Guide GHB1 - Start Here Beginner Guide to Game Hacking

Hexui Undetected CSGO Cheats Sinkicheat PUBG Cheat

_Kalu_

Dank Tier Donator
Full Member
Apr 18, 2020
4
322
0
I'm trying to reverse some csgo functions with ida, just to practice, but i encounter a lot of problem.
I've alredy reversed a lot from AC, now i wanna move to csgo that seems a bit more hard.

Before you blame me for shitposting, I've already searched for tutorial about this on the forum and on the net, but I can't find anything that helped me understand it.

The first thing i do is finding address of ammo, after this i find out what writes to it.
Then i get the address of the function ( select current function -> copy address ), and i get this:
client.dll+4F7600 ( or 27C17600)

I normally then open IDA, import 'client.dll', and go to the address found.
The problem is IDA answer with a 'JumpAsk failed', i think because the address is not within the dll.
I tried also with DllEntryPoint + 4F7600, and also only 4F7600 . But i can't get to the function either.

What am i doing wrong? how do i find the function that decrement my ammo in IDA?
This function will be gold because i can start reversing the 'shoot' function and maybe the 'traceline' function but if i have not a function to start with like i did in AC, I can't reverse anything...
 

Kekz

Maybe Pasting
Dank Tier Donator
Nobleman
Jan 10, 2020
135
3,668
12
The problem is IDA answer with a 'JumpAsk failed', i think because the address is not within the dll.
I tried also with DllEntryPoint + 4F7600, and also only 4F7600 . But i can't get to the function either.
Just 4F7600 should work, since you're already in client.dll. If I open the dll in IDA I can jump to that address no problem, it's inside the function sub_4F75D0.
If you're having trouble using IDA I recommend doing the IDA tutorials Guide - IDA Pro Beginner Guide
and take a look at some CS:GO reversing tutorials: Guide - Beginners Guide To Reverse Engineering Tutorial
Maybe you messed up some settings...?
 

_Kalu_

Dank Tier Donator
Full Member
Apr 18, 2020
4
322
0
Just 4F7600 should work, since you're already in client.dll. If I open the dll in IDA I can jump to that address no problem, it's inside the function sub_4F75D0.
If you're having trouble using IDA I recommend doing the IDA tutorials Guide - IDA Pro Beginner Guide
and take a look at some CS:GO reversing tutorials: Guide - Beginners Guide To Reverse Engineering Tutorial
Maybe you messed up some settings...?
Tutorials already all done. Maybe you missed the part where i've said it, but i've reversed a lot from AC and now wanna move to something harder.

Here it is the situation with just 4F7600:
test.gif

I haven't changed any settings at all, with AC (ac_client.exe) it was working great. I tried to delete the database and reopen the dll. Nothing changed.

p.s. already tryed waiting to the end of the auto analisys, nothing.
Tryed also in ghidra 9, getting 'no result for 4F7600', so not a problem of ida
 
Last edited:

Rake

Cesspool Admin
Administrator
Jan 21, 2014
12,061
78,998
2,370
@_Kalu_
DllEntryPoint + 4F7600

entrypoint and image base address are not the same thing

re-base the DLL, then go to 4F7600

if you don't know what this means, watch all my videos that include IDA pro
 
  • Like
Reactions: _Kalu_ and Kekz

Splose

Dank Tier Donator
May 4, 2020
4
218
0
This guide is amazing.

I have tried to learn about memory addresses, offsets, and even tried to learn C++ but at the time I didn't apply it to anything that interested me. With this guide I was able to start learning about this stuff by applying it to a game I love ... Counter Strike.

Thank you so much Rake and all the others who contributed to this.
 
  • Like
Reactions: Rake

catalinqs

Dank Tier Donator
Nobleman
Aug 2, 2019
63
553
2
well i'm going to read all the 4 books again, i was willing to jump straight into the last one cuz i got the hang of what this is all about , i don't have problems anymore with entity lists, i use reclass to find lots of stuff but since yesterday i had that problem im going to read all of them again
1598591322387.png
 
  • Like
Reactions: Rake
Community Mods