PostWarframe CE opcodes and addresses

Posts 115 of 254 · Page 1 of 17
Warframe CE opcodes and addresses
So here we start again.

Ammo opcode:
Code:
00AAFB4A - 66 89 01                   - mov [ecx],ax  //ax carries your loaded ammo
00AAFB4D - 0FB7 C0                    - movzx eax,ax
Full func(i suppose?):
Code:
00AAFB10 - 56                         - push esi
00AAFB11 - 8B F1                      - mov esi,ecx
00AAFB13 - 8B 06                      - mov eax,[esi]
00AAFB15 - 8B 90 68010000             - mov edx,[eax+00000168]
00AAFB1B - FF D2                      - call edx
00AAFB1D - 8B 4C 24 08                - mov ecx,[esp+08]
00AAFB21 - 3B C8                      - cmp ecx,eax
00AAFB23 - 73 02                      - jae 00AAFB27
00AAFB25 - 8B C1                      - mov eax,ecx
00AAFB27 - 66 8B 96 800A0000          - mov dx,[esi+00000A80]
00AAFB2E - 8D 8E 800A0000             - lea ecx,[esi+00000A80]
00AAFB34 - 57                         - push edi
00AAFB35 - 66 33 D1                   - xor dx,cx
00AAFB38 - BF B10F0000                - mov edi,00000FB1
00AAFB3D - 66 33 D7                   - xor dx,di
00AAFB40 - 66 C1 CA 03                - ror dx,03
00AAFB44 - 5F                         - pop edi
00AAFB45 - 66 3B D0                   - cmp dx,ax
00AAFB48 - 74 40                      - je 00AAFB8A
00AAFB4A - 66 89 01                   - mov [ecx],ax
00AAFB4D - 0FB7 C0                    - movzx eax,ax
00AAFB50 - 66 C1 C0 03                - rol ax,03
00AAFB54 - 66 33 C1                   - xor ax,cx
00AAFB57 - BA B10F0000                - mov edx,00000FB1
00AAFB5C - 66 33 C2                   - xor ax,dx
00AAFB5F - 66 89 01                   - mov [ecx],ax
00AAFB62 - 35 7F0D0000                - xor eax,00000D7F
00AAFB67 - 66 89 86 820A0000          - mov [esi+00000A82],ax
00AAFB6E - 8B 86 7C0A0000             - mov eax,[esi+00000A7C]
00AAFB74 - 83 C8 01                   - or eax,01
00AAFB77 - 89 86 7C0A0000             - mov [esi+00000A7C],eax
00AAFB7D - 83 E0 FE                   - and eax,FE
00AAFB80 - 74 08                      - je 00AAFB8A
00AAFB82 - B9 01000000                - mov ecx,00000001
00AAFB87 - 66 89 08                   - mov [eax],cx
00AAFB8A - 5E                         - pop esi
00AAFB8B - C2 0400                    - ret 0004
As for bypassing anti-cheat - its really easy(well at least on x64), just turn on your mind. If you can't - send me pm i will share the details.

Right now i am kinda stuck, and was able to find only one value. If anyone can help to progress - feel free to share it.

P.S. Sorry for bad english =)
This may sound stupid but how do I use these? Could you perhaps make a picture or video tutorial?
Well - i am really bad at explaining this. But you can try script i created(infite ammo) for CE:
Code:
/*
   - Infinite Ammo
   - MPGH
   - Made by Lepage. Based on nilath research and development.
*/
[ENABLE]
alloc(newmem,2048) //2kb should be enough
label(returnhere)
label(originalcode)
label(exit)

newmem: //this is allocated memory, you have read,write,execute access
//place your code here
mov ax, 1000

originalcode:
mov [ecx],ax
movzx eax,ax

exit:
jmp returnhere

"Warframe.exe"+6AFB4A:
jmp newmem
nop
returnhere:

[DISABLE]
Warframe.exe+6AFB4A:
mov [ecx],ax
movzx eax,ax

dealloc(newmem)
Ofcourse you need to bypass anti-cheat protection. But its really easy.
I see, so how would you bypass the anti-cheat? I'm terrible at these kind of things.
Yeah, I don't know much about CheatEngine, just the very basics, so any help would be greatly appreciated.
Please use English in your next posts. Respect other members of this board. I will send PM to everybody once i will finish what i started.

Next chapter - Shields - behavior of function has changed, right now it calculates shields for everyone (even mobs) but you can still find address you need.
Func code:
Code:
00469A40 - 51                         - push ecx
00469A41 - F3 0F10 41 04              - movss xmm0,[ecx+04]
00469A46 - F3 0F10 1D F0631801        - movss xmm3,[opus_get_version_string+E90F0]
00469A4E - 8D 51 04                   - lea edx,[ecx+04]
00469A51 - F3 0F11 04 24              - movss [esp+esp],xmm0
00469A56 - 8B C2                      - mov eax,edx
00469A58 - 33 04 24                   - xor eax,[esp+esp]
00469A5B - 35 B10F442F                - xor eax,2F440FB1 : [FF000000]
00469A60 - C1 C8 03                   - ror eax,03
00469A63 - 89 04 24                   - mov [esp+esp],eax
00469A66 - 8B 44 24 08                - mov eax,[esp+08]
00469A6A - F3 0F10 20                 - movss xmm4,[eax]
00469A6E - F3 0F10 0C 24              - movss xmm1,[esp+esp]
00469A73 - 0F28 C4                    - movaps xmm0,xmm4
00469A76 - 0F28 D0                    - movaps xmm2,xmm0
00469A79 - F3 0F5C D1                 - subss xmm2,xmm1
00469A7D - 0F54 C3                    - andps xmm0,xmm3
00469A80 - 0F54 CB                    - andps xmm1,xmm3
00469A83 - 0F2F C1                    - comiss xmm0,xmm1
00469A86 - 0F54 D3                    - andps xmm2,xmm3
00469A89 - 77 03                      - ja 00469A8E
00469A8B - 0F28 C1                    - movaps xmm0,xmm1
00469A8E - F3 0F10 0D E0D72701        - movss xmm1,[opus_get_version_string+1E04E0]
00469A96 - 0F2F C8                    - comiss xmm1,xmm0
00469A99 - 76 03                      - jna 00469A9E
00469A9B - 0F28 C1                    - movaps xmm0,xmm1
00469A9E - F3 0F59 05 90471901        - mulss xmm0,[opus_get_version_string+F7490]
00469AA6 - 0F2F C2                    - comiss xmm0,xmm2
00469AA9 - 73 46                      - jae 00469AF1
00469AAB - F3 0F11 22                 - movss [edx],xmm4 //Right here
00469AAF - 8B 02                      - mov eax,[edx]
00469AB1 - C1 C0 03                   - rol eax,03
00469AB4 - 33 C2                      - xor eax,edx
00469AB6 - 35 B10F442F                - xor eax,2F440FB1 : [FF000000]
00469ABB - 89 44 24 08                - mov [esp+08],eax
00469ABF - F3 0F10 44 24 08           - movss xmm0,[esp+08]
00469AC5 - 35 7F0DD312                - xor eax,12D30D7F : [8000003F]
00469ACA - F3 0F11 02                 - movss [edx],xmm0
00469ACE - 89 44 24 08                - mov [esp+08],eax
00469AD2 - 8B 01                      - mov eax,[ecx]
00469AD4 - F3 0F10 44 24 08           - movss xmm0,[esp+08]
00469ADA - 83 C8 01                   - or eax,01
00469ADD - 89 01                      - mov [ecx],eax
00469ADF - 83 E0 FE                   - and eax,FE
00469AE2 - F3 0F11 41 08              - movss [ecx+08],xmm0
00469AE7 - 74 08                      - je 00469AF1
00469AE9 - B9 01000000                - mov ecx,00000001
00469AEE - 66 89 08                   - mov [eax],cx
00469AF1 - 59                         - pop ecx
00469AF2 - C2 0400                    - ret 0004
No i suppose i am not. Cannot find Health and Weapon XP.... Ok - i posted on my page as reply how you bypass anti-cheat protection. I suppose they will change detection method at some point, but its alright. Just stay vigilant.
Any chance of a script for shields?
Okey - here is shield script. I didn't want to work with encryption so you have to enable and disable it at mission start(when you see your frame, not when video played, not on loading screen) and at mission end. It has some defense against errors - but still, it may be flawed. Anyway:
Code:
/*
   - Infinite Shields. 
   - IMPORTANT!!!!!! - Enable at mission start - disable at mission end. Script may be flawed so be careful.
   - IMPORTANT!!!!!! - This script will not defend you against attack's that overpowers you shields. 
   - MPGH
   - Made by Lepage. Based on nilath research and development.
*/
[ENABLE]
alloc(newmem,200)
alloc(definedShieldMaximum,4)
alloc(isShieldAddressDefined,4)
alloc(shieldAddress,4)

label(returnhere)
label(cheating)
label(ending)
label(originalcode)
label(defineshields)
label(exit)

newmem:
pushfd
pushad
cmp [isShieldAddressDefined], 0
je defineshields
mov eax, ecx
add eax, 00000A14
cmp [shieldAddress], eax
jne ending

cheating:
mov eax, [definedShieldMaximum]
mov [ecx+00000A14], eax

ending:
popad
popfd

originalcode:
movss xmm0,[ecx+00000A14]

exit:
jmp returnhere

defineshields:
mov eax, ecx
add eax, 00000A14
mov [shieldAddress], eax
mov eax, [ecx+00000A14]
mov [definedShieldMaximum], eax
mov [isShieldAddressDefined], 1
jmp cheating

"Warframe.exe"+92FDBA:
jmp newmem
nop
nop
nop
returnhere:

[DISABLE]
"Warframe.exe"+92FDBA:
movss xmm0,[ecx+00000A14]

dealloc(shieldAddress)
dealloc(isShieldAddressDefined)
dealloc(definedShieldMaximum)
dealloc(newmem)
About credits - i dont know if any method is still working. There was methods to do it - but i really don't know whats now, and dont have patience to try. If you need it - http://www.mpgh.net/forum/697-warfra...i-credits.html. If it works - find any opcode(in CE Find out what access/writes to this address) and pls share it. Same goes for xp.

Cheers.
Quote Originally Posted by Lepage View Post
Okey - here is shield script. I didn't want to work with encryption so you have to enable and disable it at mission start(when you see your frame, not when video played, not on loading screen) and at mission end. It has some defense against errors - but still, it may be flawed. Anyway:
Code:
/*
   - Infinite Shields. 
   - IMPORTANT!!!!!! - Enable at mission start - disable at mission end. Script may be flawed so be careful.
   - IMPORTANT!!!!!! - This script will not defend you against attack's that overpowers you shields. 
   - MPGH
   - Made by Lepage. Based on nilath research and development.
*/
[ENABLE]
alloc(newmem,200)
alloc(definedShieldMaximum,4)
alloc(isShieldAddressDefined,4)
alloc(shieldAddress,4)

label(returnhere)
label(cheating)
label(ending)
label(originalcode)
label(defineshields)
label(exit)

newmem:
pushfd
pushad
cmp [isShieldAddressDefined], 0
je defineshields
mov eax, ecx
add eax, 00000A14
cmp [shieldAddress], eax
jne ending

cheating:
mov eax, [definedShieldMaximum]
mov [ecx+00000A14], eax

ending:
popad
popfd

originalcode:
movss xmm0,[ecx+00000A14]

exit:
jmp returnhere

defineshields:
mov eax, ecx
add eax, 00000A14
mov [shieldAddress], eax
mov eax, [ecx+00000A14]
mov [definedShieldMaximum], eax
mov [isShieldAddressDefined], 1
jmp cheating

"Warframe.exe"+92FDBA:
jmp newmem
nop
nop
nop
returnhere:

[DISABLE]
"Warframe.exe"+92FDBA:
movss xmm0,[ecx+00000A14]

dealloc(shieldAddress)
dealloc(isShieldAddressDefined)
dealloc(definedShieldMaximum)
dealloc(newmem)
About credits - i dont know if any method is still working. There was methods to do it - but i really don't know whats now, and dont have patience to try. If you need it - http://www.mpgh.net/forum/697-warfra...i-credits.html. If it works - find any opcode(in CE Find out what access/writes to this address) and pls share it. Same goes for xp.

Cheers.
I think I love you bro, Your work continues to amaze me. Wow, this is pure awesome.
[NO HOMOSEXUALITY INTENDED]
Well - thank you. But it's based on nilath research - i only did some additional work. So many thanks to him.

Second - to everybody - if you want to really help me and other people here (and by this, not being a lazy leecher) - try to find xp and money values. While i am not sure that money can be cheated - xp may be not fixed yet. All you need to do - is find encoded value(unknown value search - look at thread i posted) and find what writes(access) to it. Or try to find anything else(health for example). It take's time and patience, but it don't require any special skills.

Third - while i tried to test my scripts - i played game's solo so i dont know if they gonna work in multiplayer mode. So - again - be careful.

Cheers.
I used the inf ammo in a multiplayer on a test account, it worked, and only for me.
Posts 115 of 254 · Page 1 of 17
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Need help?