Simple Byte pattern for PTCPTR

Posts 1–15 of 15 · Page 1 of 1
Simple Byte pattern for PTCPTR
So I got 2 PM's about guys crying for the PTCPTR pattern...
So i opened IDA and found it. I don't know if this was released before, but i'll just release it anyway...

Code:
PTCPTR:\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00\x83\xC4\x20 xx????xxxx????xxx
I don't think that'l work bud.
Having the first 3 bytes as wildcards is kindof pointless.
So the pattern is 2 bytes long? I find that hard to believe.

You'l need to post more info on how to use it.
Here are my Pattern:
Pointer:
Code:
PTC = FindPattern(CShell, 0xF7C000, (PBYTE)"\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????xxxx????");
PTC = *(DWORD*)(PTC + 0x2);
Offset:
Code:
PTCOffset = FindPattern(CShell,0xFC7000,(PBYTE)"\x8B\x88\x00\x00\x00\x00\x68\x00\x00\x00\x00\xFF\xD1\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????x????xxxx????xxxx????");
PTCOffset = *(DWORD*)(PTCOffset + 0x2);
Quote Originally Posted by -[I]fLuX View Post
Here are my Pattern:
Pointer:
Code:
PTC = FindPattern(CShell, 0xF7C000, (PBYTE)"\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????xxxx????");
PTC = *(DWORD*)(PTC + 0x2);
Offset:
Code:
PTCOffset = FindPattern(CShell,0xFC7000,(PBYTE)"\x8B\x88\x00\x00\x00\x00\x68\x00\x00\x00\x00\xFF\xD1\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????x????xxxx????xxxx????");
PTCOffset = *(DWORD*)(PTCOffset + 0x2);
Damnn.. I have totallyy diferrentt!
Quote Originally Posted by -[I]fLuX View Post
Here are my Pattern:
Pointer:
Code:
PTC = FindPattern(CShell, 0xF7C000, (PBYTE)"\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????xxxx????");
PTC = *(DWORD*)(PTC + 0x2);
Offset:
Code:
PTCOffset = FindPattern(CShell,0xFC7000,(PBYTE)"\x8B\x88\x00\x00\x00\x00\x68\x00\x00\x00\x00\xFF\xD1\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00","xx????x????xxxx????xxxx????");
PTCOffset = *(DWORD*)(PTCOffset + 0x2);
You don't need to include the bytes if the pattern starts or ends with wildcards.
Both your patterns will work but you're adding extra unneeded bytes to both those scans.
PTC pattern it's LTClient itself.

Code:
DWORD PTC_Offset  =FindPattern((DWORD)GetModuleHandleW(L"CShell.dll"),0xFFFFFF, (PBYTE)"\x8B\x88\x00\x00\x00\x00\x68\x00\x00\x00\x00\xFF\xD1\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00\x83\xC4\x08", "xx????x????xxxx????xxxx????xxx");
PTC_Offset+=0x2


DWORD PTC_Ptr = FindPattern((DWORD)GetModuleHandleW(L"CShell.dll"),0xFFFFFF, (PBYTE)"\x8B\x0D\x00\x00\x00\x00\x8B\x11\x8B\x82\x00\x00\x00\x00\x51\xD9\x1C\x24\xFF\xD0\xA1\x00\x00\x00\x00", "xx????xxxx????xxxxxxx????");
PTC_Ptr+=0x2
Quote Originally Posted by RobinC View Post
@Pingo @bandi12 @-[I]fLuX
Updated it, does it seems right to you guys?
They are working i used them on my released logger
Oh okay good,But I have another one then you said??
Quote Originally Posted by RobinC View Post
Oh okay good,But I have another one then you said??
One of you used more bytes
Quote Originally Posted by [H]aaBX View Post
One of you used more bytes
Oh ok...
Is ESP pattern ever released?? Shoul I relwase it + some others?
Quote Originally Posted by RobinC View Post


Oh ok...
Is ESP pattern ever released?? Shoul I relwase it + some others?
MY logger can search for the basic of them i mean the pointer for the class , i never had much time to search pattern's to all alue's inside the class then add them on my autoClass
Quote Originally Posted by bandi12 View Post
MY logger can search for the basic of them i mean the pointer for the class , i never had much time to search pattern's to all alue's inside the class then add them on my autoClass
Nice To bad I cant dump CShell etc. Ill keep ESP private .
Quote Originally Posted by RobinC View Post


Nice To bad I cant dump CShell etc. Ill keep ESP private .
you don't need to debug it , whit a small trick it can be loaded like before
Quote Originally Posted by RobinC View Post
Oh ok...
Is ESP pattern ever released?? Shoul I relwase it + some others?
Keep them private
Posts 1–15 of 15 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us