Help for ESP

Posts 1–12 of 12 · Page 1 of 1
Help for ESP
I Found these code [LINK]:
Code:
DWORD PlayerClient = *(DWORD*)(ClientShell+0x54);
		if(PlayerClient!=NULL)
		{
			
			  if(GetMeIdxInPlayerInfoList==NULL)
			  {
			  GetMeIdxInPlayerInfoList = (lpGetMeIdxInPlayerInfoList) (CShell + (0x1FD70));//this function return my player index
			  }
			int drawcount=0;
			CPlayer *me = (CPlayer*)((ClientShell + (0x743C+4))+ (GetMeIdxInPlayerInfoList(ClientShell) * 0x4c8));//this is my player
			
			char szFormat[256];
			for(int i=0;i<16;i++)//array of players
			{
				CPlayer * pPlayerInfo = (CPlayer*)((ClientShell + (0x743C+4))+ (i * 0x4c8));
				if(strlen(pPlayerInfo->Name)>2 && pPlayerInfo->Team!=me->Team)//if player have name and his Enemy
				{
					drawcount++;
					if(pPlayerInfo->Health>0)//If Enemy Alive
					{
					   
						sprintf(szFormat,"%s",pPlayerInfo->Name);
						D3DXVECTOR3 pos;
						if(WorldToScreen(pDevice,pPlayerInfo->Object->Head,&pos))//If visible in My Screen
						{
							if(hack1>=1)//first type ESP
							{
							WriteText(szFormat,pos.x,pos.y,Red);//Draw Enemy Name
							if(pPlayerInfo->Has_C4)
							{
								sprintf(szFormat,"%s","C4");
								WriteText(szFormat,pos.x,pos.y+15+15,Red);//Draw what Enemy have C4
							}
							}
						
							if(hack1>=2)//second ESP type
							{
							if(pPlayerInfo->Health>=90)//enemy health is very good
							{
								DrawHealthBar(pos.x,pos.y+15,30,5,Green,Black,pPlayerInfo->Health,100,pDevice);
							}
							else if(pPlayerInfo->Health>=40)//enemy health is not good
							{
								DrawHealthBar(pos.x,pos.y+15,30,5,Yellow,Black,pPlayerInfo->Health,100,pDevice);
							}
							else //enemy health - very bad, you can kill him very easy :)
							{
								DrawHealthBar(pos.x,pos.y+15,30,5,Red,Black,pPlayerInfo->Health,100,pDevice);
							}
							
							}
								int ScreenCenterX = GetSystemMetrics(0) / 2;
								int ScreenCenterY = GetSystemMetrics(1) / 2;
								if(hack1>=3)// DrawLines from center screen to Enemy
								{
								DrawLine(ScreenCenterX,ScreenCenterY,pos.x,pos.y,1,Blue,pDevice);
								}
						}
						
					}
					

				}
			}
		}
I updated the offsets
My problem is to find "ClientShell"
What does he mean with it?

And does this CShell
Code:
(CShell + (0x1FD70));
mean this ?
Code:
CShell = (DWORD)GetModuleHandleA("CShell.dll");
Yes it most likely does.
No one can help?
Quote Originally Posted by Aldimann View Post
No one can help?
I already did.
My problem is to find "ClientShell"
What does he mean with it?
Thats my second problem ^^
Quote Originally Posted by Aldimann View Post
Thats my second problem ^^
ClientShell ? I am sure it's LTClient + 0xC
And how can I find LTCLient?
I Never searched before for this value
Code:
/* CGameClientShell
833D????????005356
\x83\x3D\x04\x2F\x80\x37\x00\x53\x56
xx????xxx
371A8DA0   . 833D 042F8037 00   CMP DWORD PTR DS:[37802F04],0            ;  pGameClientShell
371A8DA7   . 53                 PUSH EBX
371A8DA8   . 56                 PUSH ESI
371A8DA9   . 57                 PUSH EDI
371A8DAA   . 8BF9               MOV EDI,ECX
371A8DAC   . 74 69              JE SHORT CShell.371A8E17                 ;  error
371A8DAE   . 66:8B5C24 14       MOV BX,WORD PTR SS:[ESP+14]
371A8DB3   . 0FB7F3             MOVZX ESI,BX
371A8DB6   . 85F6               TEST ESI,ESI
371A8DB8   . 7C 5D              JL SHORT CShell.371A8E17                 ;  error
371A8DBA   . A1 14168037        MOV EAX,DWORD PTR DS:[37801614]
371A8DBF   . 3BB0 C0150000      CMP ESI,DWORD PTR DS:[EAX+15C0]
371A8DC5   . 7D 50              JGE SHORT CShell.371A8E17                ;  error
371A8DC7   . 8B0D F0888037      MOV ECX,DWORD PTR DS:[378088F0]          ;  CShell.377E0124
371A8DCD   . 8B49 18            MOV ECX,DWORD PTR DS:[ECX+18]
371A8DD0   . E8 EB192F00        CALL CShell.3749A7C0
371A8DD5   . 66:3BD8            CMP BX,AX
371A8DD8   . 75 52              JNZ SHORT CShell.371A8E2C                ;  allt gick fint
371A8DDA   . 8B0D 14168037      MOV ECX,DWORD PTR DS:[37801614]          ;  CShell.37801698
371A8DE0   . 56                 PUSH ESI
371A8DE1   . E8 6A9C2400        CALL CShell.373F2A50
371A8DE6   . 85C0               TEST EAX,EAX
371A8DE8   . 74 42              JE SHORT CShell.371A8E2C                 ;  allt gick fint
371A8DEA   . 0FB64424 10        MOVZX EAX,BYTE PTR SS:[ESP+10]
371A8DEF   . 66:8B5424 18       MOV DX,WORD PTR SS:[ESP+18]
371A8DF4   . 8987 90010000      MOV DWORD PTR DS:[EDI+190],EAX
371A8DFA   . 66:8977 28         MOV WORD PTR DS:[EDI+28],SI
371A8DFE   . 66:8957 2A         MOV WORD PTR DS:[EDI+2A],DX
371A8E02   . 8B0D DCC48137      MOV ECX,DWORD PTR DS:[3781C4DC]          ;  CShell.377DD19C
371A8E08   . 8B11               MOV EDX,DWORD PTR DS:[ECX]
371A8E0A   . 8B42 10            MOV EAX,DWORD PTR DS:[EDX+10]
371A8E0D   . 6A 10              PUSH 10
371A8E0F   . FFD0               CALL EAX
371A8E11   . 5F                 POP EDI
371A8E12   . 5E                 POP ESI
371A8E13   . 5B                 POP EBX
371A8E14   . C2 1000            RETN 10
371A8E17   > A1 50857C37        MOV EAX,DWORD PTR DS:[377C8550]
371A8E1C   . 8B08               MOV ECX,DWORD PTR DS:[EAX]
371A8E1E   . 8B51 18            MOV EDX,DWORD PTR DS:[ECX+18]
371A8E21   . 68 B83A6D37        PUSH CShell.376D3AB8                     ;  ASCII "if(!g_pGameClientShell || !g_pWeaponMgr->IsValidWeaponId(nWeaponId))"
371A8E26   . 50                 PUSH EAX
371A8E27   . FFD2               CALL EDX
371A8E29   . 83C4 08            ADD ESP,8
371A8E2C   > 5F                 POP EDI
371A8E2D   . 5E                 POP ESI
371A8E2E   . 5B                 POP EBX
371A8E2F   . C2 1000            RETN 10
*/
If it's the class you mean..
I found that 0x7e9b5c0 in CF EU?
Is this correct?
Quote Originally Posted by Aldimann View Post
I found that 0x7e9b5c0 in CF EU?
Is this correct?
No it's not correct, LTClient .. people are calling it PushToConsole Addresses in Crossfire section ! what a choobs

oh and you can find LTClient at a string called " FogEnable 0 " its up to the offest to it.
so just open windows calculator and do LTClient + 0xC and it will equal LTClientShell.
Oh you're right
My PTC Address is the same

Ill try again with these

if(ClientShell)
{
PlayerClient = *(DWORD*)(ClientShell + CShell_Player);
if(PlayerClient != NULL)
{
if(GetMeIdxInPlayerInfoList==NULL)
{
GetMeIdxInPlayerInfoList = (lpGetMeIdxInPlayerInfoList)(cshell+(0x25170)); // Get MyPlayer Index*/
}
int drawcount = 0;
CPlayer *me = (CPlayer*)((ClientShell + (PlayerBase_offs+4))+ (GetMeIdxInPlayerInfoList(ClientShell) * 0x420));//this is my player // Not working
sprintf_s(szFormat,me->Name);

.
.
.
Don't working :/

Clientshell = PTC+0xC
PTC = 0x5bb5b4

Output : me->Name are just some strange characters
Quote Originally Posted by Aldimann View Post
Oh you're right
My PTC Address is the same

Ill try again with these



Don't working :/

Clientshell = PTC+0xC
PTC = 0x5bb5b4
Something wrong you did, why don't you make your own ESP Function instead of leaking people shits.
Posts 1–12 of 12 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us