Creating Byte Patterns
In this tut, i'm gonna teach you, how to create byte patterns, with the easiest way i can...
To start you need:
-A debugger
-Brain.exe
First of all, you have to find the needed offset, i will use "ReloadAnimRatio"
This is the actual CF Eu CShell.dll:
I don't teach you how to find this, not how to find out, which is the offset, only in major parts...
So you know the offset is:
But you need more byte, to make sure, so you a bit more command...
Than you need the central column, that is the Bytes (in Olly)
Each 2 number represents 1 byte in this way:
put them in a single line:
this is still NOT correct, because some of the bytes would change after a patch...
You have to describe which is static, and which is dynamic bytes...
to do this, you gonna use the command, but you need some brain and a small ASM knowledge
The commands are:
Than you have to match the bytes to the commands...
That means, we figure out, which byte is a command, and which is a parameter...
Greens are static bytes, while orange is dynamic...
So, Green bytes won't change after each patch but greens are possibli will...
Now we have to create the Byte Mask, the FindPattern use it to decide wheter it has to check the specific byte or not...
X = Means Static Bytes, FindPattern will Check
? = Dynamic byte, FindPattern will ignores...
In this case, Green bytes will be "X" and orange ones will be "?"
Now, you have pattern and the mask too...
Second step is to read ou the needed value...
But how it is works ?
FindPattern loop throught the memory, searching for this byte array (pattern)...
When it finds is, it sends back the ADDRESS where it found it...
Like "0x0A3244"...
It is still NOT the offset...
"0x0A3244" is the starting address of that byte array...
that means:
Than we has the pointer "0x0A3244" and the offset "08" for the Reload Offset...
Why 08 ? Because that 4 byte is an INT number...
So the most logical way to read out as an int...
and it will read out that 4 bytes (1 int) and done you has the offset...
For pointers, you has to do the same, but use "DWORD" instead of "int" and you have to remove the "CShell" from the value, since the pointers point into the CShell also...
So:
Goo luck for every rookie hacker...
To start you need:
-A debugger
-Brain.exe
First of all, you have to find the needed offset, i will use "ReloadAnimRatio"
This is the actual CF Eu CShell.dll:
Code:
102359F9 68 ACF65510 PUSH CShell.1055F6AC ; ASCII "ReloadAnimRatio" 102359FE D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C] 10235A04 55 PUSH EBP 10235A05 E8 86662500 CALL CShell.1048C090 10235A0A 83C4 08 ADD ESP,8 10235A0D 85C0 TEST EAX,EAX 10235A0F 74 46 JE SHORT CShell.10235A57 10235A11 8B48 04 MOV ECX,DWORD PTR DS:[EAX+4] 10235A14 8B51 04 MOV EDX,DWORD PTR DS:[ECX+4] 10235A17 8B0D 3C5D0111 MOV ECX,DWORD PTR DS:[11015D3C] 10235A1D 85C9 TEST ECX,ECX 10235A1F 8B5A 04 MOV EBX,DWORD PTR DS:[EDX+4] 10235A22 74 0E JE SHORT CShell.10235A32 10235A24 A1 405D0111 MOV EAX,DWORD PTR DS:[11015D40] 10235A29 2BC1 SUB EAX,ECX 10235A2B C1F8 02 SAR EAX,2 10235A2E 3BF0 CMP ESI,EAX 10235A30 72 08 JB SHORT CShell.10235A3A 10235A32 FFD7 CALL EDI 10235A34 8B0D 3C5D0111 MOV ECX,DWORD PTR DS:[11015D3C] 10235A3A 53 PUSH EBX 10235A3B 8D3CB1 LEA EDI,DWORD PTR DS:[ECX+ESI*4] 10235A3E FF15 ACC45110 CALL DWORD PTR DS:[1051C4AC] ; MSVCR80.atof 10235A44 D95C24 14 FSTP DWORD PTR SS:[ESP+14] 10235A48 D94424 14 FLD DWORD PTR SS:[ESP+14] 10235A4C 8B07 MOV EAX,DWORD PTR DS:[EDI] 10235A4E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C] 10235A54 83C4 04 ADD ESP,4
So you know the offset is:
Code:
10235A4E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
Code:
10235A48 D94424 14 FLD DWORD PTR SS:[ESP+14] 10235A4C 8B07 MOV EAX,DWORD PTR DS:[EDI] 10235A4E D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
Code:
D94424 14 8B07 D998 3C0C0000
Code:
D9 44 24 14 8B 07 D9 98 3C 0C 00 00
Code:
D9 44 24 14 8B 07 D9 98 3C 0C 00 00
You have to describe which is static, and which is dynamic bytes...
to do this, you gonna use the command, but you need some brain and a small ASM knowledge
The commands are:
Code:
FLD DWORD PTR SS:[ESP+14] MOV EAX,DWORD PTR DS:[EDI] FSTP DWORD PTR DS:[EAX+C3C]
That means, we figure out, which byte is a command, and which is a parameter...
Code:
D94424 14 FLD DWORD PTR SS:[ESP+14] 8B07 MOV EAX,DWORD PTR DS:[EDI] D998 3C0C0000 FSTP DWORD PTR DS:[EAX+C3C]
So, Green bytes won't change after each patch but greens are possibli will...
Now we have to create the Byte Mask, the FindPattern use it to decide wheter it has to check the specific byte or not...
X = Means Static Bytes, FindPattern will Check
? = Dynamic byte, FindPattern will ignores...
In this case, Green bytes will be "X" and orange ones will be "?"
Code:
D9 44 24 14 8B 07 D9 98 3C 0C 00 00 x x x ? x x x x ? ? ? ?
Second step is to read ou the needed value...
But how it is works ?
FindPattern loop throught the memory, searching for this byte array (pattern)...
When it finds is, it sends back the ADDRESS where it found it...
Like "0x0A3244"...
It is still NOT the offset...
"0x0A3244" is the starting address of that byte array...
that means:
Code:
HEX + DEC = HEX 0x0A3244 + 00 = D9 0x0A3244 + 01 = 44 0x0A3244 + 02 = 24 0x0A3244 + 03 = 14 0x0A3244 + 04 = 8B 0x0A3244 + 05 = 07 0x0A3244 + 06 = D9 0x0A3244 + 07 = 98 0x0A3244 + 08 = 3C 0x0A3244 + 09 = 0C 0x0A3244 + 10 = 00 0x0A3244 + 11 = 00
Why 08 ? Because that 4 byte is an INT number...
So the most logical way to read out as an int...
Code:
ReloadOffset = *(int*)(0x0A3244 + 08);
For pointers, you has to do the same, but use "DWORD" instead of "int" and you have to remove the "CShell" from the value, since the pointers point into the CShell also...
So:
Code:
WeaponMgr = (*(DWOR*)(0x0A3244 + 08))-CShell;
)
special thx

