HelpMemory hacking (WinAPI)

Posts 1–14 of 14 · Page 1 of 1
Memory hacking (WinAPI)
Ok so I just started into hacking (Making my own hacks)(I'm not someone stupid who leech everyone's code because I don't know c++...)
I studied the msdn library functions (OpenProcess-WriteProcess-etc...)

Every time you restart any program, all addresses of that program changes since they are stored in RAM ( Randomly accessed memory ). So how to deal with ? If I write process memory with 0x2ff18 as address and compile everything this will only work once because if I close the game and run it again the address will have changed. So what to do to not to have to make a new code each time ?

/*I hope you understand because english is not my native language*/
/*As for now I only hacked my calculator, but it is still a question that is important to me*/
ASLR - Address Space Layout Randomization (Windows memory management: big subject)


Basically each module of the program can/will be loaded at a random address.

You must base each important address off a module.

ie. 0x2ff18 should be .... moduleMain.dll + 1234 // example


so, find the addr RELATIVE to some module. CheatEngine will help. (image below)



so don't use 1 solid addr like 0x12345678, use calc.exe + offset

because "main module" could get loaded ANYWHERE, so we have to ask windows "Hey, where is main module loaded?" in our C++ program, and make everything relative to that addr.

In my picture's example the address was 0x000AE08C
but we want to use calc.exe + 0x12475


---
edit:
Just to prove, I closed calc.exe and CE and did it a 2nd time. Now the address is different, but the calc.exe + offset, is still the same


0x000AE2CC
calc.exe + 0x12475
Quote Originally Posted by abuckau907 View Post
ASLR - Address Space Layout Randomization (Windows memory management: big subject)


Basically each module of the program can/will be loaded at a random address.

You must base each important address off a module.

ie. 0x2ff18 should be .... moduleMain.dll + 1234 // example


so, find the addr RELATIVE to some module. CheatEngine will help. (image below)



so don't use 1 solid addr like 0x12345678, use calc.exe + offset

because "main module" could get loaded ANYWHERE, so we have to ask windows "Hey, where is main module loaded?" in our C++ program, and make everything relative to that addr.

In my picture's example the address was 0x000AE08C
but we want to use calc.exe + 0x12475


---
edit:
Just to prove, I closed calc.exe and CE and did it a 2nd time. Now the address is different, but the calc.exe + offset, is still the same


0x000AE2CC
calc.exe + 0x12475
What windows are you using?
Ok, ty for the fast answer. I'm going to try this later because for now I have enough ^^, but a big thanks.

So I must remember to use "Module" + offset
Well, AFTER you try it, let us know.

Um..I generally hate saying the word "always" (implied)...so maybe not always, but in your case, I do believe so.
Quote Originally Posted by master131 View Post
ASLR is not present in Windows XP @abuckau907
edit: removed flame(s). Not sure why that pissed me off, but it did. (Maybe because you assume I don't know? And I fail to see how it matters anyway)

@master131 abuckau907 is currently on xp, and might have known that already.

Is there a problem? ...Why are you telling me instead of OP?


---
"Ok so I just started into hacking (Making my own hacks)(I'm not someone stupid who leech everyone's code because I don't know c++...)
I studied the msdn library functions (OpenProcess-WriteProcess-etc...)

Every time you restart any program, all addresses of that program changes since they are stored in RAM ( Randomly accessed memory ). So how to deal with ? If I write process memory with 0x2ff18 as address and compile everything this will only work once because if I close the game and run it again the address will have changed. So what to do to not to have to make a new code each time ?

/*I hope you understand because english is not my native language*/
/*As for now I only hacked my calculator, but it is still a question that is important to me*/
"
Nothing about what version of windows he's on. I guess I *should* have asked, but, I think my answer is still valid. If if not, maybe you should have explained!

Or, was your goal simply to point out a fact? Then why point it out to me personally?
I'm only clarifying that ASLR is not present in Windows XP, there's no need to go full out on me like that. Your screenshot was showing that you were using XP so I was just making that fact clear so the OP doesn't get the wrong idea. The address changing is not a result of ASLR anyway. The Windows Loader is free to change the base address of a module if required (in this case calc.exe). It does this with the help of the relocation table (if it's present).
"I'm only clarifying that ASLR is not present in Windows XP" -- that's fine, but don't address it to me please.

"The address changing is not a result of ASLR anyway." -- doesn't matter, OP still learned what he needed to learn. he'll flush out the details as he gets more experience. "and I fail to see how it matters"

I apologize.

-I'm glad you know a lot about it, maybe tell OP instead of me.

@OP: When you get a chance to mess with this again, will you please update this thread.
--I assumed you were on newer version of Windows: If not, ASLR is not your problem, I'm sorry.
Quote Originally Posted by abuckau907 View Post

@OP: When you get a chance to mess with this again, will you please update this thread.
--I assumed you were on newer version of Windows: If not, ASLR is not your problem, I'm sorry.
I'm on windows 7.


---------- Post added at 02:26 PM ---------- Previous post was at 01:12 PM ----------

Mhmmmm . How to find it (Module + offset) ? Because I tried by looking the memory with CE, but couldn't find how to find it lol. (I've tried many things)

And also, what is the syntax to use ? Is it like this ?

Code:
int areYouSuccessful = WriteProcessMemory(hProc, (LPVOID)"calc.exe"+125119, &newValue, (DWORD)sizeof(newValue), NULL);
            if(areYouSuccessful > 0)
            {
                cout << "Process memory written" << endl;
            }
            else
            {
                cout << "Coulnd't write process memory" << endl;
            }
Thank you
Kind of, but no. "calc.exe" doesn't mean jack to msvs (edit: or any other compiler) :/

Each module has a memory range: so it has a beginning and end.

module.BaseAddress to module.EndAddress

we need: module.Base + some offset

You have to enumerate the module list and find the module you want.

(I don't know C++ well enough sorry - I just googled, there are plenty of examples out there)

uint mainModuleBase = 0;

mainModuleBase = ****************; //enumerate process / module list and find it


then when you want to read/write:

WriteProcessMemory(mainModuleBase + offset)


I can't explain it much more than that, sorry.


The CE thing was in my picture... :| When in "memory browser" form, click VIEW ->Show Module Addresses.

Hope that helps.

If not, first make an app which can show every module in a process (name, base addr, end addr), and that should help you learn more. Google "enumerate module list C++" or "enumerate process list C++" and those will help.
Ok thank you gonna take a look in that.
Np. Basically you have to figure out how to loop over each module in the process, compare it's name, and if it's the correct module, record it's .BaseAddress.
Good luck.
Posts 1–14 of 14 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us