| View previous topic :: View next topic |
| Author |
Message |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Sun Jun 10, 2007 11:08 pm Post subject: Newb need some help |
|
|
Here it goes. I have this address from this game. It's a bool(Prevent you from talking). Just like the one in maplestory you can't talk to fast.
0=You can talk
1=You can't
Now I freeze this address at 0(noob way).
Sometimes the address changes when the game restart.
Any tips on how to find the orginal address and how to keep the value at 0?
The opt for that address was this:
004da411 - c7 83 6c 17 00 00 01 00 00 00 - mov [ebx+0000176c],00000001
Turned back to 0
004da411 - c7 83 6c 17 00 00 00 00 00 00 - mov [ebx+0000176c],00000000
Any tips or tutorial on how to write a simple script to keep that at 0?
Thanks in advance.
|
|
| Back to top |
|
 |
Labyrnth Moderator
Reputation: 10
Joined: 28 Nov 2006 Posts: 6301
|
Posted: Mon Jun 11, 2007 5:07 am Post subject: |
|
|
The pointer may help, but your saying this address changes?
4da411
Show screenshot or post a couple it has changed too.
Post the name of the game as well.
The more information you post the better off any one is trying to help.
|
|
| Back to top |
|
 |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Mon Jun 11, 2007 8:38 am Post subject: |
|
|
Thanks for the replys.
This game is a Chinese music game call R2Beat(don't know if that helps).
When the red msg shows up, it prevents you from speaking(you still can type but when you hit enter nothing shows up). And after a while, it unfreezes again. Even i freeze that address at 0 i can't keep spamming. Maybe i should find out what cause the red msg show up.
| Description: |
|
| Filesize: |
251.03 KB |
| Viewed: |
6177 Time(s) |

|
|
|
| Back to top |
|
 |
Labyrnth Moderator
Reputation: 10
Joined: 28 Nov 2006 Posts: 6301
|
Posted: Mon Jun 11, 2007 1:51 pm Post subject: |
|
|
Well i see the address is not changed,
So you need find the pointer. Those instructions are triggered by something.
Sort of like a compare, If blah blah then 0, If blah blah then 1
|
|
| Back to top |
|
 |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Mon Jun 11, 2007 5:02 pm Post subject: |
|
|
| Labyrnth wrote: | Well i see the address is not changed,
So you need find the pointer. Those instructions are triggered by something.
Sort of like a compare, If blah blah then 0, If blah blah then 1 |
Any idea how to do that?
I tried to find the pointer but 3 addresses came up.
|
|
| Back to top |
|
 |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Mon Jun 11, 2007 6:24 pm Post subject: |
|
|
Well Thanks to everyone now I found the pointer.
But i have to keep freezing and unfreezing if i want to spam.
Any idea or tips on writing an AA script to do this?
Or is there some other way?
Thanks in advance.
|
|
| Back to top |
|
 |
Labyrnth Moderator
Reputation: 10
Joined: 28 Nov 2006 Posts: 6301
|
Posted: Mon Jun 11, 2007 6:50 pm Post subject: |
|
|
You should be able to do an AA for it.
Or just use nops,
|
|
| Back to top |
|
 |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Tue Jun 12, 2007 6:58 pm Post subject: |
|
|
I am new to AA, any idea why this can't be assign to CT?
| Code: |
[Enable]
alloc(newopcode,1024)
alloc(oldopcode,1024)
0049630A:
jmp newopcode
mov [ebp+00000080],ecx
newopcode:
push edx
mov edx, 3B9AC9FF
pop edx
oldopcode:
add ecx,edx
[Disable]
0049630A:
jmp oldopcode
mov [ebp+00000080],ecx
dealloc(newopcode)
dealloc(oldopcode)
|
|
|
| Back to top |
|
 |
Uzeil Moderator
Reputation: 6
Joined: 21 Oct 2006 Posts: 2411
|
Posted: Tue Jun 12, 2007 9:23 pm Post subject: |
|
|
Well it isn't going to work out very well since you don't jump back in newopcode or oldopcode, and I have this feeling that the bytes may be incorrect but hopefully DB thought about that since this looks like a preset.
_________________
|
|
| Back to top |
|
 |
GreenBeret Advanced Cheater
Reputation: 0
Joined: 03 Oct 2006 Posts: 82 Location: Canada
|
Posted: Tue Jun 12, 2007 9:37 pm Post subject: |
|
|
| Uzeil wrote: | | Well it isn't going to work out very well since you don't jump back in newopcode or oldopcode, and I have this feeling that the bytes may be incorrect but hopefully DB thought about that since this looks like a preset. |
Any hints or tips on how to fix this?
I couldn't find any good AA tutorial, all they tell was the command, didn't tell how it actually worked and what to be aware.
|
|
| Back to top |
|
 |
Uzeil Moderator
Reputation: 6
Joined: 21 Oct 2006 Posts: 2411
|
Posted: Tue Jun 12, 2007 9:42 pm Post subject: |
|
|
Look at some scripts in the MapleStory stickies. A lot of them have these assembly hooks, and, hoping you learn by example, it's a great place to learn.
_________________
|
|
| Back to top |
|
 |
|