Pointer Problem

Posts 1–12 of 12 · Page 1 of 1
Pointer Problem
Basically, I'm trying to get the address a pointer points to, then add a hex. value to it and write from there.

Here's what I have now,

Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, DWORD OFF_2 = 0, INT Value = 0)
{
    __try {
        DWORD_PTR ptrLoc = (DWORD_PTR)((int*)dwBase + OFF_1); //STORE_POINTED_ADDRESS
        DWORD BUFF = ptrLoc + OFF_2; //GET_POINTED_ADDY + HEXDECIMAL

        *( int *)( *( int *) BUFF) = Value; //WRITE_TO_ADDRESS

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
It isn't working correctly, and I've also tried,

Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, DWORD OFF_2 = 0, INT Value = 0)
{
    __try {
        DWORD BUFF = *(int*)(dwBase + OFF_1);
        BUFF += OFF_2;

        *( int *)( *( int *) BUFF) = Value;

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
Which should logically work, but doesn't.
Quote Originally Posted by drlunar View Post
..
Are you trying to dereference 2 pointers? Looking at your code, I'm not sure why you have 2 offsets.

Basically you're adding 2 offsets, which I don't understand, because you might as well make it one large offset. I must be mistaken.

In the first code you derefernce the pointer then add off_1 and off_2. Math says you might as well just add one large offset instead of two smaller. Unless you're trying to dereference twice...



Code:
 
DWORD ptrLoc = *(DWORD*)dwBase;
ptrLoc += OFF_1;

//At this point, are you trying to dereference another pointer, or simply add a 2nd offset?
2 deref.
Code:
DWORD ptrLoc = *(DWORD*)dwBase;
ptrLoc += OFF_1;

DWORD BUFF = *(DWORD*)ptrLoc;
BUFF += OFF_2;
only 1 deref.
Code:
DWORD ptrLoc = *(DWORD*)dwBase;
ptrLoc += OFF_1;

DWORD BUFF = ptrLoc + OFF_2; // Why not just say "ptrLoc += OFF_1 + OFF_2" ...
--I'm not too great with pointer syntax. So I broke it up as 1 operation per line. You can combine them into a single statement; I didn't.
I'm trying to get the address a pointer points to, then add a hex. value...
I'm trying to get the address referenced at 'BASE+OFF_1', then add 'OFF_2' to that, to calculate my final address.
Quote Originally Posted by drlunar View Post
...
Code:
DWORD ptr = *(DWORD*)base;

ptr += OFF_1;

ptr = *(DWORD*)ptr;
ptr += OFF_2;
I think : )

--------
edit:
'BASE+OFF_1'
You mean "Read the value at Base, then add OFF_1" ..... I think.

Should be written as [base] + off_1;

Use the [ ]'s to mean "Read the value at this address". Then add offset. Otherwise it looks like you're saying add off_1 to base, then dereference; which would be silly.

 
edit

Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, DWORD OFF_2 = 0, INT Value = 0)
{
    __try {
        DWORD ptrLoc = *(DWORD*)dwBase;
        ptrLoc += OFF_1;
        DWORD BUFF = *(DWORD*) ptrLoc;
        BUFF  += OFF_2; 

        *(DWORD*)BUFF = Value; //WRITE_TO_ADDRESS

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
Example,

Code:
class Main {
  Main(...) {
    Profile profile* = new profile;
    profile->VALID = ?;
  }
public:
  class Profile {
    INT VALID = 0;
  }
}
(BASE + OFF_1) point to 'Profile', created in user-space virtualized memory.
Then, I want to add a constant hex. value (to (BASE+OFF_1)) to calculate the location of 'VALID'.
base + off_1 is a constant. :|



edit: so you mean

Code:
base += OFF_1; // wtf

DWORD ptr = *(DWORD*)base;

ptr += OFF_2;
Quote Originally Posted by abuckau907 View Post
base + off_1 is a constant. :|
By constant, I mean OFF_2, which will calculate the location of 'VALID'.



The first "address" that you pull out.....

is it stored in dwBase, or dwBase + off_1

?

We have to read 4 bytes, which will contain an address:

Is that address STORED in dwBase, or dwBase + off_1



If the 2nd, dwBase + off_1 is a constant. It's like saying

Int x = 0;
x += 10;
x += 5;
//why not just add 15
dwBase is the 'base' address, we then TRY to add OFF_1 to grab the address 'profile' is located at in the virtualized mem. space.
Then, to obtain the final address, I want to add a hex value atop of the address that (dwBase+OFF_1) point to.
Quote Originally Posted by drlunar View Post
dwBase is the 'base' address, we then TRY to add OFF_1 to grab the address 'profile' is located at in the virtualized mem. space.
Then, to obtain the final address, I want to add a hex value atop of the address that (dwBase+OFF_1) point to.
(Sorry for delay, stepped out of the house - if you prefer Skype over communicating via forum, add me: username is same as here on mpgh)

Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, DWORD OFF_2 = 0, INT Value = 0)
{
    __try {
        DWORD ptrLoc = dwBase + OFF_1; // actual base address

        ptrLoc = *(DWORD)* ptrLoc; // read the value(which is a 4 byte memory address) at ptrLoc. Ie. Dereference*
       
        ptrLoc += OFF_2; // add offset to the value we got

        *(DWORD*) ptrLoc = Value; // Write a new value at that address

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
I think. ?

 
edit

Btw,
dwBase is the 'base' address, we then TRY to add OFF_1...
So dwBase + off_1 is still a constant

ie. 1000000 + 15 is the same as using 1000015 ...

You should* be adding the first offset to your 'base base address' BEFORE calling the WriteMultiPtr function, not inside it.

That is..
Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, INT Value = 0)
{
    __try {
        ptrLoc = *(DWORD)* ptrLoc; // Dereference ptrLoc
       
        ptrLoc += OFF_2; // add offset to the value we got

        *(DWORD*) ptrLoc = Value; // Write a new value at that address

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
used as:
Code:
DWORD base = 0x10000000;
const INT OFFSET_1 = 0x****;
const INT OFFSET_2 = 0x****;

DWORD actualBase = base + OFFSET_1;

WriteMultiPtr(actualBase, OFFSET_2, 1000); // 1000 is value written
//Calculate the actual baseAddress HERE, NOT inside the WriteMultiPtr function.
//Otherwise any time you call that function, it will add the offset to your baseAddress. That is NOT what you want. At that point, it's not a generic function anymore.
Design choice. You'll see once you try to add more functionality to your code.
Well, I found out my problem.. All the methods I posted about above seem to actually work, but my compiler was, for some odd reason, not reading my class correctly, and running my OLD structure instead.

Requesting thread closure or marked as solved.
Quote Originally Posted by drlunar View Post
Well, I found out my problem.. All the methods I posted about above seem to actually work, but my compiler was, for some odd reason, not reading my class correctly, and running my OLD structure instead.

Requesting thread closure or marked as solved.
your code from OP
Code:
BOOL WriteMultiPtr(DWORD dwBase, DWORD OFF_1 = 0, DWORD OFF_2 = 0, INT Value = 0)
{
    __try {
        DWORD BUFF = *(int*)(dwBase + OFF_1);
        BUFF += OFF_2;

        *( int *)( *( int *) BUFF) = Value;

        return TRUE;
    }
    __except (EXCEPTION_EXECUTE_HANDLER) { return FALSE; }
}
I'm trying to get the address referenced at 'BASE+OFF_1', then add 'OFF_2' to that, to calculate my final address.
dwBase is the 'base' address, we then TRY to add OFF_1 to grab the address 'profile' is located at in the virtualized mem. space.
Then, to obtain the final address, I want to add a hex value atop of the address that (dwBase+OFF_1) point to.
(BASE + OFF_1) point to 'Profile'...
Then, I want to add a constant hex. value (to (BASE+OFF_1)) to calculate the location of 'VALID'.
Isn't the code dereferencing twice? *(int*)(*(int*)BUFF)
But your saying "dereference (dwbase+OFF_1) then add OFF_2 and done." ??

I thought, based on your description, it would be simply *(int*)BUFF = Value;

Cool that it works now maybe now u can help explain it to me? sry & thnx. Is "*( int *)( *( int *) BUFF) = Value;" doing 2 dereferences or simply 1 ??
Posts 1–12 of 12 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us