[CoD4] Code

Posts 1–8 of 8 · Page 1 of 1
[CoD4] Code
Code:
#include <windows.h>

bool bWallHack=false;
bool bNoRecoil=false;
bool bNameTags=false;

unsigned char *playerFlag = (unsigned char*)0x00445480;
unsigned char xwallhackpatch[2] = { 0x6a, 0x12 }; // push 12, patched
unsigned char owallhackpatch[2];// copy unpatched

unsigned long fireRecoil = (unsigned long)0x00457D2E;
unsigned char oRecoilPatch[5];

unsigned long xTeamcheck = (unsigned long)0x0042E1AC; //Orig 0x0F 0x85 0xCE 0x00 0x00 0x00
unsigned long xVisible = (unsigned long)0x0042E1CE; //Orig 0x74 0x25
unsigned char oTeamCheckPatch[6] = { 0x0F, 0x85, 0xCE, 0x00, 0x00, 0x00 };
unsigned char oVisiblePatch[2] = { 0x74, 0x25 };

void doWallhack(void)
{
	unsigned long orig;
	if(bWallhack==false)
	{
		VirtualProtect(playerFlag, sizeof(xwallhackpatch), PAGE_EXECUTE_READWRITE, &orig);
		memcpy(playerFlag, &xwallhackpatch, sizeof(xwallhackpatch));
		VirtualProtect(playerFlag, sizeof(xwallhackpatch), orig, &orig);
		bWallHack=true;
	}
	else
	{
		VirtualProtect(playerFlag, sizeof(owallhackpatch), PAGE_EXECUTE_READWRITE, &orig);
		memcpy(playerFlag, &owallhackpatch, sizeof(owallhackpatch));
		VirtualProtect(playerFlag, sizeof(owallhackpatch), orig, &orig);
		bWallHack=false;
	}
}

void doNoRecoil(void)
{
	if(bNoRecoil==false)
	{
		//nop 5 bytes @ fireRecoil
		bNoRecoil=true;
	}
	else
	{
		VirtualProtect(fireRecoil, sizeof(oRecoilPatch), PAGE_EXECUTE_READWRITE, &orig);
		memcpy(fireRecoil, &oRecoilPatch, sizeof(oRecoilPatch));
		VirtualProtect(fireRecoil, sizeof(oRecoilPatch), orig, &orig);
		bNoRecoil=false;
	}
}

void doNametags(void)
{
	if(bNameTags==false)
	{
		//nop 6 bytes @ xTeamCheck
		//nop 2 bytes @ xVisible
	}
	else
	{
		VirtualProtect(xTeamcheck, sizeof(oTeamCheckPatch), PAGE_EXECUTE_READWRITE, &orig);
		memcpy(xTeamcheck, &oTeamCheckPatch, sizeof(oTeamCheckPatch));
		VirtualProtect(xTeamcheck, sizeof(oTeamCheckPatch), orig, &orig);
		VirtualProtect(xVisible, sizeof(oVisiblePatch), PAGE_EXECUTE_READWRITE, &orig);
		memcpy(xVisible, &oVisiblePatch, sizeof(oVisiblePatch));
		VirtualProtect(xVisible, sizeof(oVisiblePatch), orig, &orig);
	}
}

void InitBackups(void)
{
	unsigned long orig;
	VirtualProtect(playerFlag, sizeof(owallhackpatch), PAGE_EXECUTE_READWRITE, &orig);
	memcpy(owallhackpatch, playerFlag, sizeof(owallhackpatch));
	VirtualProtect(playerFlag, sizeof(owallhackpatch), orig, &orig);

	VirtualProtect(fireRecoil, sizeof(oRecoilPatch), PAGE_EXECUTE_READWRITE, &orig);
	memcpy(oRecoilPatch, fireRecoil, sizeof(oRecoilPatch));
	VirtualProtect(fireRecoil, sizeof(oRecoilPatch), orig, &orig);
}

void HackThread(void)
{
	InitBackups();
	while(1)
	{
		if(GetAsyncKeyState(VK_NUMPAD0)&1) // Panic key
		{
			DisableAll();
		}
		if(GetAsyncKeyState(VK_NUMPAD1)&1)
		{
			doWallhack();
		}
		if(GetAsyncKeyState(VK_NUMPAD2)&1)
		{
			doNametags();
		}
		if(GetAsyncKeyState(VK_NUMPAD3)&1)
		{
			doNoRecoil();
		}
		Sleep(1);
	}
}

BOOL __stdcall DllMain(HMODULE hinst, DWORD reason, void *useless)
{
	DisableThreadLibraryCalls(hinst);
	if(reason == 1)
	{
		CreateThread(0, 0, (LPTHREAD_START_ROUTINE)HackThread, 0, 0, 0);
	}
	return TRUE;
}
I've removed some parts of the code(patch util related) since the patching utility I used is not mine.
Happy copy pasting I guess
You know this is kind of really useless since the patch util related is the only thing i may actually have use off -.-
Quote Originally Posted by zeco View Post
You know this is kind of really useless since the patch util related is the only thing i may actually have use off -.-
It's not just for you...
Quote Originally Posted by LegendaryAbbo View Post
It's not just for you...
=) Are you sure about that? (joking)

Anyway, maybe you should just write a function to handle the virtual protect and memcpy, instead of having to write out 3 functions each time.

BY the way, what are the pro's of this method over write/readprocessmemory?
Quote Originally Posted by zeco View Post
=) Are you sure about that? (joking)

Anyway, maybe you should just write a function to handle the virtual protect and memcpy, instead of having to write out 3 functions each time.

BY the way, what are the pro's of this method over write/readprocessmemory?
Write and ReadProcessmemory need a window handle, this doesnt
And write and readprocessmemory are the first thing an anticheat would look for I guess.
Quote Originally Posted by Hell_Demon View Post
I've removed some parts of the code(patch util related) since the patching utility I used is not mine.
Happy copy pasting I guess
How does VirtualProtect and memcopy work? Well I'll look at this later when I don't have to study for a test.
Quote Originally Posted by why06 View Post
How does VirtualProtect and memcopy work? Well I'll look at this later when I don't have to study for a test.
VirtualProtect Function (Windows)
memcpy

VirtualProtect changes the protection(from whatever it is to read from & write to), stores the old protection in orig.
Then we memcpy our bytes over to the place we just unprotected
Then use virtualprotect again to restore the old acces rights in case some noob anticheat checks it.
I was bored last night after typing my message to you so i made a function to handle it more easily xD. Except there are some faults. Thanks for reminding, i'll go fix those now
Posts 1–8 of 8 · Page 1 of 1
This thread is closed for replies.

Similar Threads

Tags for this Thread

None

Talk with us