Heya all as you are now awear alt1 has patched the attack speed hack.
This is how I have worked arround it. Please Alt1 Patch it SERVER SIDE for once.
First I found the attack speed buff as one usally does. Had help from Iktov on that one.
Then we noticed it had a limiter.
Here is how to bypass it.
Find what code accesses the attack speed buff:
This is the code address that copy's the attack speed modifyer buff
00430A00
Stepping out of the function it had two things calling it I found the mele hit one.
Code:
0048EA5E |. 52 PUSH EDX
0048EA5F |. B9 845A5F00 MOV ECX,TwelveSk.005F5A84
0048EA64 |. E8 971FFAFF CALL TwelveSk.00430A00
There is also this one for other kinds of attacks
Code:
0048F3BE |. 52 PUSH EDX ; /Arg1
0048F3BF |. B9 845A5F00 MOV ECX,TwelveSk.005F5A84 ; |
0048F3C4 |. E8 3716FAFF CALL TwelveSk.00430A00 ; \TwelveSk.00430A00
Scrolling down we see a JPE
For Mele one
Code:
0048F3EA |. /7A 1E JPE SHORT TwelveSk.0048F40A
For Skills one
Code:
0048F3EA |. /7A 1E JPE SHORT TwelveSk.0048F40A
Look for code that could jump or something:
Tests god knows what against 5 im not too sure how TEST operator works all I know is that the jump is not taken when not speed hacking but is taken when speed hacking above 20 soooo.
Code:
0048EA87 |. F6C4 05 TEST AH,5
0048EA8A |. 7A 1E JPE SHORT TwelveSk.0048EAAA
Solution:
Lets force it to not be taken by changing it to a nop.
Mele Hit
Code:
Origionaly
0048EA8A |. 7A 1E JPE SHORT TwelveSk.0048EAAA
Change to
0048EA8A 90 NOP
0048EA8B 90 NOP
Skills Hit
Code:
Origionaly
0048F3EA |. /7A 1E JPE SHORT TwelveSk.0048F40A
Change to
0048F3EA 90 NOP
0048F3EB 90 NOP
And success.. we can now freeze attack speed buff address which is
10D0EEB
To anything we want.
To apply this alter the code.
You should be able to add
0048EA8A and 0048F3EA as byte arrays with length of 2 and set both byte's in them to 90 90
in cheat engine or do it in memory view w/e
I win,