walkThroughWall

Posts 1–15 of 32 · Page 1 of 3
walkThroughWall
Hi,i want to relase a walk throuh wals ... Is there a string?Or how can i find it?
You can make it with wallmgr
Quote Originally Posted by pceumel View Post
Hi,i want to relase a walk throuh wals ... Is there a string?Or how can i find it?
@darkness99: --' /msgtoshort
@pceumel: do you know how to find clientshell? without that you can't make a walk thru wall
Is clientshell a string in CShell.dll?
Quote Originally Posted by pceumel View Post
Is clientshell a strin in CShell.dll?
It's in CShell but taht's not the right string
Quote Originally Posted by pceumel View Post
Is clientshell a string in CShell.dll?
ClientShell is not a string it's a pointer that points to a class.
And how can i find it with olly? (=
search for "HP" then you'll see a loop:

mov eax,ds: [ecx+esi+6] or something like that.
search for the pointer that is registered in ecx register.
should be some lines above.
I found 0xAAF4C0 ,is this the right one?
Quote Originally Posted by pceumel View Post
I found 0xAAF4C0 ,is this the right one?
not below i said above
it's even more above than "HP"
If you know asm you should know that asm must be read from the bottom to the top like chinese from right to left.
Hi,
i dont know where i must search (can´t find any loop there):
 
ASM
07BB7AB6 68 EC41E807 PUSH cshell.07E841EC ; ASCII "HP" <- Begin
07BB7ABB 53 PUSH EBX
07BB7ABC 68 CE610000 PUSH 61CE
07BB7AC1 FFD0 CALL EAX
07BB7AC3 8B4F 74 MOV ECX,DWORD PTR DS:[EDI+74]
07BB7AC6 69C9 C0010000 IMUL ECX,ECX,1C0
07BB7ACC 50 PUSH EAX
07BB7ACD 8D5431 06 LEA EDX,DWORD PTR DS:[ECX+ESI+6]
07BB7AD1 52 PUSH EDX
07BB7AD2 8D4424 30 LEA EAX,DWORD PTR SS:[ESP+30]
07BB7AD6 68 E041E807 PUSH cshell.07E841E0 ; ASCII "%s %s : %d"
07BB7ADB 50 PUSH EAX
07BB7ADC 90 NOP
07BB7ADD E8 7BFC816A CALL MSVCR80.sprintf
07BB7AE2 83C4 14 ADD ESP,14
07BB7AE5 8D4C24 24 LEA ECX,DWORD PTR SS:[ESP+24]
07BB7AE9 51 PUSH ECX
07BB7AEA 8B0D C0F46508 MOV ECX,DWORD PTR DS:[865F4C0]
07BB7AF0 E8 1B752000 CALL cshell.07DBF010
07BB7AF5 8B0D 100BF007 MOV ECX,DWORD PTR DS:[7F00B10] ; cshell.07F09050
07BB7AFB 895C24 10 MOV DWORD PTR SS:[ESP+10],EBX
07BB7AFF 895C24 14 MOV DWORD PTR SS:[ESP+14],EBX
07BB7B03 895C24 18 MOV DWORD PTR SS:[ESP+18],EBX
07BB7B07 895C24 1C MOV DWORD PTR SS:[ESP+1C],EBX
07BB7B0B 8BE8 MOV EBP,EAX
07BB7B0D 8B81 888B0100 MOV EAX,DWORD PTR DS:[ECX+18B88]
07BB7B13 8B50 04 MOV EDX,DWORD PTR DS:[EAX+4]
07BB7B16 895424 10 MOV DWORD PTR SS:[ESP+10],EDX
07BB7B1A 8B70 08 MOV ESI,DWORD PTR DS:[EAX+8]
07BB7B1D 897424 14 MOV DWORD PTR SS:[ESP+14],ESI
07BB7B21 8B58 0C MOV EBX,DWORD PTR DS:[EAX+C]
07BB7B24 8B35 880BF007 MOV ESI,DWORD PTR DS:[7F00B88]
07BB7B2A 895C24 18 MOV DWORD PTR SS:[ESP+18],EBX
07BB7B2E 8B40 10 MOV EAX,DWORD PTR DS:[EAX+10]
07BB7B31 2BDA SUB EBX,EDX
07BB7B33 2BF3 SUB ESI,EBX
07BB7B35 83EE 0D SUB ESI,0D
07BB7B38 894424 1C MOV DWORD PTR SS:[ESP+1C],EAX
07BB7B3C 8D141E LEA EDX,DWORD PTR DS:[ESI+EBX]
07BB7B3F 8D4424 10 LEA EAX,DWORD PTR SS:[ESP+10]
07BB7B43 897424 10 MOV DWORD PTR SS:[ESP+10],ESI
07BB7B47 895424 18 MOV DWORD PTR SS:[ESP+18],EDX
07BB7B4B 8B89 888B0100 MOV ECX,DWORD PTR DS:[ECX+18B88]
07BB7B51 50 PUSH EAX
07BB7B52 E8 F9FC1A00 CALL cshell.07D67850
07BB7B57 8B4C24 1C MOV ECX,DWORD PTR SS:[ESP+1C]
07BB7B5B 83C1 05 ADD ECX,5
07BB7B5E 2BDD SUB EBX,EBP
07BB7B60 51 PUSH ECX
07BB7B61 895C24 24 MOV DWORD PTR SS:[ESP+24],EBX
07BB7B65 DB4424 24 FILD DWORD PTR SS:[ESP+24]
07BB7B69 DC0D D841E807 FMUL QWORD PTR DS:[7E841D8]
07BB7B6F E8 EC5A2B00 CALL cshell.07E6D660
07BB7B74 8B4F 6C MOV ECX,DWORD PTR DS:[EDI+6C]
07BB7B77 2BF0 SUB ESI,EAX
07BB7B79 56 PUSH ESI
07BB7B7A 8D5424 2C LEA EDX,DWORD PTR SS:[ESP+2C]
07BB7B7E 52 PUSH EDX
07BB7B7F 6A 01 PUSH 1
07BB7B81 E8 7A831B00 CALL cshell.07D6FF00
07BB7B86 8B8C24 A4000000 MOV ECX,DWORD PTR SS:[ESP+A4]
07BB7B8D 5F POP EDI
07BB7B8E 5E POP ESI
07BB7B8F 5D POP EBP
07BB7B90 5B POP EBX
07BB7B91 33CC XOR ECX,ESP
07BB7B93 E8 98592B00 CALL cshell.07E6D530
07BB7B98 81C4 98000000 ADD ESP,98
07BB7B9E C3 RETN ; <-End of function



Is the pointer into this block?I think this is the function ,or isn´t it?
Look up and you'll see what I mean.
I told you above (UP) but you constantly look down. if you don't know where is up and where is down then I can't help you.
btw you found at least where approximately it can be.
Is it in the part above, or is it higher?
I hope its this one: 0x350B04
this is ltclient not ltclientshell
but add 0xC to this and it's the clientshell

Code:
#define LTClient 0x350B04
#define LTClientShell 0x350B10
now you need the PlayerClient
easy one
mov PlayerClient, DWORD PTR DS: [LTClientShell+50]
try to find what PlayerClient is.
0x350B60 ?
Posts 1–15 of 32 · Page 1 of 3

Post a Reply

Tags for this Thread

Talk with us