Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


How to know what writes to EAX ?

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking
View previous topic :: View next topic  
Author Message
tquery
How do I cheat?
Reputation: 0

Joined: 22 Jan 2013
Posts: 4

PostPosted: Tue Jan 22, 2013 6:54 am    Post subject: How to know what writes to EAX ? Reply with quote

I have an instruction
move [eax+8], edx

EAX = 2BE365E0 (it is the value)

I need to know, which instruction wrote this value to the EAX (from which registers/offsets etc...)

How to monitor EAX?

Thanks!
Back to top
View user's profile Send private message
Fresco
Grandmaster Cheater
Reputation: 4

Joined: 07 Nov 2010
Posts: 600

PostPosted: Sat Jan 26, 2013 7:25 am    Post subject: This post has 1 review(s) Reply with quote

go in the diassembler at the "move [eax+8], edx" instruction, (it's mov btw)
scroll up the code and find something that writes to it
like:
mov eax,whatever
or
inc eax
dec eax
...

_________________
... Fresco
Back to top
View user's profile Send private message
desertricker
Advanced Cheater
Reputation: 0

Joined: 20 Jan 2013
Posts: 55
Location: 127.0.0.1

PostPosted: Wed Feb 13, 2013 9:45 am    Post subject: Reply with quote

Fresco wrote:
go in the diassembler at the "move [eax+8], edx" instruction, (it's mov btw)
scroll up the code and find something that writes to it
like:
mov eax,whatever
or
inc eax
dec eax
...

This... really rustled my jimmies.This method won't work probably.The thing you have to do is to right click the opcode (in our case it's mov [eax+8],edx) and then choose break and trace instructions.It might not be easy because you have to analyze the codes.

_________________
Assembly var dediler geldik Very Happy
Back to top
View user's profile Send private message Visit poster's website
daspamer
Grandmaster Cheater Supreme
Reputation: 54

Joined: 13 Sep 2011
Posts: 1588

PostPosted: Wed Feb 13, 2013 9:57 am    Post subject: Reply with quote

What Frensco said is right and it works..
Search for something like
mov edx, something
add edx, something
sub edx, something
dec edx
inc edx

Then you can use auto assembler to set your own value to EDX.
Or you can do right click on that opcode > Find out what addesses this instruction accesses > do something that that will change edx (buy sell kill idk..) and then you will see the address and you will be able to change it..

_________________
I'm rusty and getting older, help me re-learn lua.
Back to top
View user's profile Send private message Visit poster's website
Fresco
Grandmaster Cheater
Reputation: 4

Joined: 07 Nov 2010
Posts: 600

PostPosted: Sun Feb 17, 2013 11:40 am    Post subject: Reply with quote

@azginporsuk
break and trace won't tell you what wrote to eax Wink
break and trace will only show you the values in stack, registers, etc...
what you could do is scroll up a few lines of code and then break and trace with stop condition at eip == (address of "move [eax+8], edx" instruction)
then in the tracer you would go at eip == (address of "move [eax+8], edx" instruction) and then scroll up line by line till you see eax register in red, which means something wrote to it.
and yes, only these kinda instruction change edx, as for eax, just chage edx with eax
Flashacking wrote:
[...]
mov edx, something
add edx, something
sub edx, something
dec edx
inc edx
[...]

_________________
... Fresco
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> General Gamehacking All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites