NOP

Posts 1–3 of 3 · Page 1 of 1
NOP
Code:
#include <windows.h>
#define NOP 0x90

void _main();
void unlim_ammo();
void _NOP(PVOID, int);

void _main()
{
     unlim_ammo();
}

void unlim_ammo()
{
     DWORD client = (DWORD)GetModuleHandleA("client.exe");
     DWORD ammo_patch = (DWORD)(client + 0x255F0);
     _NOP((PVOID)ammo_patch, 6);
}

void _NOP(PVOID address, int bytes)
{ 
    DWORD d, ds;
    VirtualProtect(address, bytes, PAGE_EXECUTE_READWRITE, &d);
    memset(address, NOP, bytes);
    VirtualProtect(address,bytes,d,&ds);
}  

BOOL APIENTRY DllMain (HINSTANCE hInst     /* Library instance handle. */ ,
                       DWORD reason        /* Reason this function is being called. */ ,
                       LPVOID reserved     /* Not used. */ )
{
    switch (reason)
    {
      case DLL_PROCESS_ATTACH:
           CreateThread(0, 0, (LPTHREAD_START_ROUTINE)_main, 0, 0, 0);
        break;

      case DLL_PROCESS_DETACH:
        break;

      case DLL_THREAD_ATTACH:
        break;

      case DLL_THREAD_DETACH:
        break;
    }

    /* Returns TRUE on success, FALSE on failure */
    return TRUE;
}
A truly stupid question, but why is my NOP not NOPing?
It probably is (if that is the only factor left - since you should have checked everything else), but it might be getting overwritten or intercepted.

EDIT: Oh yeah, check the return value of VirtualProtect() to see if it actually succeeded.
Although our respective nop functions look pretty much identical, here's mine anyway:

Code:
PBYTE __nop(PVOID,DWORD);
VOID __denop(DWORD,PBYTE,DWORD);

PBYTE __nop(PVOID pAddress, DWORD dwByteCount)
{
    PBYTE pBytes = (PBYTE)new BYTE[dwByteCount];
    DWORD dwOldProt, dwNewProt;
    VirtualProtect(pAddress, dwByteCount, PAGE_EXECUTE_READWRITE, &dwOldProt);
    memcpy((PVOID)pBytes, pAddress, dwByteCount);
    memset(pAddress, 0x90, dwByteCount);
    VirtualProtect(pAddress, dwByteCount, dwOldProt, &dwNewProt);
    return pBytes;
}

VOID __denop(DWORD dwAddress, PBYTE pBytes, DWORD dwByteCount)
{
    DWORD dwOldProt, dwNewProt;
    VirtualProtect((PVOID)dwAddress, (SIZE_T)dwByteCount, PAGE_EXECUTE_READWRITE, &dwOldProt);
    for( unsigned int i = 0; i < dwByteCount; i++)
        memset((PVOID)(dwAddress + i), (int)(pBytes[i]), 1);
    VirtualProtect((PVOID)dwAddress, (SIZE_T)dwByteCount, dwOldProt, &dwNewProt);
}
Use:
Code:
    PBYTE oldBytes = __nop((PVOID)0xDEADBEEF, 6); //nop 6 bytes and store them.
    __denop(0xDEADBEEF, oldBytes, 6); //remove the nop.
One thing to try would be capture the results of VirtualProtect and see if you are in fact being able to change the protection level on the memory page. Other than that it could just simply be your addresses are incorrect or something else entirely.
Posts 1–3 of 3 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us