIdxInPlayerInfoList GetMeIdxInPlayerInfoList; typedef struct _st3rdPlayerInfo * (__thiscall *lpGet3rdPlayerInfoList)(unsigned long ulCLTClientShell); lpGet3rdPlayerInfoList Get3rdPlayerInfoList; typedef unsigned int (__thiscall *lpIsDeadState)(unsigned long ulCFX); lpIsDeadState IsDeadState; typedef void (__thiscall *lpDrawEngineString)(unsigned long ulBase, char *String, int x, int y, unsigned long Color, bool Shadow); lpDrawEngineString DrawEngineString; GetCameraObject = (lpGetCameraObject) (CShellBase + 0x23950); Get3rdPlayerInfoList = (lpGet3rdPlayerInfoList) (CShellBase + 0x18930); GetMeIdxInPlayerInfoList = (lpGetMeIdxInPlayerInfoList) (CShellBase + 0x18950 ); unsigned long ulCLTClientShell = *(unsigned long*)(CShellBase + 0x6103DC); DrawEngineString = (lpDrawEngineString )(CShellBase + 0x1CAF30); unsigned long ulBase = *(unsigned long*)(CShellBase + 0x66D76C); IsDeadState = (lpIsDeadState)(CShellBase + 0x11A800); unsigned long ulCFX = *(unsigned long *)(ulCLTClientShell + (i * 0x1AC) + 0x77FC);//0x612C ulCPlayerClnt = *(unsigned long *)(ulCLTClientShell + 0x50); (ulCPlayerClnt + 0xCC)//yaw (ulCPlayerClnt + 0xC8)//pitch
Code:
PLAYER_DATA GetMyPlayerData(void)
PLAYER_DATA GetPlayerData(BYTE PlayerNumber)
void SetCrosshairOnEnemy(BYTE PlayerNumber
PLAYER_DATA? Yup, to make things more tidy in my programming, I like to use some structs as well as functions. My PLAYER_DATA structure holds valuable information about a player. Such as:
Code:
typedef struct _PLAYER_DATA {
DWORD baseadd; // base address of this current player
DWORD coordEW; // East/West (X) co-ord
DWORD coordNS; // North/South (Y) co-ord
DWORD coordUD; // Up/Down (Z) co-ord
DWORD coordEWa; // The address of the players EW co-ord
DWORD coordNSa; // The address of the players NS co-ord
DWORD coordUDa; // The address of the players UD (up/down..wtf was i thinking when naming this) co-ord
DWORD lookX; // The players X-axis look (what will change if you move the mouse side to side)
DWORD lookY; // The players Y-axis look (what will change if you move the mouse forwards and backwards)
DWORD lookXa; // The address of the X look
DWORD lookYa; // The address of the Y look
char name; // Holds the current players name
DWORD namea; // The address of the current players name
} PLAYER_DATA;
I don't really know why I put all the addresses for everything in the struct, but hell, might come in use when making something one day. All the stuff in there will come to use when making our aimbot, so here's how to search for each of them (in DFX at least).
The easiest to start with is name, use Artmoney's Text search
Co-ords:
NS - Move north, search increased, move south, search decreased
EW - Move east, search increased, move west, search decreased
UD - Move up (a hill/ladder), search increased, move down, search decreased
LookX - Move mouse left/right, search has changed...set your search range to around the other addies to narrow search down (this value may be different to DFX. In DFX, 0 was east, and it increased as you went anti-clockwise until you got to just before east, which was 0xFFFFFFFF)
LookY - Move mouse forward/backward, search has changed
You should be able to get the player base address from near enough any of these, and a pointer to get it in game. I use 2 pointers, 1 which always points to player 0's (or 1, the 1st player in memory)'s base address, and 1 which always points to the base address of my player. Now we can modify the GetMyPlayerData and GetPlayerData functions to get us this info:
At the top of the C++, I define the bases:
Code:
#define mBase 0xBD63D8 // mBase = My Base, always holds my players base address
#define hBase 0xB0D228 // hBase = Host Base, always holds th
///
PLAYER_DATA GetMyPlayerData(void)
{
PLAYER_DATA Player; // Create a blank PLAYER_DATA struct
ZeroMemory(&Player, sizeof(PLAYER_DATA)); // Initiate it all to 0 (thanks L.Spiro, this solved some problems)
Peek((void*)mBase,(void*)&Player.baseadd,4); // Get our players Base Address from the pointer
Player.coordEWa = Player.baseadd + 0x8; // Get all the addies for everything...the 0x8, 0xC and shit are the offsets I found for DFX
Player.coordNSa = Player.baseadd + 0xC;
Player.coordUDa = Player.baseadd + 0x10;
Player.lookXa = Player.baseadd + 0x14;
Player.lookYa = Player.baseadd + 0x18;
Player.namea = Player.baseadd + 0xF4;
Peek((void*)Player.coordEWa,(void*)&Player.coordEW ,4); // Now we got all the addies, read in the info from em all
Peek((void*)Player.coordNSa,(void*)&Player.coordNS ,4);
Peek((void*)Player.coordUDa,(void*)&Player.coordUD ,4);
Peek((void*)Player.lookXa,(void*)&Player.lookX,4);
Peek((void*)Player.lookYa,(void*)&Player.lookY,4);
Peek((void*)Player.namea,(void*)&Player.name,15);
return Player; // Give our PLAYER_DATA Player, as the return value
}
///
PLAYER_DATA GetPlayerData(BYTE PlayerNum) // Takes the number of the player as a param
{
PLAYER_DATA Player;
ZeroMemory(&Player, sizeof(PLAYER_DATA));
Peek((void*)hBase,(void*)&Player.baseadd,4);
Player.baseadd = Player.baseadd + (PlayerNum*0x388); // 0x388 is the gap between players, starting with player 1
Player.coordEWa = Player.baseadd + 0x8;
Player.coordNSa = Player.baseadd + 0xC;
Player.coordUDa = Player.baseadd + 0x10;
Player.lookXa = Player.baseadd + 0x14;
Player.lookYa = Player.baseadd + 0x18;
Player.namea = Player.baseadd + 0xF4;
Peek((void*)Player.coordEWa,(void*)&Player.coordEW ,4);
Peek((void*)Player.coordNSa,(void*)&Player.coordNS ,4);
Peek((void*)Player.coordUDa,(void*)&Player.coordUD ,4);
Peek((void*)Player.lookXa,(void*)&Player.lookX,4);
Peek((void*)Player.lookYa,(void*)&Player.lookY,4);
Peek((void*)Player.namea,(void*)&Player.name,15);
return Player;
}
///
Now that we've made our functions to collect all the data we need, it's time to get to the core of the aimbot. Got a feeling this is gonna be alot of reading, so if I were you I'd go get a snack and a drink or something, then come back =)
//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//-//
Maths knowledge is needed to make this! If you're useless at maths, and still reading, you're also useless at english for not understanding the knowledge requirements at the top =) Let's start with the X look.
Because DFX works around the East point (, facing Directly east = 0x00000000/0xFFFFFFFF), then all our calculations will be made off it. To help the understanding with this tutorial, I'll include some snazzy little photoshuppered drawings, woo =)
The aimbot works in 4 sectors. This makes things easier when finding out distances. Here are the sectors and how to determine what sector an enemy is in :
Sector 1 = South-East of our position
Sector 2 = South-West of our position
Sector 3 = North-West of our position
Sector 4 = North-East of our position
So, let's add these sectors to our source code. Note that also we have to tell our aimbot what to do if they are, for example, east of us, but the same on the NS axis. No need to put the code for if they are the same on both the NS and the EW axis, as otherwise you won't need it to set an aim for you, you're on them =)
Code:
void SetCrosshairOnEnemy(BYTE PlayerNumber)
{
PLAYER_DATA oP = GetPlayerData(PlayerNumber); // oP = Opposition's Player
PLAYER_DATA cP = GetMyPlayerData(); // cP = Current Player (our player) .. sorry for bad var names :-)
/*Sec 1*/
if(oP.coordEW > cP.coordEW && oP.coordNS <= cP.coordNS)
{
}
/*Sec 2*/
if(oP.coordEW <= cP.coordEW && oP.coordNS < cP.coordNS)
{
}
/*Sec 3*/
if(oP.coordEW < cP.coordEW && oP.coordNS >= cP.coordNS)
{
}
/*Sec 4*/
if(oP.coordEW >= cP.coordEW && oP.coordNS > cP.coordNS)
{
}
}
Now, to get the angle we need to look, we have to make a triangle between the EW axis, us, and the player. Then we have to find the angle of which we are the apex.
This is a top view :
Blue dot = Our player
Red dot = enemy
Green = The triangle we make
Purple = The angle we need to find
Orange = The difference's we need to work out for the angle
Incase you've forgotten Triganometry, then due to the 2 side we can get the easiest we will the Tangent function :
Tan(angle) = Opposite/Adjacent
In all our sectors, the Adjacent is the EW difference, and the Opposite is the NS difference. So let's add some coding to our function :
Code:
void SetCrosshairOnEnemy(BYTE PlayerNumber)
{
PLAYER_DATA oP = GetPlayerData(PlayerNumber);
PLAYER_DATA cP = GetMyPlayerData();
double EWdif; // These need to be double for our Trig calculations to work later on
double NSdif;
/*Sec 1*/
if(oP.coordEW > cP.coordEW && oP.coordNS <= cP.coordNS)
{
EWdif = oP.coordEW - cP.coordEW;
NSdif = cP.coordNS - oP.coordNS;
}
/*Sec 2*/
if(oP.coordEW <= cP.coordEW && oP.coordNS < cP.coordNS)
{
EWdif = cP.coordEW - oP.coordEW;
NSdif = cP.coordNS - oP.coordNS;
}
/*Sec 3*/
if(oP.coordEW < cP.coordEW && oP.coordNS >= cP.coordNS)
{
EWdif = cP.coordEW - oP.coordEW;
NSdif = oP.coordNS - cP.coordNS;
}
/*Sec 4*/
if(oP.coordEW >= cP.coordEW && oP.coordNS > cP.coordNS)
{
EWdif = oP.coordEW - cP.coordEW;
NSdif = oP.coordNS - cP.coordNS;
}
}
Default [Aimbot] Source Code
Credits: tutorial was created by eVoByte added by GM Sobel
Hello :]
I want to show you an example source code for an aimbot. If this is an example, so only experienced user could need this
Here we go! :
Tools needed :
Favourite Memory Searcher ( I use T-Search )
C/C++ Compiler ( I use VC++ )
Game with FPS style view ( This guide uses Delta Force Xtreme v1.6.5.0 )
Code:
At the top of the C++, I define the bases:
Code:
#define mBase 0xBD63D8 // mBase = My Base, always holds my players base address
#define hBase 0xB0D228 // hBase = Host Base, always holds th
///
PLAYER_DATA GetMyPlayerData(void)
{
PLAYER_DATA Player; // Create a blank PLAYER_DATA struct
ZeroMemory(&Player, sizeof(PLAYER_DATA)); // Initiate it all to 0 (thanks L.Spiro, this solved some problems)
Peek((void*)mBase,(void*)&Player.baseadd,4); // Get our players Base Address from the pointer
Player.coordEWa = Player.baseadd + 0x8; // Get all the addies for everything...the 0x8, 0xC and shit are the offsets I found for DFX
Player.coordNSa = Player.baseadd + 0xC;
Player.coordUDa = Player.baseadd + 0x10;
Player.lookXa = Player.baseadd + 0x14;
Player.lookYa = Player.baseadd + 0x18;
Player.namea = Player.baseadd + 0xF4;
Peek((void*)Player.coordEWa,(void*)&Player.coordEW ,4); // Now we got all the addies, read in the info from em all
Peek((void*)Player.coordNSa,(void*)&Player.coordNS ,4);
Peek((void*)Player.coordUDa,(void*)&Player.coordUD ,4);
Peek((void*)Player.lookXa,(void*)&Player.lookX,4);
Peek((void*)Player.lookYa,(void*)&Player.lookY,4);
Peek((void*)Player.namea,(void*)&Player.name,15);
return Player; // Give our PLAYER_DATA Player, as the return value
}
///
PLAYER_DATA GetPlayerData(BYTE PlayerNum) // Takes the number of the player as a param
{
PLAYER_DATA Player;
ZeroMemory(&Player, sizeof(PLAYER_DATA));
Peek((void*)hBase,(void*)&Player.baseadd,4);
Player.baseadd = Player.baseadd + (PlayerNum*0x388); // 0x388 is the gap between players, starting with player 1
Player.coordEWa = Player.baseadd + 0x8;
Player.coordNSa = Player.baseadd + 0xC;
Player.coordUDa = Player.baseadd + 0x10;
Player.lookXa = Player.baseadd + 0x14;
Player.lookYa = Player.baseadd + 0x18;
Player.namea = Player.baseadd + 0xF4;
Peek((void*)Player.coordEWa,(void*)&Player.coordEW ,4);
Peek((void*)Player.coordNSa,(void*)&Player.coordNS ,4);
Peek((void*)Player.coordUDa,(void*)&Player.coordUD ,4);
Peek((void*)Player.lookXa,(void*)&Player.lookX,4);
Peek((void*)Player.lookYa,(void*)&Player.lookY,4);
Peek((void*)Player.namea,(void*)&Player.name,15);
return Player;
}
///
DA uma olha ai @ParkII
DA uma olhada ai @ParkII
@soad
@Capevaldo
@TheVampike
Achei uma base para aimbot , acho que da umas 300 linhas de programação!
@Capevaldo
@TheVampike
Achei uma base para aimbot , acho que da umas 300 linhas de programação!
Vc nunca esta online no , msn , preciso de um cara que saiba decompilar um arquivo executavel e mostrar o codigo fonte , ? existiria tal ser humano?
@Capevaldo
@Capevaldo
@WE11ington com certeza consegue
Só que ele não faz isso para ninguem.
Alem de ele estar desligadão daqui da mpgh.
OBS : Ele manda as pessoas que pedem estudar.
Alem de ele estar desligadão daqui da mpgh.
OBS : Ele manda as pessoas que pedem estudar.
Eu sei, e está certo ele.Ele não tem obrigação de passar as coisas para os outros . .-.
Topic : Se pá é a vip do gellin mano, eu tenho ela e ta parecido mais ou menos, não comparei
Topic : Se pá é a vip do gellin mano, eu tenho ela e ta parecido mais ou menos, não comparei
Estou aprendendo assembly , logo irei tentar reversa , um dia chego lah!
This thread is closed for replies.


