Go Back   FileForums > Games > Game Coders
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 18-04-2007, 19:43
pikachu5501 pikachu5501 is offline
Senior Member
 
Join Date: Oct 2006
Location: canada
Posts: 101
Thanks: 0
Thanked 1 Time in 1 Post
pikachu5501 is on a distinguished road
about finding adress for a debuger.

Ok, i don't need a step by step instruction, i just need a hint or a simple explanation. You are all so nice to answer so many questions already so i dont want to abuse either.

I use Cheat Engine to find the adress to nop and all but sometime, i dont want to nope but change the value instead. So i want to find out where i can find every time the value of the pointer.

That how i did it. First i searched and found the value at 0A1823C1.

i found: sub ecx, [edx+35]
edx = 01A8238C

01A8238C + 35 = 0A1823C1

so i looked in the memory dump (at the adress of the instruction) hoping to find something like 8C 23 A8 01 or C1 23 A8 01 somewhere so i can retreive it whithin my trainer and use it to change the value with it (like money or something else)

but there is only 2b 4a 34 (wierd)...

how i can find the code segment that store the adress value? pretty please with sugar and chocolat sprinkles on top..

thanx in advance.
Reply With Quote
Sponsored Links
  #2  
Old 19-04-2007, 04:40
DABhand DABhand is offline
Banned
 
Join Date: Nov 2004
Location: Near my PC
Posts: 5,406
Thanks: 0
Thanked 3 Times in 3 Posts
DABhand is on a distinguished road
You could use code injection.


Find a code cave, free space to have your own code, 10abf is always a good addy if you cant find one.

Then I would write this at the code cave


mov ecx , xxxxxx whatever value you want here in hex
jmp xxxxxxx (whatever addy you will jump from in the game)


And at the game coding, where the sub is


jump 10abf (and say yes to nop extra)

Any coding apart from the sub op code that is destroyed here will have to be replaced in your code cave. jumps take 5 bytes so bear that in mind.
Reply With Quote
  #3  
Old 19-04-2007, 12:34
pikachu5501 pikachu5501 is offline
Senior Member
 
Join Date: Oct 2006
Location: canada
Posts: 101
Thanks: 0
Thanked 1 Time in 1 Post
pikachu5501 is on a distinguished road
Thank you for you prompt reply . I will study this further. Now i know where to look.
Reply With Quote
  #4  
Old 19-04-2007, 14:50
TippeX's Avatar
TippeX TippeX is offline
zeroes and ones.....
 
Join Date: Jan 2003
Posts: 3,842
Thanks: 2
Thanked 33 Times in 23 Posts
TippeX is on a distinguished road
Quote:
Originally Posted by DABhand View Post
10abf is always a good addy if you cant find one.
hope thats baseless - otherwise its a heap area, and if the program hasn't initialised heaps then ur buggered....
wonder why people dont use virtualallocex and inject their code that way....
__________________
bleh
DO NOT PM me with questions, leave that in the forums...ESPECIALLY if i dont know you...
Reply With Quote
  #5  
Old 19-04-2007, 15:18
pikachu5501 pikachu5501 is offline
Senior Member
 
Join Date: Oct 2006
Location: canada
Posts: 101
Thanks: 0
Thanked 1 Time in 1 Post
pikachu5501 is on a distinguished road
Actualy, i saw something like that about code injecting in the CE tutorial but now i know what it does so i think i am ready to advance to that next level.

I found that learning to do trainer and all it is as fun (and frustrating sometime) as a game itself.

As usual, Thank for you priceless(the good way!) advices . I hope i will be able to give back anytime soon .
Reply With Quote
  #6  
Old 19-04-2007, 15:42
DABhand DABhand is offline
Banned
 
Join Date: Nov 2004
Location: Near my PC
Posts: 5,406
Thanks: 0
Thanked 3 Times in 3 Posts
DABhand is on a distinguished road
Quote:
Originally Posted by TippeX View Post
hope thats baseless - otherwise its a heap area, and if the program hasn't initialised heaps then ur buggered....
wonder why people dont use virtualallocex and inject their code that way....
Its a safe area, ive used it for many a trainer myself.
Reply With Quote
  #7  
Old 14-05-2007, 21:11
pikachu5501 pikachu5501 is offline
Senior Member
 
Join Date: Oct 2006
Location: canada
Posts: 101
Thanks: 0
Thanked 1 Time in 1 Post
pikachu5501 is on a distinguished road
I use 10abf myself now and allways filled with 0, i wonder if it was something from an old legacy thing from another windows version or something.
Reply With Quote
  #8  
Old 21-05-2007, 23:37
Synaesthesia Synaesthesia is offline
Registered User
 
Join Date: May 2007
Location: Incensed
Posts: 92
Thanks: 0
Thanked 0 Times in 0 Posts
Synaesthesia is on a distinguished road
Usually, first section of an .exe has tons of 00s at the end of it...
Reply With Quote
  #9  
Old 22-05-2007, 03:26
TippeX's Avatar
TippeX TippeX is offline
zeroes and ones.....
 
Join Date: Jan 2003
Posts: 3,842
Thanks: 2
Thanked 33 Times in 23 Posts
TippeX is on a distinguished road
that very much depends on the code size
the 00's come from file / section alignment
if the code is exactly the size of alignment,
you will find no zeroes.....
__________________
bleh
DO NOT PM me with questions, leave that in the forums...ESPECIALLY if i dont know you...
Reply With Quote
  #10  
Old 22-05-2007, 09:42
Synaesthesia Synaesthesia is offline
Registered User
 
Join Date: May 2007
Location: Incensed
Posts: 92
Thanks: 0
Thanked 0 Times in 0 Posts
Synaesthesia is on a distinguished road
Yeah, that's also true. Encountered that issue a lot in Delphi applications. Not to mention that if you open your app in Olly, you may see 00s at an address found at the end of the first section, but once you run the app, that memory gets written at And you're screwed. Gotta love Delphi...
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Help finding somebody to install Messiah dansanch PS2 Games 2 28-03-2002 08:01
HELP Finding a Modchip dansanch PS2 Games 2 26-03-2002 14:51
Wma & What are the best programs for finding mp3s adriannqld Media Files 4 25-07-2001 21:00
Need help finding a dc coder cable ChroNik007 DC Games 1 18-02-2001 19:16
CAN Anyone HELP with finding a Working exe for DEEP Raider??? d5guy PC Games 0 20-11-2000 09:16



All times are GMT -7. The time now is 05:17.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
FileForums @ https://fileforums.com