C++ ASM JMP HELP

Posts 1–12 of 12 · Page 1 of 1
C++ ASM JMP HELP
How can I write the following code in c + +? (.dll)

e.g 004BC8F4 jmp -> 004BC92D

Original Code :

Code:
004BC8F4   68 8CA96700      PUSH XXXXXX.0067A98C                   
004BC8F9   6A 01            PUSH 1
004BC8FB   68 FA6464FF      PUSH FF6464FA
004BC900   8BF1             MOV ESI,ECX
004BC902   E8 89EEF6FF      CALL XXXXXX.0042B790
004BC907   33C0             XOR EAX,EAX
004BC909   8946 34          MOV DWORD PTR DS:[ESI+34],EAX
004BC90C   8B0D F84E6D00    MOV ECX,DWORD PTR DS:[6D4EF8]            ; cshDC4D.345C4E48
004BC912   83C4 0C          ADD ESP,0C
004BC915   5E               POP ESI
004BC916   3BC8             CMP ECX,EAX
004BC918   74 15            JE SHORT XXXXXX.004BC92F
004BC91A   837D 0C 06       CMP DWORD PTR SS:[EBP+C],6
004BC91E   75 05            JNZ SHORT XXXXXX.004BC925
004BC920   B8 51000000      MOV EAX,51
004BC925   8B11             MOV EDX,DWORD PTR DS:[ECX]
004BC927   50               PUSH EAX
004BC928   8B42 1C          MOV EAX,DWORD PTR DS:[EDX+1C]
004BC92B   6A 01            PUSH 1
004BC92D   FFD0             CALL EAX
004BC92F   5D               POP EBP
004BC930   C2 0800          RETN 8
JMP :

Code:
004BC8F4   EB 37            JMP SHORT XXXXXX.004BC92D
004BC8F6   90               NOP
004BC8F7   90               NOP
004BC8F8   90               NOP
004BC8F9   6A 01            PUSH 1
004BC8FB   68 FA6464FF      PUSH FF6464FA
004BC900   8BF1             MOV ESI,ECX
004BC902   E8 89EEF6FF      CALL XXXXXX.0042B790
004BC907   33C0             XOR EAX,EAX
004BC909   8946 34          MOV DWORD PTR DS:[ESI+34],EAX
004BC90C   8B0D F84E6D00    MOV ECX,DWORD PTR DS:[6D4EF8]            ; cshDC4D.345C4E48
004BC912   83C4 0C          ADD ESP,0C
004BC915   5E               POP ESI
004BC916   3BC8             CMP ECX,EAX
004BC918   74 15            JE SHORT XXXXXX.004BC92F
004BC91A   837D 0C 06       CMP DWORD PTR SS:[EBP+C],6
004BC91E   75 05            JNZ SHORT XXXXXX.004BC925
004BC920   B8 51000000      MOV EAX,51
004BC925   8B11             MOV EDX,DWORD PTR DS:[ECX]
004BC927   50               PUSH EAX
004BC928   8B42 1C          MOV EAX,DWORD PTR DS:[EDX+1C]
004BC92B   6A 01            PUSH 1
004BC92D   FFD0             CALL EAX
004BC92F   5D               POP EBP
004BC930   C2 0800          RETN 8
use inline assembly if that's what you mean?
Quote Originally Posted by Auxilium View Post
use inline assembly if that's what you mean?
Sorry my english is bad :/
Assuming the address is static and your jump does not need to change from the offset it has:
Code:
BYTE btJump[] = { 0xEB, 0x37, 0x90, 0x90, 0x90 };
memcpy( (LPVOID)0x004BC8F4, &btJump, sizeof( btJump ) );
Quote Originally Posted by atom0s View Post
Assuming the address is static and your jump does not need to change from the offset it has:
Code:
BYTE btJump[] = { 0xEB, 0x37, 0x90, 0x90, 0x90 };
memcpy( (LPVOID)0x004BC8F4, &btJump, sizeof( btJump ) );
Thanks work.
Quote Originally Posted by atom0s View Post
Assuming the address is static and your jump does not need to change from the offset it has:
Code:
BYTE btJump[] = { 0xEB, 0x37, 0x90, 0x90, 0x90 };
memcpy( (LPVOID)0x004BC8F4, &btJump, sizeof( btJump ) );
Is the virtualprotect function required to do memcpy?
Quote Originally Posted by FingerLickin'Good View Post
Is the virtualprotect function required to do memcpy?
It can be if the page you are writing to is protected. I'm assuming in his case it wasn't.
Quote Originally Posted by atom0s View Post
Assuming the address is static and your jump does not need to change from the offset it has:
Code:
BYTE btJump[] = { 0xEB, 0x37, 0x90, 0x90, 0x90 };
memcpy( (LPVOID)0x004BC8F4, &btJump, sizeof( btJump ) );
what is Delphi and VB.NET Code ?
Quote Originally Posted by NmDahmeT View Post
what is Delphi and VB.NET Code ?
I do not code in either Delphi or VB.NET. Both are horrible languages imo.
Quote Originally Posted by atom0s View Post
It can be if the page you are writing to is protected. I'm assuming in his case it wasn't.
if you don't know whether or not it's protected?
Quote Originally Posted by FingerLickin'Good View Post
if you don't know whether or not it's protected?
If you don't know ahead of time then just use VirtualProtect to unprotect it.
Posts 1–12 of 12 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us