Spawning stuff without scripts [sd333221]

Posts 1–15 of 21 · Page 1 of 2
Spawning stuff without scripts [sd333221]
Just a proof of concept atm (offsets are for 96836). It works online however and completely bypasses any battle-eye check and can therefore be remotely executed without modifying arma at all:
Code:
Code:
	typedef unsigned int (__thiscall *f_getWeaponClassFromName)(unsigned int dwThis, const char * cName);
	typedef void(__thiscall *f_addWeapon)(unsigned int dwEntInventoryManager, unsigned int ent, unsigned int weaponClass, unsigned int reserved1, unsigned int reserved2);
	unsigned int locplayer = *(*(*reinterpret_cast<unsigned int***>(ARMA_ENT_PTR)+0x13a4/4)+0x4/4);
	f_getWeaponClassFromName getWeaponClassFromName = reinterpret_cast<f_getWeaponClassFromName>(0x004BD67C);
	f_addWeapon addWeapon = reinterpret_cast<f_addWeapon>(0x0065AFDF);
	unsigned int nvclass = getWeaponClassFromName(0xdddf08,"NVGoggles");
	if(nvclass) {
		unsigned int invmgr = locplayer+0x678;
		addWeapon(invmgr,locplayer,nvclass,0,0);
	}
Magazines work similar. It is working online but you have to put the stuff down and pick it up again.

If the interest is high I might think about coding a small gear spawner with teleport functionality that should be relatively safe to use.

THIS IS NOT MINE!
All of the credits go to sd333221
How can i use this?
Found php code too:
Code:
void CObject::addWeapon( const char weapName )
{
    arma_string hintWeapon(weapName);

    // Get our corresponding weapon
    DWORD unk1 = 0;
    matchString(&unk1, &hintWeapon);

    if(!unk1)
        return;

    typedef void* (__thiscall* t_addWeapon)(void* weapBegin, CObject* object, void* matched, DWORD a3, DWORD a4);
    static t_addWeapon pAddWeapon;

    if(!pAddWeapon)
    {
        pAddWeapon = (t_addWeapon)framework::utility::findPatternInModule(GetModuleHandle("arma2oa.exe"), (BYTE*)"\x55\8B\xEC\x51\x8B\x45\x0C\x56\x8B\xF1\x85\xC0\x74\x00\x83\xC0\x08", "xxxxxxxxxxxxx?xxx");
        framework::utility::log("[%s->addWeapon] addWeapon found at 0x%X", getTypeName().c_str(), pAddWeapon);
    }

    pAddWeapon((void*)((DWORD)this+0x678), this, (void*)unk1, 1, 1);
}


---------- Post added at 02:21 PM ---------- Previous post was at 02:20 PM ----------

Quote Originally Posted by kroganin1 View Post
How can i use this?
Im not sure my self i think you have to make a c++ version of this and then execute it
Where exactly did you get this?
I believe this was the concept he used for his survival hack. The thread you copied this from was very old. I'd check to make sure you didn't just go full retard.
So this is a script?
Quote Originally Posted by KidoThe View Post
So this is a script?
nope it reads and then writes to the arma memory. it looks like some derivative of C
Quote Originally Posted by typh0 View Post
nope it reads and then writes to the arma memory. it looks like some derivative of C
BattlEye checks Arma's memory for changes though. So why wouldn't it find this?
Quote Originally Posted by typh0 View Post
nope it reads and then writes to the arma memory. it looks like some derivative of C
So it's a script.
Quote Originally Posted by disabilitor View Post
BattlEye checks Arma's memory for changes though. So why wouldn't it find this?
BattlEye cant catch everything

Quote Originally Posted by KidoThe View Post


So it's a script.
Since its written in C/C#/C++ which are all procedural languages while Arma has a scripting language. I wouldnt say this is a script. It would be a class or subroutine.
Quote Originally Posted by typh0 View Post
BattlEye cant catch everything



Since its written in C/C#/C++ which are all procedural languages while Arma has a scripting language. I wouldnt say this is a script. It would be a class or subroutine.
However, it is a script.
Wow, that's really interesting.
I'm dropping my current project, and working on something like this.
I just want to notice that this was used in the survival hack...
Posts 1–15 of 21 · Page 1 of 2

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us