~FALLEN~ Q & A ( Coding Only )

Posts 76–90 of 108 · Page 6 of 8
Quote Originally Posted by BlackLite View Post
how to find LTCLIENT ? mmz
FogEnable 0 (im not sure) 0x3....
Quote Originally Posted by ~FALLEN~ View Post
Virtual method table - Wikipedia, the free encyclopedia

Example:
*reinterpret_cast< unsigned long* >( &VTable[Index ] ) = reinterpret_cast< unsigned long >( YourFunction );
Woah, hold up. So you are replacing the virtual function with your own function? I understand what you're doing, but doesn't this mean that the real virtual function such as dip and es won't ever be called?
Quote Originally Posted by 258456 View Post
Woah, hold up. So you are replacing the virtual function with your own function? I understand what you're doing, but doesn't this mean that the real virtual function such as dip and es won't ever be called?
No, just redirect flow back into the original function when you're done
Quote Originally Posted by ~FALLEN~ View Post
No, just redirect flow back into the original function when you're done
Hmm... Well, this is a lot more simple than what i have been doing. I would think that this would be easily detected by xtrap since changing the address of a vtable function in directx is a pretty major adjustment. Well, i guess you learn new things everyday. Good job @~FALLEN~ on your method. Simple is the way to go, lol. This is definitely going to change my hooking methods, hehe.
Quote Originally Posted by 258456 View Post
Woah, hold up. So you are replacing the virtual function with your own function? I understand what you're doing, but doesn't this mean that the real virtual function such as dip and es won't ever be called?
it is really easy just declare your function like the original one
first you define the original function like this:
Code:
typedef HRESULT (WINAPI* oEndScene)            (IDIRECT3DCREATE9 pDevice);
oEndScene pEndScene; //pointer to original function
then your function:
Code:
HRESULT WINAPI myEndScene(LPDIRECT3DDEVICE9 pDevice) //WINAPI like the original function ; )
{
    return pEndScene(pDevice);
}
ofc you should backup the original pointer to pEndScne before replacing it with your own..
Quote Originally Posted by giniyat101 View Post
it is really easy just declare your function like the original one
first you define the original function like this:
Code:
typedef HRESULT (WINAPI* oEndScene)            (IDIRECT3DCREATE9 pDevice);
oEndScene pEndScene; //pointer to original function
then your function:
Code:
HRESULT WINAPI myEndScene(LPDIRECT3DDEVICE9 pDevice) //WINAPI like the original function ; )
{
    return pEndScene(pDevice);
}
ofc you should backup the original pointer to pEndScne before replacing it with your own..
Ya i know that gini, but what fallen was suggesting is changing the address of the endscene function in the vtable to your own. Usually I hook into the function itself i never even dared to change the address of the function.
Quote Originally Posted by giniyat101 View Post
it is really easy just declare your function like the original one
first you define the original function like this:
Code:
typedef HRESULT (WINAPI* oEndScene)            (IDIRECT3DCREATE9 pDevice);
oEndScene pEndScene; //pointer to original function
then your function:
Code:
HRESULT WINAPI myEndScene(LPDIRECT3DDEVICE9 pDevice) //WINAPI like the original function ; )
{
    return pEndScene(pDevice);
}
ofc you should backup the original pointer to pEndScne before replacing it with your own..
oh my /double facepalm

Code:
long __stdcall EndSceneHooked( IDirect3DDevice9* pDevice ){

return reinterpret_cast< long( __stdcall* )( IDirect3DDevice9* ) >(OriginalEndScenePointer)( pDevice );
}
no need for extra allocation = wasted memory
Quote Originally Posted by ~FALLEN~ View Post
oh my /double facepalm

Code:
long __stdcall EndSceneHooked( IDirect3DDevice9* pDevice ){

return reinterpret_cast< long( __stdcall* )( IDirect3DDevice9* ) >(OriginalEndScenePointer)( pDevice );
}
no need for extra allocation = wasted memory
never knew that typedef takes part of memory
thanks again
Quote Originally Posted by giniyat101 View Post
never knew that typedef takes part of memory
thanks again
doesn't, but the pointer you make *pEndScene* or w.e you decide to name it, does.
Quote Originally Posted by ~FALLEN~ View Post
doesn't, but the pointer you make *pEndScene* or w.e you decide to name it, does.
you used another pointer
OriginalEndScenePointer in your case.. so same allocated size
anyways 4 bytes is not a big cost of memory
Quote Originally Posted by giniyat101 View Post
you used another pointer
OriginalEndScenePointer in your case.. so same allocated size
anyways 4 bytes is not a big cost of memory
this is true, but there's ways to avoid this Was just psudo code.
Can OHK working with Bypass?
Quote Originally Posted by [G]a[M]e[R] View Post
Can OHK working with Bypass?
No.. it's not detected by Xtrap Only Client Error nothing to do with Bypass
/
Posts 76–90 of 108 · Page 6 of 8

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?