SolvedProblem With Memory Reading

Posts 1–15 of 17 · Page 1 of 2
Problem With Memory Reading
Hello, it's my first post here. First to say english isn't my primary language so it could be understandable sometimes.
I started programming with visual basic a while ago. I tried yesterday to make my first memory reading and writing program but i failed.
I sew this topic: http://www.mpgh.net/forum/33-visual-...vb-2008-a.html
so i tried to make everything perfect and it was perfect. I was trying to read the text in notepad by memory reading but without a succsses.
My question is how to point to the program what it have to read. I mean i found this thing - "&H26FFA8", but i have no idea what is this and it seems that it's wrong. i've read the whole topic from above but... So i will appriciate it if someone tell me what is this thing "&H26FFA8" and how do i find it.
My code seems to be perfect but when i click the button with this code: TextBox1.Text = Memory_ReadString(&H26FFA8, 5).ToString
I get this:
its a memory location in a program.

all your program is doing is pulling the data from it, and putting it into a textbox.

nothing more, nothing less.
we cant tell you what that memory location is, because its just a memory location.
kind of like, a single line of code in a program, except its even more useless than that.
maybe even, a single part of a line of code.
Post a pic of the code you used to write the string. Dont attach it, put linkhere so we can see it straight away.
If 26FFA8 is indeed the correct address, it might be in the wrong string format.
Quote Originally Posted by *****179 View Post
its a memory location in a program.

all your program is doing is pulling the data from it, and putting it into a textbox.

nothing more, nothing less.
we cant tell you what that memory location is, because its just a memory location.
kind of like, a single line of code in a program, except its even more useless than that.
maybe even, a single part of a line of code.
ok ty for the information i appriciate it.

Quote Originally Posted by Pingo View Post
Post a pic of the code you used to write the string. Dont attach it, put linkhere so we can see it straight away.
If 26FFA8 is indeed the correct address, it might be in the wrong string format.
ok i couldn't understand which part of the code u exacly want so i gonna post the one for memroy read.
That code is alittle hard to read, so it'l be easier to do alittle spoon feeding.
Your read string returns a unicode string type (2 bytes per char) Maybe you need to be looking at ascii.
You dont need to loop the readprocessmemory or bitconvertor.
95% of the time you dont need to use Openprocess, rare cases you do.
You dont need Closehandle, system.diagnostics will close it for you.

Try this
Imports
Code:
Imports System.Runtime.InteropServices
Imports System.Text.Encoding
API
Code:
    <DllImport("kernel32.dll")> _
    Public Shared Function ReadProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As Integer, ByVal buffer As Byte(), ByVal size As Integer, ByVal lpNumberOfBytesRead As Integer) As Boolean
    End Function
And a piece of code i just put together. May need tweaking, i dont code in this language
Code:
    Private Function ReadString(ByVal Address As Integer, ByVal UnicodeType As Boolean, ByVal ProcessName As String) As String
        Dim Proc = Process.GetProcessesByName(ProcessName)
        If Proc.Length = 0 Then
            Return String.Empty 'Return blank string if process isnt open
        End If
        Dim buff(0 To 120) As Byte
        If ReadProcessMemory(Proc(0).Handle, Address, buff, buff.Length, 0) Then 'if read, contintue
            Dim tmp = If(UnicodeType, Unicode.GetString(buff), ASCII.GetString(buff))
            If (tmp <> String.Empty) Then
                Dim LastChar As Integer = tmp.IndexOf("  ", StringComparison.Ordinal)
                Return If(LastChar = -1, tmp, tmp.Substring(0, LastChar)) 'returns the cut string
            End If
        End If
        Return String.Empty
    End Function
Try these one at a time. Just replace it with your processname
Code:
TextBox1.Text = ReadString(&H26FFA8, False, "Processname")
TextBox1.Text = ReadString(&H26FFA8, True, "Processname")
The first one with False will return Ascii, the other with True will return unicode.
If these dont work, maybe you have the wrong address.
Quote Originally Posted by Pingo View Post
That code is alittle hard to read, so it'l be easier to do alittle spoon feeding.
Your read string returns a unicode string type (2 bytes per char) Maybe you need to be looking at ascii.
You dont need to loop the readprocessmemory or bitconvertor.
95% of the time you dont need to use Openprocess, rare cases you do.
You dont need Closehandle, system.diagnostics will close it for you.

Try this
Imports
Code:
Imports System.Runtime.InteropServices
Imports System.Text.Encoding
API
Code:
    <DllImport("kernel32.dll")> _
    Public Shared Function ReadProcessMemory(ByVal hProcess As IntPtr, ByVal lpBaseAddress As Integer, ByVal buffer As Byte(), ByVal size As Integer, ByVal lpNumberOfBytesRead As Integer) As Boolean
    End Function
And a piece of code i just put together. May need tweaking, i dont code in this language
Code:
    Private Function ReadString(ByVal Address As Integer, ByVal UnicodeType As Boolean, ByVal ProcessName As String) As String
        Dim Proc = Process.GetProcessesByName(ProcessName)
        If Proc.Length = 0 Then
            Return String.Empty 'Return blank string if process isnt open
        End If
        Dim buff(0 To 120) As Byte
        If ReadProcessMemory(Proc(0).Handle, Address, buff, buff.Length, 0) Then 'if read, contintue
            Dim tmp = If(UnicodeType, Unicode.GetString(buff), ASCII.GetString(buff))
            If (tmp <> String.Empty) Then
                Dim LastChar As Integer = tmp.IndexOf("  ", StringComparison.Ordinal)
                Return If(LastChar = -1, tmp, tmp.Substring(0, LastChar)) 'returns the cut string
            End If
        End If
        Return String.Empty
    End Function
Try these one at a time. Just replace it with your processname
Code:
TextBox1.Text = ReadString(&H26FFA8, False, "Processname")
TextBox1.Text = ReadString(&H26FFA8, True, "Processname")
The first one with False will return Ascii, the other with True will return unicode.
If these dont work, maybe you have the wrong address.
OK i tried this way i get: য়ȃ৙ȃ৛ȃঢ়ȃ়ȃ৉ȃ (i should get "asd") Triend with unicode and ascii almost the same result
i tought my address is wrong. How could i find it my self becouse i found this one with google...
You need a memory scanner. I use cheat engine. Just attach it to the process, from the drop down list choose Text.
scan the value, if no results, tick the unicode box.
Quote Originally Posted by Pingo View Post
You need a memory scanner. I use cheat engine. Just attach it to the process, from the drop down list choose Text.
scan the value, if no results, tick the unicode box.
The address happend to be: 000AB980 but, i get this :
Quote Originally Posted by Pwnographer View Post
The address happend to be: 000AB980 but, i get this :
You need to prefix the address with "&H" in Visual Basic when using hexadecimal numbering.

i.e
Code:
TextBox1.Text = ReadString(&H000AB980, True, "notepad")
Quote Originally Posted by Broderick View Post


You need to prefix the address with "&H" in Visual Basic when using hexadecimal numbering.

i.e
Code:
TextBox1.Text = ReadString(&H000AB980, True, "notepad")
Finally worked... thanks man. Also thanks to the guy who gave me propper code and the one who explained me what was that thing.
I wouldnt say its the proper code, just a dirty function i coded up.
AB980 is hex, 702848 in dec form.
You can put it without &h TextBox1.Text = ReadString(702848, True, "notepad")
But if its hex, you need to tell VB its hex using &h.
I code in C# so id need to put 0xAB980, 0x meaning hex aswell.
This is a quick function I just wrote to read a string from the remote process:

Code:
    Private Shared Function ReadRemoteString(ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, Optional ByVal encoding As Encoding = Nothing) As String
        If encoding Is Nothing Then encoding = System.Text.Encoding.ASCII 'default encoding value.

        Dim builder As New StringBuilder() 'easiest and cleanest way to build an unknown-length string.
        Dim buffer(255) As Byte 'fucking despise VB's array declarations
        Dim nbytes As Integer = 0
        Dim terminator As Integer = -1

        While terminator < 0 AndAlso ReadProcessMemory(hProcess, lpAddress, buffer, buffer.Length, nbytes) AndAlso nbytes > 0
            lpAddress = New IntPtr(lpAddress.ToInt32() + nbytes) 'advance where we're reading from.
            nbytes = builder.Length 'micro-optimization for .IndexOf
            builder.Append(encoding.GetString(buffer)) 'append the data to the StringBuilder
            terminator = builder.ToString().IndexOf(ControlChars.NullChar, nbytes) 'check if there's a null-byte in the string yet (strings are null-terminated)
        End While

        Return builder.ToString().Substring(0, terminator) 'return the data up til the null terminator.
    End Function
My ReadProcessMemory P/Invoke was this:
Code:
    <DllImport("kernel32.dll")>
    Private Shared Function ReadProcessMemory(ByVal hProcess As IntPtr, ByVal lpAddress As IntPtr, ByVal lpBuffer As Byte(), ByVal szBuffer As Integer, <Out()> ByRef nBytesRead As Integer) As <MarshalAs(UnmanagedType.Bool)> Boolean
    End Function
The following imports are required:
Code:
Imports System.Text
Imports System.Runtime.InteropServices
An example usage would be this:

Code:
Dim hProcess As IntPtr = OpenProcess( ... )
Dim value As String = ReadRemoteString(hProcess, New IntPtr(&H1F028), Encoding.Unicode)
MessageBox.Show(value)
Quote Originally Posted by Broderick View Post
fucking despise VB's array declarations
haha i know how you feel! I hate the syntax aswell.
Why prople say vb is easier i'll never know. I personally think C# is.
Quote Originally Posted by Pingo View Post
haha i know how you feel! I hate the syntax aswell.
Why prople say vb is easier i'll never know. I personally think C# is.
The whole language is idiotic. Such stupid differences that there is no need for.

I.e, in VB:
Code:
Dim buffer(255) As Byte
Creates a fixed-size array of bytes that contains 256 elements.

In virtually every other common language known to man
Code:
byte[] buffer = new byte[256];
Is needed to create an array of bytes that contains 256 elements. For some reason, the people in charge of the VB syntax decided to make the numerical notation describe the upper index of the array rather than the size of the array...stupid as shit.
Quote Originally Posted by Broderick View Post


The whole language is idiotic. Such stupid differences that there is no need for.

I.e, in VB:
Code:
Dim buffer(255) As Byte
Creates a fixed-size array of bytes that contains 256 elements.

In virtually every other common language known to man
Code:
byte[] buffer = new byte[256];
Is needed to create an array of bytes that contains 256 elements. For some reason, the people in charge of the VB syntax decided to make the numerical notation describe the upper index of the array rather than the size of the array...stupid as shit.
You can change that from compiler options and make it like C#
Posts 1–15 of 17 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us