ExclamationHelpAdress Pointers

Posts 1–6 of 6 · Page 1 of 1
Adress Pointers
Hello, i'm here to ask how to track the pointers, im making a trainer, and i want to add a adress(yes i use readwrittingmemory.vb) AND i alredy know the pointer and offset by using CE, can someone help me?
Please explain better.
Ok, lets see, im trying to make a trainer but the adress always change(yeah pointers and offset) i want to know how to find the new adress and yes i alredy scanned stuff in cheat engine so i know the offsets
Quote Originally Posted by Kyoz123 View Post
Ok, lets see, im trying to make a trainer but the adress always change(yeah pointers and offset) i want to know how to find the new adress and yes i alredy scanned stuff in cheat engine so i know the offsets
You did a proper Pointer Scan?
(Closed the game and re-did the pointer scan without closing CE)

If so, then a pattern scanning would do the trick maybe.
(It allows you to scan for a pattern of bytes. Also known as AOB (Array of Bytes) Scanner)


Tho, then you would have to find/make the pattern from the game. (This is also used sometimes, as it allows you to search for arrays, while having unknown bytes in the AOB)


Example like:
(My VB coding is horrible. So if you understand it. I'm sure you're able to make something like this
Dim MyArray As Byte() = TheBytes
For Each ByTe As Byte In ReadMemory(Starting Address, Size of ByteBlock, ETC)
If ByTe = MyArray(CurrentIndex) Or MyArray(CurrentIndex) = 0 *The Unknown Value* Then Continue Pattern Search
ELSE: Stop and start from Index 0.
I think he's just asking for multilevel pointers in vb..

I have no idea what your readwrittingmemory.vb can do since I'v never used it but here is an example.
The code seems like alot but it covers a few things and can be used separate from your current memory class.

 
Screenshot of my example pointer


 
Pointer Function
Code:
    Declare Function ReadProcessMemory Lib "kernel32" Alias "ReadProcessMemory" (ByVal hProcess As IntPtr, ByVal lpBaseAddress As Integer, ByVal buffer As Byte(), ByVal size As Integer, ByVal lpNumberOfBytesRead As Integer) As Boolean

    Function GetPointer(ByVal ProcessName As String, ByVal PointerBase As Object, ByVal Offsets As Integer()) As Integer
        'Get the Process and return 0 if not found
        Dim P = Process.GetProcessesByName(ProcessName)
        If P.Length = 0 Then Return 0

        Dim Address = PointerBase
        Dim buff(3) As Byte

        'Check PointerBase type. String type will be treated as a module for codeshifting.
        If PointerBase.GetType Is GetType(String) Then
            Dim tmp As String() = PointerBase.ToString.Split(New Char() {"+"c})

            'If PointerBase type is String but isn't a module
            If tmp.Length = 1 Then
                Address = Integer.Parse(tmp(0), System.Globalization.NumberStyles.HexNumber)
            Else
                'Continue on to loop the modules and get the base+offset
                For Each M In P(0).Modules
                    If M.ModuleName.ToLower = tmp(0).ToLower Then
                        Address = M.BaseAddress.ToInt32 + Integer.Parse(tmp(1), System.Globalization.NumberStyles.HexNumber)
                        Exit For
                    End If
                Next
                If Address = 0 Then Return 0 'Just incase the module wasn't found.
            End If
        End If


        If Not ReadProcessMemory(P(0).Handle, Address, buff, buff.Length, 0) Then Return 0
        Address = BitConverter.ToInt32(buff, 0)

        'Loops through the pointer offsets and returns 0 if ReadProcessMemory fails.
        For X = 0 To Offsets.Length - 1
            If Not ReadProcessMemory(P(0).Handle, Address + Offsets(X), buff, buff.Length, 0) Then Return 0
            Address = If(X <> Offsets.Length - 1, BitConverter.ToInt32(buff, 0), Address + Offsets(X))
        Next
        Return Address
    End Function


Usage using that pointer in the screenshot..

Base module
Code:
Dim PointerBase = GetPointer("solitaire", "solitaire.exe+97074", New Integer() {&H2C, &H8})
Normal integer
Code:
Dim PointerBase = GetPointer("solitaire", &H507074, New Integer() {&H2C, &H8})
Module from the collection
Code:
Dim PointerBase = GetPointer("solitaire", "SomeDll.dll+12345", New Integer() {&H10, &H20})
That should cover normal,codeshifting and pointers located in any module including dll's.
Let us know if you're after something different.
I think hes just asking how to use pointers, if so then all you need to do is to get the pointer value and add the offset and convert it to hex so you will have proper address.
I always make it like this however there are easier ways i think:
Code:
Dim pointerValue As Integer = BitConverter.ToInt32(ReadMemory(pointing_address, size), 0)
Dim finalAddy As String = Hex(pointerValue + offset)
finalAddy = "&H"+ finalAddy
However i dont know what memory module you are using, and what functions it has but you can easily adjust this to your own.
The offset has to be in HEX so its like &HA1
Ill explain this on a example from SA-MP game:
You got a address CPed +0x540 = [float]
few lines abowe you got 0xB6F5F0 - Player pointer (CPed) so 0xB6F5F0 is the CPed (pointeR) and 0x540 is the offset (You replace 0x with &H in VB)
So you just do this like this:
Code:
Dim pointerValue As Integer = BitConverter.ToInt32(ReadMemory(&HB6F5F0, 4), 0)
Dim finalAddy As String = Hex(pointerValue + &H540)
finalAddy = "&H"+ finalAddy
and its done, however you will need to write a float value otherwise the health wont be changed properly (float = single in VB)

Anyways, dont get the pointer value to a string (you see pointerValue is a integer) because it will get the bytes to a string and it will reverse them and split every byte with "-" so you will need to split the string by "-" characters and connect it in reverse order (the bytes arent reversed, but they are in reverse order so if the value is BF64FC then in your app it would show it as FC-64-BF)
Posts 1–6 of 6 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Need help?