[Source] Round Ender Code

Posts 1–15 of 15 · Page 1 of 1
[Source] Round Ender Code
This is the code that is used to end the game in: TEKNOMW3 1.4.382 ONLY
Thanks -InSaNe- for the origional hint which led me to find Hooch's code. So thanks Hooch for the Magic Number Pattern/Mask

Code:
#include <Windows.h>
#include <iostream>

//PATTERN INFO FOR MAGIC NUMBER
#define MAGIC_NUMBER_PATTERN    "\xa1\x00\x00\x00\x00\x8d\x94\x24\x04\x08\x00\x00\x52\x56\x50\x68\x00\x00\x00\x00\xe8\x00\x00\x00\x00\x8b\x8c\x24\x18\x0c\x00\x00\x50\x51\xe8\x00\x00\x00\x00\x83\xc4\x18"
#define MAGIC_NUMBER_MASK        "x????xxxxxxxxxxx????x????xxxxxxxxxx????xxx" // +1  

//Definitions for PROCESSCOMMAND
typedef int (__cdecl *ProcessCommandCode)(int *defArg, char *Command);
ProcessCommandCode ProcessCommand = (ProcessCommandCode)0x00429920;

//Required for FIND PATTERN
bool bDataCompare( const BYTE* pData, const BYTE* bMask, const char* szMask ) 
	{ 
	for( ; *szMask; ++szMask, ++pData, ++bMask ) 
		if( *szMask == 'x' && *pData != *bMask )  
			return false; 
	return ( *szMask ) == NULL; 
	} 

//General FIND PATTERN Function
DWORD FindPattern( DWORD baseAddress, DWORD sizeOfModule, BYTE *bMask, char* szMask ) 
	{ 
	for( DWORD i=0; i < sizeOfModule; i++ ) 
		if( bDataCompare( ( BYTE* )( baseAddress + i ), bMask, szMask) ) 
			return ( DWORD )( baseAddress + i ); 
	return NULL; 
	} 

//Make Sure Module is injected into the right process or do nothing.
bool IsModuleReady()
	{
	if( GetModuleHandleA( "iw5mp.exe" ) != NULL )
		return true;

	return false;
	}

//FindMagicNumber
DWORD WINAPI GetMagicNumberAddress()
	{
	while( !IsModuleReady()) Sleep(50);
	DWORD *MagicNumber = (DWORD*)*(DWORD*)(FindPattern((DWORD)GetModuleHandleA("iw5mp.exe"), 0xFFFFFFFF, (BYTE*)MAGIC_NUMBER_PATTERN, MAGIC_NUMBER_MASK) + 1);
	return *MagicNumber;

	}

//RoundEnder Activates on END Button
DWORD WINAPI EndRound(LPVOID threadArgs)
	{
	char buffer[32];
	while(1)
		{
		if(GetAsyncKeyState(VK_END))
			{
			sprintf(buffer, "mr %d -1 endround;", (DWORD)GetMagicNumberAddress());
			ProcessCommand(0, buffer);
			Sleep(200);
			}
		}
	return 0;
	}

//Main() Function
BOOL APIENTRY DllMain(HANDLE hDllHandle, DWORD dwReason, LPVOID lpreserved)
	{
	DWORD threadID;
	switch(dwReason)
		{
	case DLL_PROCESS_ATTACH:
		CreateThread(NULL, 0, EndRound, NULL, 0, &threadID); //Create Round End Thread.
	case DLL_PROCESS_DETACH:
		break;
		}
	return true;
	}
Quote Originally Posted by Kenshin13 View Post
This is the code that is used to end the game in: TEKNOMW3 1.4.382 ONLY
Thanks -InSaNe- for the origional hint CodMaster for the Magic Number Pattern/Mask

Code:
#include <Windows.h>
#include <iostream>

//PATTERN INFO FOR MAGIC NUMBER
#define MAGIC_NUMBER_PATTERN    "\xa1\x00\x00\x00\x00\x8d\x94\x24\x04\x08\x00\x00\x52\x56\x50\x68\x00\x00\x00\x00\xe8\x00\x00\x00\x00\x8b\x8c\x24\x18\x0c\x00\x00\x50\x51\xe8\x00\x00\x00\x00\x83\xc4\x18"
#define MAGIC_NUMBER_MASK        "x????xxxxxxxxxxx????x????xxxxxxxxxx????xxx" // +1  

//Definitions for PROCESSCOMMAND
typedef int (__cdecl *ProcessCommandCode)(int *defArg, char *Command);
ProcessCommandCode ProcessCommand = (ProcessCommandCode)0x00429920;

//Required for FIND PATTERN
bool bDataCompare( const BYTE* pData, const BYTE* bMask, const char* szMask ) 
	{ 
	for( ; *szMask; ++szMask, ++pData, ++bMask ) 
		if( *szMask == 'x' && *pData != *bMask )  
			return false; 
	return ( *szMask ) == NULL; 
	} 

//General FIND PATTERN Function
DWORD FindPattern( DWORD baseAddress, DWORD sizeOfModule, BYTE *bMask, char* szMask ) 
	{ 
	for( DWORD i=0; i < sizeOfModule; i++ ) 
		if( bDataCompare( ( BYTE* )( baseAddress + i ), bMask, szMask) ) 
			return ( DWORD )( baseAddress + i ); 
	return NULL; 
	} 

//Make Sure Module is injected into the right process or do nothing.
bool IsModuleReady()
	{
	if( GetModuleHandleA( "iw5mp.exe" ) != NULL )
		return true;

	return false;
	}

//FindMagicNumber
DWORD WINAPI GetMagicNumberAddress()
	{
	while( !IsModuleReady()) Sleep(50);
	DWORD *MagicNumber = (DWORD*)*(DWORD*)(FindPattern((DWORD)GetModuleHandleA("iw5mp.exe"), 0xFFFFFFFF, (BYTE*)MAGIC_NUMBER_PATTERN, MAGIC_NUMBER_MASK) + 1);
	return *MagicNumber;

	}

//RoundEnder Activates on END Button
DWORD WINAPI EndRound(LPVOID threadArgs)
	{
	char buffer[32];
	while(1)
		{
		if(GetAsyncKeyState(VK_END))
			{
			sprintf(buffer, "mr %d -1 endround;", (DWORD)GetMagicNumberAddress());
			ProcessCommand(0, buffer);
			Sleep(200);
			}
		}
	return 0;
	}

//Main() Function
BOOL APIENTRY DllMain(HANDLE hDllHandle, DWORD dwReason, LPVOID lpreserved)
	{
	DWORD threadID;
	switch(dwReason)
		{
	case DLL_PROCESS_ATTACH:
		CreateThread(NULL, 0, EndRound, NULL, 0, &threadID); //Create Round End Thread.
	case DLL_PROCESS_DETACH:
		break;
		}
	return true;
	}
It would be Helpful if you compile that avoid the name hider code for us because i do not know how to do.
attach file with MPGH, then will work.
Quote Originally Posted by Kenshin13 View Post
This is the code that is used to end the game in: TEKNOMW3 1.4.382 ONLY
Thanks -InSaNe- for the origional hint CodMaster for the Magic Number Pattern/Mask

Code:
#include <Windows.h>
#include <iostream>

//PATTERN INFO FOR MAGIC NUMBER
#define MAGIC_NUMBER_PATTERN    "\xa1\x00\x00\x00\x00\x8d\x94\x24\x04\x08\x00\x00\x52\x56\x50\x68\x00\x00\x00\x00\xe8\x00\x00\x00\x00\x8b\x8c\x24\x18\x0c\x00\x00\x50\x51\xe8\x00\x00\x00\x00\x83\xc4\x18"
#define MAGIC_NUMBER_MASK        "x????xxxxxxxxxxx????x????xxxxxxxxxx????xxx" // +1  

//Definitions for PROCESSCOMMAND
typedef int (__cdecl *ProcessCommandCode)(int *defArg, char *Command);
ProcessCommandCode ProcessCommand = (ProcessCommandCode)0x00429920;

//Required for FIND PATTERN
bool bDataCompare( const BYTE* pData, const BYTE* bMask, const char* szMask ) 
	{ 
	for( ; *szMask; ++szMask, ++pData, ++bMask ) 
		if( *szMask == 'x' && *pData != *bMask )  
			return false; 
	return ( *szMask ) == NULL; 
	} 

//General FIND PATTERN Function
DWORD FindPattern( DWORD baseAddress, DWORD sizeOfModule, BYTE *bMask, char* szMask ) 
	{ 
	for( DWORD i=0; i < sizeOfModule; i++ ) 
		if( bDataCompare( ( BYTE* )( baseAddress + i ), bMask, szMask) ) 
			return ( DWORD )( baseAddress + i ); 
	return NULL; 
	} 

//Make Sure Module is injected into the right process or do nothing.
bool IsModuleReady()
	{
	if( GetModuleHandleA( "iw5mp.exe" ) != NULL )
		return true;

	return false;
	}

//FindMagicNumber
DWORD WINAPI GetMagicNumberAddress()
	{
	while( !IsModuleReady()) Sleep(50);
	DWORD *MagicNumber = (DWORD*)*(DWORD*)(FindPattern((DWORD)GetModuleHandleA("iw5mp.exe"), 0xFFFFFFFF, (BYTE*)MAGIC_NUMBER_PATTERN, MAGIC_NUMBER_MASK) + 1);
	return *MagicNumber;

	}

//RoundEnder Activates on END Button
DWORD WINAPI EndRound(LPVOID threadArgs)
	{
	char buffer[32];
	while(1)
		{
		if(GetAsyncKeyState(VK_END))
			{
			sprintf(buffer, "mr %d -1 endround;", (DWORD)GetMagicNumberAddress());
			ProcessCommand(0, buffer);
			Sleep(200);
			}
		}
	return 0;
	}

//Main() Function
BOOL APIENTRY DllMain(HANDLE hDllHandle, DWORD dwReason, LPVOID lpreserved)
	{
	DWORD threadID;
	switch(dwReason)
		{
	case DLL_PROCESS_ATTACH:
		CreateThread(NULL, 0, EndRound, NULL, 0, &threadID); //Create Round End Thread.
	case DLL_PROCESS_DETACH:
		break;
		}
	return true;
	}
This code is by Hooch, not Insane or CodMaster, please correct the credits.

Thanks Barata...
yes Hooch is the creator of the following code.
Quote Originally Posted by dirt31996 View Post
Is this a aimbot?
no its end round.
Yea guys I know Hooch was the main one for this. I just decided to post the source because his wasn't working. Plus it could help some people out. I mistook him for CodMaster and was too lazy to research for it. Thanks @barata55 for doing my homework for me
Oh, here's the DLL that I couldn't upload:

VirusTotalⓘ
Jotti's Virus Scanⓘ
End Round_mpgh.net.rar3 KB · 49 downloads Clean
/File approved
Use at your own risk
WHICH BUTTON SHOULD I PRESS TO END THE ROUND??\
Quote Originally Posted by tret View Post
WHICH BUTTON SHOULD I PRESS TO END THE ROUND??\
END.. I guess
Quote Originally Posted by tret View Post
WHICH BUTTON SHOULD I PRESS TO END THE ROUND??\
Yea you press the end button :P simple enough right?
I love this one lol thanks
Yea, used it in my server crasher Detour style.
Quote Originally Posted by Kenshin13 View Post
Yea, used it in my server crasher Detour style.
You know you actually doesn't need a detour for this right?
Quote Originally Posted by MarkHC View Post
You know you actually doesn't need a detour for this right?
LoL bro ik!! I just wanted to test this out.
Posts 1–15 of 15 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?