Functions from cracky7
I'll give the source with some explaination of some functions in the cracky7 hack. I'll do alot in inline asm because i find that easy
Im dutch so i'll have some dutch names for it.
Introduction
Most of the time codecaves made by inline asm will be done. Codecaves mean that on a certain adress we'll jump to somewhere else simply because there's no room to edit in the Original code. With a codecave we do it like this:
Adress (Place of a function we want to edit)
->Empty space (Place for our modified function)
->Jump back to Original code (So the code can continou)
I use inline asm because its easy to edit valuables with c++.
I hope this part is clear. Let's make OPK!!!!!!
Opk
Explained Opk
The Original code of Opk is like this:
// // Get the value of eax in edx+8. ( With hack our positiony is in eax. So everybody will teleport to us in Z-axis)[/code]
So with this we basicly have the stuff needed to make opk.
Now the last part, making our modified function work:
Please if I explained badly tell me, also when i made a mistake pls tell me.
I hope you understand how to make it.. Im planning on adding more like unl ammo with refill or quickdraw.
Please becarefull with what u do and dont hack to Obvious! Im also not responsible for bans..
Log:
12-02-2014 - Begin, Opk added
Im dutch so i'll have some dutch names for it.Introduction
Most of the time codecaves made by inline asm will be done. Codecaves mean that on a certain adress we'll jump to somewhere else simply because there's no room to edit in the Original code. With a codecave we do it like this:
Adress (Place of a function we want to edit)
->Empty space (Place for our modified function)
->Jump back to Original code (So the code can continou)
I use inline asm because its easy to edit valuables with c++.
I hope this part is clear. Let's make OPK!!!!!!
Opk
Code:
#define ASM_OPKX 0x00466960
#define MEM_POSX 0x00C2B518
#define MEM_POSY 0x00C2B51C
#define MEM_POSZ 0x00C2B520
DWORD Callbackbase = (ASM_OPKX+0x13);//posx
float PositieX;
float PositieY;
float PositieZ;
void __declspec(naked) playerbase()
{
__asm {
jmp [toccopkon]//jmp tocodecave
toccopkon://codecave to opk
mov eax, PositieX // PositieX means PositionX
add edx, 0D8h
mov [edx],eax
mov ecx,PositieY
mov [edx+4],ecx
mov eax,PositieZ
jmp [Callbackbase]//jump back to Original code
}
}
if(item.opk==1)
{
PositieX = *(float*)MEM_POSX;
PositieY = *(float*)(MEM_POSX + 0x4);
PositieZ = *(float*)(MEM_POSX + 0x8);
cdetour->DetourFunc((PBYTE)ASM_OPKX, (PBYTE)playerbase,5);
}else
{
ctool->WriteAsm((void*)ASM_OPKX,(PBYTE)"\x8B\x07\x81\xC2\xD8\x00\x00\x00",8);//off byte eerste 2 regels
}
The Original code of Opk is like this:
Code:
.text:0046695A mov edx, [esi+1BCh] // edx = pointer + 1BC (believe its pointer to struc of all players, i call it basepointer) .text:00466960 mov eax, [edi] // Value of edi is stored in eax. This is the X position (We can use this to store our position in eax, so all players will teleport to us) .text:00466962 add edx, 0D8h // Add 0xD8 to edx (PlayerpositionX = esi+1BC+D8 => basepointer+D8) .text:00466968 mov [edx], eax // Get the value of eax in edx. ( With hack our positionx is in eax. So everybody will teleport to us in X-axis) .text:0046696A mov ecx, [edi+4] // Value of edi+4 is stored in eax. This is the Y position (We can use this to store our position in eax, so all players will teleport to us) .text:0046696D mov [edx+4], ecx // Get the value of eax in edx+4. ( With hack our positiony is in eax. So everybody will teleport to us in Y-axis) .text:00466970 mov eax, [edi+8] // Value of edi+8 is stored in eax. This is the Z position (We can use this to store our position in eax, so all players will teleport to us) .text:00466973 mov edi, [esp+2Ch+var_1C] .text:00466977 mov [edx+8], eax
So with this we basicly have the stuff needed to make opk.
Code:
mov eax, PositieX // Get our position on X-axis in eax add edx, 0D8h // edx+D8 is where enemy position is. mov [edx],eax // Get our positionX in edx, so all enemy players will teleport to us. mov ecx,PositieY // Get our position on Y-axis in eax mov [edx+4],ecx // Get our positionY in edx, so all enemy players will teleport to us. mov eax,PositieZ // Get our position on X-axis in eax jmp [Callbackbase]//jump back to Original code. We will jump back to this part: 00466973 mov edi, [esp+2Ch+var_1C]. This is where we stopped modifying the Original code.
Code:
if(item.opk==1)// when opk is turned on
{
PositieX = *(float*)MEM_POSX; // get our positionX into PositieX (used in opk)
PositieY = *(float*)(MEM_POSX + 0x4); // get our positionY into PositieY (used in opk)
PositieZ = *(float*)(MEM_POSX + 0x8);// get our positionZ into PositieZ (used in opk)
cdetour->DetourFunc((PBYTE)ASM_OPKX, (PBYTE)playerbase,5);// The jmp will be 5 bytes long
}else
{
ctool->WriteAsm((void*)ASM_OPKX,(PBYTE)"\x8B\x07\x81\xC2\xD8\x00\x00\x00",8);
}
Offbyte explained:
.text:00466960 mov eax, [edi] // ASM_OPKX , where we begin our modification (2 bytes long, 0x8B 0x07)
.text:00466962 add edx, 0D8h // See above ( 6 bytes long, 0x81 0xC2 0xD8 0x00 0x00 0x00)
.text:00466968 mov [edx], eax // because our jmp to jump to codecave is 5 bytes long will need to restore add edx, 0D8h aswell. The offbytes of both will be 0x8B 0x07 0x81 0xC2 0xD8 0x00 0x00 0x00. After this the original code wont go to the place where we modify it.
I hope you understand how to make it.. Im planning on adding more like unl ammo with refill or quickdraw.
Please becarefull with what u do and dont hack to Obvious! Im also not responsible for bans..
Log:
12-02-2014 - Begin, Opk added


