• Amused
  • Angry
  • Annoyed
  • Awesome
  • Bemused
  • Cocky
  • Cool
  • Crazy
  • Crying
  • Down
  • Drunk
  • Embarrased
  • Enraged
  • Friendly
  • Geeky
  • Godly
  • Happy
  • Hateful
  • Hungry
  • Innocent
  • Meh
  • Piratey
  • Poorly
  • Sad
  • Secret
  • Shy
  • Sneaky
  • Tired
  • Wtf
  • At Work
  • CodenzHub
  • Coding
  • Deejaying
  • Donating
  • Drinking
  • Eating
  • Editing
  • Hacking
  • Hate Mailing
  • Jamin'
  • Lagging
  • Live Streaming
  • Lurking
  • No Status
  • Pawning
  • PC Gaming
  • PS Gaming
  • Raging
  • Reversing
  • Sleeping
  • Steam Gaming
  • Trolling
  • TwitchStreamer
  • Vodka!
  • Watching TV/Movie
  • Xbox Gaming
  • Youtuber
  • Zombies
  • Page 1 of 2 12 LastLast
    Results 1 to 10 of 12

    Thread: Pattern Scan

    1. #1
      Jr.Coder
      <3 D3D
       
      Coding
       
      gnuzim's Avatar
      Join Date
      Nov 2012
      Posts
      67
      Thanks (-->)
      43
      Thanks (<--)
      28

      Pattern Scan

      Silent VPN
      Heys guys, problems again!
      Click image for larger version. 

Name:	module.jpg 
Views:	20 
Size:	422.2 KB 
ID:	2417

      I'm trying to make a simple Health hack for this game, address always changes, i'm doing patternscan method.. but can't seem to find the right module ...

      DWORD healthAddy = FindPattern("Magicka.exe", "\x89\x0A\x8B\x76\x14\xFF\x0E", "xxxxxxx");
      And crashes!

      Any advice?

    2. #2
      The Angel Of Verdun
      Always More To Code!
       
      Lurking
       
      Nether's Avatar
      Join Date
      Dec 2013
      Location
      England, SW
      Posts
      299
      Thanks (-->)
      54
      Thanks (<--)
      188
      you can view what module an address is in via cheat engine memory viewer, right click your address and browse this memory region:
      It will show you (Process.exe |Client.dll | Some.dll) etc

      Pattern Scan
      Last edited by Nether; 01-27-2014 at 11:29 PM.
      No Need For Anything Extravagant, Your Blood As A Present Shall Suffice.

    3. Thanks gnuzim thanked for this post
    4. #3
      Jr.Coder
      <3 D3D
       
      Coding
       
      gnuzim's Avatar
      Join Date
      Nov 2012
      Posts
      67
      Thanks (-->)
      43
      Thanks (<--)
      28
      Thats what i did, i've attached one image, doesn't show any module before addresses, yes, there is a module name after addresses, but when i use it i get crash!
      And i'm pretty sure my signature scan is right!

    5. #4
      Jr.Hacker
      Haze-Productions
       
      Coding
       
      rN''s Avatar
      Join Date
      Jan 2014
      Posts
      340
      Thanks (-->)
      20
      Thanks (<--)
      126
      Quote Originally Posted by gnuzim View Post
      Thats what i did, i've attached one image, doesn't show any module before addresses, yes, there is a module name after addresses, but when i use it i get crash!
      And i'm pretty sure my signature scan is right!
      Upload the picture to imgur.com or an other site like this..

    6. #5
      The Angel Of Verdun
      Always More To Code!
       
      Lurking
       
      Nether's Avatar
      Join Date
      Dec 2013
      Location
      England, SW
      Posts
      299
      Thanks (-->)
      54
      Thanks (<--)
      188
      Quote Originally Posted by gnuzim View Post
      Thats what i did, i've attached one image, doesn't show any module before addresses, yes, there is a module name after addresses, but when i use it i get crash!
      And i'm pretty sure my signature scan is right!
      would be easier if you can upload to imageshack instead of an attachment as i cant see it yet not aprooved.

      if it doesnt say any module maybe its loaded before the first module kinda of like an initializer in C++ before main, if not find it several times and it should be in a region like 02000000 to 02FFFFFFFF or something and then you can get your range.
      this is highly NOT Recomended but you could just start scan from 0000000000 to FFFFFFFFFFF but this will more than likley cause a crash or a high rate of detection.

      if its loaded before process.exe you can just start search at 0000000 and end at the address of process.exe
      No Need For Anything Extravagant, Your Blood As A Present Shall Suffice.

    7. #6
      Jr.Coder
      <3 D3D
       
      Coding
       
      gnuzim's Avatar
      Join Date
      Nov 2012
      Posts
      67
      Thanks (-->)
      43
      Thanks (<--)
      28
      Sorry, i thought you guys could see it!
      https://w3devz.com.br/img/module.jpg
      Image link

      I did some pointer scanning, i got a few things, steam.dll and other things!
      I think this game does not have any anti-cheat! There's no worries about detection at this point!
      Attached Thumbnails Attached Thumbnails module.jpg  
      Last edited by gnuzim; 01-28-2014 at 12:20 AM.

    8. #7
      The Angel Of Verdun
      Always More To Code!
       
      Lurking
       
      Nether's Avatar
      Join Date
      Dec 2013
      Location
      England, SW
      Posts
      299
      Thanks (-->)
      54
      Thanks (<--)
      188
      Quote Originally Posted by gnuzim View Post
      Sorry, i thought you guys could see it!
      https://w3devz.com.br/img/module.jpg
      Image link

      I did some pointer scanning, i got a few things, steam.dll and other things!
      I think this game does not have any anti-cheat! There's no worries about detection at this point!
      :P well if you could get a pointer to it, that would be better, try use ollydbg/IDA and find an offset to it, else if its not loaded in a module only thing i can think of is find its general memory region and scan that area, as i said not recomended due to crash/detection but scan all of code but that will most likley not work. best try find a pointer.
      No Need For Anything Extravagant, Your Blood As A Present Shall Suffice.

    9. Thanks gnuzim thanked for this post
    10. #8
      Jr.Coder
      <3 D3D
       
      Coding
       
      gnuzim's Avatar
      Join Date
      Nov 2012
      Posts
      67
      Thanks (-->)
      43
      Thanks (<--)
      28
      I will try to get the right pointer then, the problem is, i'm not doing a address & offset based hack, if i get the pointer i still can use signature scan right?

    11. #9
      The Angel Of Verdun
      Always More To Code!
       
      Lurking
       
      Nether's Avatar
      Join Date
      Dec 2013
      Location
      England, SW
      Posts
      299
      Thanks (-->)
      54
      Thanks (<--)
      188
      Quote Originally Posted by gnuzim View Post
      I will try to get the right pointer then, the problem is, i'm not doing a address & offset based hack, if i get the pointer i still can use signature scan right?
      well once you have a pointer there would be no need but sure you could, get the pointer address and scan from there
      No Need For Anything Extravagant, Your Blood As A Present Shall Suffice.

    12. Thanks gnuzim thanked for this post
    13. #10
      Jr.Coder
      <3 D3D
       
      Coding
       
      gnuzim's Avatar
      Join Date
      Nov 2012
      Posts
      67
      Thanks (-->)
      43
      Thanks (<--)
      28
      Silent VPN
      Ok, the only reason i'm doing this by signature scans is that i'm studying it right now!
      I'm changing every hack that i've made with address and offsets to sig/scans, just for fun!

      Thank you very much for this advice

    Page 1 of 2 12 LastLast

    Similar Game Hacker Threads

    1. [Source Code] Pattern Scanning
      By Solaire in forum Tutorials and Snippets
      Replies: 18
      Last Post: 07-11-2016, 09:23 PM
    2. [VideoTutorial] C++ Signature Scan / Pattern Scanning Tutorial DIFFICULTY[3/10]
      By Fleep in forum GH Hack Video Tutorials
      Replies: 41
      Last Post: 06-14-2016, 09:25 PM
    3. [Help] Pattern Scan -> Get Value
      By Clarityworld in forum Hacking Help
      Replies: 10
      Last Post: 12-14-2015, 05:08 PM
    4. Replies: 13
      Last Post: 11-14-2014, 09:38 AM