Creating Byte Patterns

Posts 1–14 of 14 · Page 1 of 1
Creating Byte Patterns
In this tut, i'm gonna teach you, how to create byte patterns, with the easiest way i can...
To start you need:
-A debugger
-Brain.exe

First of all, you have to find the needed offset, i will use "ReloadAnimRatio"

This is the actual CF Eu CShell.dll:
Code:
102359F9   68 ACF65510      PUSH CShell.1055F6AC                     ; ASCII "ReloadAnimRatio"
102359FE   D998 3C0C0000    FSTP DWORD PTR DS:[EAX+C3C]
10235A04   55               PUSH EBP
10235A05   E8 86662500      CALL CShell.1048C090
10235A0A   83C4 08          ADD ESP,8
10235A0D   85C0             TEST EAX,EAX
10235A0F   74 46            JE SHORT CShell.10235A57
10235A11   8B48 04          MOV ECX,DWORD PTR DS:[EAX+4]
10235A14   8B51 04          MOV EDX,DWORD PTR DS:[ECX+4]
10235A17   8B0D 3C5D0111    MOV ECX,DWORD PTR DS:[11015D3C]
10235A1D   85C9             TEST ECX,ECX
10235A1F   8B5A 04          MOV EBX,DWORD PTR DS:[EDX+4]
10235A22   74 0E            JE SHORT CShell.10235A32
10235A24   A1 405D0111      MOV EAX,DWORD PTR DS:[11015D40]
10235A29   2BC1             SUB EAX,ECX
10235A2B   C1F8 02          SAR EAX,2
10235A2E   3BF0             CMP ESI,EAX
10235A30   72 08            JB SHORT CShell.10235A3A
10235A32   FFD7             CALL EDI
10235A34   8B0D 3C5D0111    MOV ECX,DWORD PTR DS:[11015D3C]
10235A3A   53               PUSH EBX
10235A3B   8D3CB1           LEA EDI,DWORD PTR DS:[ECX+ESI*4]
10235A3E   FF15 ACC45110    CALL DWORD PTR DS:[1051C4AC]             ; MSVCR80.atof
10235A44   D95C24 14        FSTP DWORD PTR SS:[ESP+14]
10235A48   D94424 14        FLD DWORD PTR SS:[ESP+14]
10235A4C   8B07             MOV EAX,DWORD PTR DS:[EDI]
10235A4E   D998 3C0C0000    FSTP DWORD PTR DS:[EAX+C3C]
10235A54   83C4 04          ADD ESP,4
I don't teach you how to find this, not how to find out, which is the offset, only in major parts...

So you know the offset is:
Code:
10235A4E   D998 3C0C0000    FSTP DWORD PTR DS:[EAX+C3C]
But you need more byte, to make sure, so you a bit more command...

Code:
10235A48   D94424 14        FLD DWORD PTR SS:[ESP+14]
10235A4C   8B07             MOV EAX,DWORD PTR DS:[EDI]
10235A4E   D998 3C0C0000    FSTP DWORD PTR DS:[EAX+C3C]
Than you need the central column, that is the Bytes (in Olly)

Code:
D94424 14
8B07
D998 3C0C0000
Each 2 number represents 1 byte in this way:
Code:
D9 44 24 14
8B 07
D9 98 3C 0C 00 00
put them in a single line:
Code:
D9 44 24 14 8B 07 D9 98 3C 0C 00 00
this is still NOT correct, because some of the bytes would change after a patch...
You have to describe which is static, and which is dynamic bytes...
to do this, you gonna use the command, but you need some brain and a small ASM knowledge

The commands are:
Code:
FLD DWORD PTR SS:[ESP+14]
MOV EAX,DWORD PTR DS:[EDI]
FSTP DWORD PTR DS:[EAX+C3C]
Than you have to match the bytes to the commands...
That means, we figure out, which byte is a command, and which is a parameter...
Code:
D94424 14           FLD DWORD PTR SS:[ESP+14]
8B07                            MOV EAX,DWORD PTR DS:[EDI]
D998 3C0C0000          FSTP DWORD PTR DS:[EAX+C3C]
Greens are static bytes, while orange is dynamic...
So, Green bytes won't change after each patch but greens are possibli will...
Now we have to create the Byte Mask, the FindPattern use it to decide wheter it has to check the specific byte or not...
X = Means Static Bytes, FindPattern will Check
? = Dynamic byte, FindPattern will ignores...

In this case, Green bytes will be "X" and orange ones will be "?"

Code:
D9 44 24 14 8B 07 D9 98 3C 0C 00 00
x   x   x   ?   x  x   x   x   ?   ?   ?   ?
Now, you have pattern and the mask too...

Second step is to read ou the needed value...
But how it is works ?

FindPattern loop throught the memory, searching for this byte array (pattern)...
When it finds is, it sends back the ADDRESS where it found it...
Like "0x0A3244"...
It is still NOT the offset...
"0x0A3244" is the starting address of that byte array...
that means:
Code:
HEX         + DEC =  HEX
0x0A3244 + 00   = D9
0x0A3244 + 01   = 44
0x0A3244 + 02   = 24
0x0A3244 + 03   = 14
0x0A3244 + 04   = 8B
0x0A3244 + 05   = 07
0x0A3244 + 06   = D9
0x0A3244 + 07   = 98
0x0A3244 + 08   = 3C
0x0A3244 + 09   = 0C
0x0A3244 + 10   = 00
0x0A3244 + 11   = 00
Than we has the pointer "0x0A3244" and the offset "08" for the Reload Offset...
Why 08 ? Because that 4 byte is an INT number...
So the most logical way to read out as an int...
Code:
ReloadOffset = *(int*)(0x0A3244 + 08);
and it will read out that 4 bytes (1 int) and done you has the offset...

For pointers, you has to do the same, but use "DWORD" instead of "int" and you have to remove the "CShell" from the value, since the pointers point into the CShell also...

So:
Code:
WeaponMgr = (*(DWOR*)(0x0A3244 + 08))-CShell;
Goo luck for every rookie hacker...
nice tutorial. Very easy to understand. ( sorry for bad english )
Nice tutorial
i love your tutorials . special thx
Well Done
Very Good TuT and Easy To Understand
@ComboDance @olwayy @I2espect @sobasoba13

Thanks for all... (y) i'll keep making tuts for newbies if i figure out some useful thing that hackers may need...
Please also create a tut on how to create an AddyLogger. Thanks in advance..
Nice tutorial , Good Job
There is an ollydbg plugin for that -.-
i use that plugin. But really good to learn how to make it urself
Good job ?
Old tutorial, have much others in this section.
You think you're making a tutorial, but speak as if the person you're teaching has no idea about anything lol.
Posts 1–14 of 14 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us