Byte Patterns ASM

Posts 1–6 of 6 · Page 1 of 1
Byte Patterns ASM
I have the following line in ASM

Code:
_:004F73BB C6 83 54 41 03 00 01     mov  byte ptr [ebx+34154h], 1
In c++ i need to return the value of 34154h as an address ( 0x34154 )


Im hoping this can be done like so:

Code:
 void getADR(BYTE *ptr1){//something like this?
         __asm{//i don't know how to call this at 004F73BB
              mov [ptr1], ebx
              mov  byte ptr [ebx+34154h], 1
         }
         //((BYTE)0x004F73BB - ptr1)
    }


_____MY Logger____
This is my address logger that gets the ASM line 0x004F73BB
The playerpointer and server pointers are both easy to get because the byte patters point to a MOV and MOV returns the pointer of itself.

Code:
DWORD FindPattern(DWORD dwAddress, DWORD dwLen, BYTE *bMask, char * szMask)
    {
    	for (DWORD i = 0; i < dwLen; i++)
    	if (Match((BYTE*)(dwAddress + i), bMask, szMask))
    		return (DWORD)(dwAddress + i);
    
    	return 0;
    }
    void SearchPatterns(void)
    {
    	while (true){
    
    		add_log("ADR_PlayerPointer", "\xA4\xA2\xAE\x00", "xxx?", "A4 A2 AE 00, xxx?");
    		add_log("ADR_ServerPointer", "\x48\x92\xAE\x00", "xxx?", "A1 48 92 AE 00, xxx?");
    		add_log("OFS_5thSlot", "\x75\x09\xC6\x83\x54\x41\x03\x00\x01", "xxxxxxx?x", "75 09 C6 83 54 41 03 00 01, xxxxxxx?x");
    
    		ExitProcess(0);
    	}
    }
    
    
    
    BOOL WINAPI DllMain(HMODULE hDll, DWORD dwReason, LPVOID lpReserved)
    {
    	//DisableThreadLibraryCalls(hDll);
    	if (dwReason == DLL_PROCESS_ATTACH)
    	{
    		logging(hDll);
    		CreateThread(NULL, NULL, (LPTHREAD_START_ROUTINE)SearchPatterns, NULL, NULL, NULL);
    	}
    	return TRUE;
    }
Option 1:
Hook the function as you'll need to catch the value of EBX.
Redirect it to a stub:

Code:
// I assume you know about hooking...

__declspec(naked) void x(){
  __asm{ 
     mov ds:[ ptr ], ebx
     mov  byte ptr [ebx+34154h], 1
     jmp [retPtr]
  }
}
After that happens:

Code:
Log( "mein addr: %08x", *PDWORD( (char*)ptr + 0x34154 ) );
Option 2:

Additionally, you can simply attach a debugger and break on access at that instruction ( Hardware/Software breakpoints or whatever tickles your fancy ).
Once you get the value of EBX, it's simply adding then getting that pointer's value.
That'll be your address.
A hook as mentioned above would be okay or a code cave. But typically altering the code section might be caught by an anticheat. You can also try placing an exception handler to catch the instruction on access.
Quote Originally Posted by stdio View Post
A hook as mentioned above would be okay or a code cave. But typically altering the code section might be caught by an anticheat. You can also try placing an exception handler to catch the instruction on access.
VirtualProtect edits the entire page's protection. You'll catch every function if you do that.
If that's what you meant.
Yes. He'll have to remove it shortly after. It's why an exception handler would be slow. But it would help him get access to the registers.
When the exception handler is hit he can check the EIP.
Good shit guys, thanks a billion
Posts 1–6 of 6 · Page 1 of 1

Post a Reply

Similar Threads

Tags for this Thread

None

Talk with us