Dark_Byte's Speedhack source code

Posts 46–60 of 86 · Page 4 of 6
Quote Originally Posted by why06 View Post
Yeh. I could but that seems like kind of a bass ackward way of doing it o_O. And it might just be easier to build a speedhack from scratch. Anyway I'm not completly sure how "injection" works or how exactly it works. I know what a .dll does but I'm a little confused on how to inject one into a process when the process hasn't called for that .dll
Aha conveniently i was researching this myself yesterday, i love Wikipedia more and more. Such a useful topic =D.

DLL injection - Wikipedia, the free encyclopedia
i like the idea of making a speed hack from scratch, but i dont know y we are stuck with dark byte's speed hack, if we put a little more effort surfing on the net to find a speed hack which is written in C++, we can actually fix the problems!!!, so whos in??
Yeh you might be able to find something. I was sorta hoping he's speed hack would be written in C++, but I guess we got the short end of the stick. Anyway sure go for it. I guess I could google around for another speedhack. Though it will be tough to find one like DarkByte's. I mean he coded the entire Cheat Engine single-handedly he's kinda a legend :l. More then that you can actly post on his site and he will answer your question o_O.

We may find another speedhack, but idk if we will find the source code for it... Sorry I can be a bit skeptical at times (like all the time) lets look for it and see.
ya i know, he is a legend, he coded the fantastic cheat engine which almost half of the runescape users use to get gp, anyways, im sure there are more than one legend in the programming world
Quote Originally Posted by why06 View Post
Lol. Ur mean xD...

And Hell_Demon, I'm not sure what that is you posted :l
Wait. Is that the speed hack in C++? Does it compile and run correctly?
I'm sorry for the late reply, dont use these forums often.
It is a QueryPerformanceCount speedhack in C++

Compiles and runs fine for me(although you need to add something in the direction of if(GetAsyncKeyState(VK_NUMPAD0)&1) speedhacking=!speedhacking; in a loop to enable/disable it while playing)

Edit: from quickly reading through the DarkByte speedhack it seems he also detours/hooks GetTickCount and timeGetTime. use msdn for parameters and the rest can be done in almost the same way as I did
Hmmm... so all these functions are used by the game to time how fast it runs. And your program detours the function so mess with it before the game reads it.

Thanks a lot Hell Demon. Let me see if I can find out more so I can detour GetTime and GetTickCount and add it to your code .
Quote Originally Posted by why06 View Post
Hmmm... so all these functions are used by the game to time how fast it runs. And your program detours the function so mess with it before the game reads it.

Thanks a lot Hell Demon. Let me see if I can find out more so I can detour GetTime and GetTickCount and add it to your code .
here is timeGetTime:
Code:
#include <windows.h>
#include <detours.h>
bool speedhacking=false;
DWORD oldtGT=0;
DWORD (*timeGetTime_orig)(void);
DWORD timeGetTime_hooked(void) 
{ 
	if(oldtGT==0)
	{
		oldtGT=(*timeGetTime_orig)();
		return oldtGT;
	}
	DWORD factor;
	DWORD ret;

	ret = (*timeGetTime_orig)();

	if(speedhacking == 1)
	{
		factor = 2.0;
		//factor = 3.0;
		//factor = 5.0;
	}
	else
	{
		factor = 1.0;
	}
	DWORD newret;
	newret = ret+((oldtGT-ret)*(factor-1));

	oldtGT=ret;
	return newret; 
}

bool WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	switch(dwReason)
	{	
	case DLL_PROCESS_ATTACH:
		timeGetTime_orig = (DWORD (__cdecl *)(void))DetourFunction((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	case DLL_PROCESS_DETACH:
		DetourRemove((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	}

	return TRUE;
}
GetTickCount:
Code:
#include <windows.h>
#include <detours.h>
bool speedhacking=false;
DWORD oldtick=0;
DWORD (WINAPI *GetTickCount_orig)(void);
DWORD WINAPI GetTickCount_hooked(void)
{ 
	if(oldtick==0)
	{
		oldtick=(*GetTickCount_orig)();
		return oldtick;
	}
	DWORD factor;
	DWORD ret;

	ret = (*GetTickCount_orig)();

	if(speedhacking == 1)
	{
		factor = 2.0;
		//factor = 3.0;
		//factor = 5.0;
	}
	else
	{
		factor = 1.0;
	}
	DWORD newret;
	newret = ret+((oldtick-ret)*(factor-1));

	oldtick=ret;
	return newret; 
}

bool WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	switch(dwReason)
	{	
	case DLL_PROCESS_ATTACH:
		GetTickCount_orig = (DWORD (__stdcall *)(void))DetourFunction((PBYTE)GetProcAddress(GetModuleHandle("Kernel32.dll"), "GetTickCount"), (PBYTE)GetTickCount_hooked);
	case DLL_PROCESS_DETACH:
		DetourRemove((PBYTE)GetProcAddress(GetModuleHandle("Kernel32.dll"), "GetTickCount"), (PBYTE)GetTickCount_hooked);
	}

	return TRUE;
}
I haven't tested these yet since I am on a crappy school computer atm ^^
Hey wow! thanks a lot. You must be a pretty smart guy to write the whole thing :P
Unfortunately I don't get how these two parts work. And I don't feel like I have the right to compile it unless I know how the code works. I know this is asking a lot, but could you explain this part:
Code:
#include <windows.h>
DWORD (*timeGetTime_orig)(void);
DWORD timeGetTime_hooked(void)
What does this declare. I think it's a function, but I've never seen a function prototype like this.



And ofcourse there's this one too.
Code:
bool WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	switch(dwReason)
	{	
	case DLL_PROCESS_ATTACH:
		timeGetTime_orig = (DWORD (__cdecl *)(void))DetourFunction((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	case DLL_PROCESS_DETACH:
		DetourRemove((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	}

	return TRUE;
}
I'm not sure what is going on here. It looks like you just defined a function DllMain but nowhere in the entire code do I see you call this function. :L
so I'm really confused o_O


I haven't tested these yet since I am on a crappy school computer atm ^^[/QUOTE]
Quote Originally Posted by why06 View Post
Code:
#include <windows.h>
DWORD (*timeGetTime_orig)(void);
DWORD timeGetTime_hooked(void)
What does this declare. I think it's a function, but I've never seen a function prototype like this.
'DWORD (*timeGetTime_orig)(void);' is a pointer to the function, which will contain the address to the original function(after we detour it)
The return value of that function is a DWORD(hence the DWORD infront of it) and it has no parameters(hence the (void)).


Quote Originally Posted by why06 View Post
And ofcourse there's this one too.
Code:
bool WINAPI DllMain( HINSTANCE hinstDLL, DWORD dwReason, LPVOID lpReserved )
{
	switch(dwReason)
	{	
	case DLL_PROCESS_ATTACH:
		timeGetTime_orig = (DWORD (__cdecl *)(void))DetourFunction((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	case DLL_PROCESS_DETACH:
		DetourRemove((PBYTE)GetProcAddress(GetModuleHandle("winmm.dll"), "timeGetTime"), (PBYTE)timeGetTime_hooked);
	}

	return TRUE;
}
I'm not sure what is going on here. It looks like you just defined a function DllMain but nowhere in the entire code do I see you call this function. :L
so I'm really confused o_O
its code for a DLL, DllMain is called when
1 Your DLL gets attached to the process
2 Your DLL gets detached from the process
And its also called for every thread starting and stopping(threads created by the DLL I asume, never used that part of it ^^)

if you wish to do this externally then you should use CreateRemoteThread and install the hooks from the thread you created in the target program.
good work very helpful
Hmmm... a pointer to a function huh? That's really interesting I didn't know you can do that. I will have to read up on function pointers.

Also I think I understand the DllMain thing now too. Thanks a lot Hell_Demon. That was a lot of help and it seems this whole thread has turned out to be very informative.

BTW: I don't completely understand everything yet, but I'm trying to wrap my head around it. Lol. If anyone else wants to give it a shot here's a little tut on function pointers: http://www.newty.de/fpt/index.html

Lol it's gonna take me a couple days to understand this... Luckily I'm on chapter 7 in my beginners guide. It covers Inline functions and classes in chapter 8. Maybe it will be easier to understand then. I have to say I'm getting to the point where I can see I'm losing my little advantage by taking 2 years of Java. I'm seeing stuff I never even heard of in Java now!
Whoah. Didn't know speed hack was that much code. Lol, I fail.
Quote Originally Posted by FragInABox View Post
Whoah. Didn't know speed hack was that much code. Lol, I fail.
:P Well the speed hack is only this much code:
Code:
DWORD WINAPI GetTickCount_hooked(void)
{ 
	if(oldtick==0)
	{
		oldtick=(*GetTickCount_orig)();
		return oldtick;
	}
	DWORD factor;
	DWORD ret;

	ret = (*GetTickCount_orig)();

	if(speedhacking == 1)
	{
		factor = 2.0;
		//factor = 3.0;
		//factor = 5.0;
	}
	else
	{
		factor = 1.0;
	}
	DWORD newret;
	newret = ret+((oldtick-ret)*(factor-1));

	oldtick=ret;
	return newret; 
}
The real effort is hooking the GetTickCount from what I can see...
are you gonna make it public (or pm it to me) soon?
just on a side note: its detected(the detours are)
so dont use it on VAC/PB secured servers
Posts 46–60 of 86 · Page 4 of 6
This thread is closed for replies.

Similar Threads

Tags for this Thread

Talk with us