PWI - Guide for finding chat message offsets - C# code included

04/12/2012 19:06 Shopko#136
Quote:
Originally Posted by dumbfck View Post
I'll add some finishing touches and update the first post a bit later today... well the first post in the other thread ;)
Nice to see someone new here with the enthusiasm to really get stuck in and figure this stuff out ^_^
Oh yeah, lol. Wrong thread... I think I was almost cross-eyed by the time I came here to update the thread. And thanks, this stuff is fun. :)

Quote:
Originally Posted by dumbfck View Post
One thing I never got around to checking last time because I wasn't familiar with the technique... I'm hoping that this call can be somehow derived from one of the function pointers in the chatbox's vTable (not sure if that's even the correct term, but that's what I'm gonna call it lol) in a similar way that the setChatText is. E.g., the setChatText() address can simply be found at [[[chatBoxBase]+0]+0x44]
I don't think the sendChat() function is directly referenced in that table, but I suspect that there's something else there that calls it :D
Pretty likely, I agree. I think elementclient was written in C++ because I see a lot of references in their code to std::string (the "string" class from C++ Standard Template Library). That being the case, it makes sense that the chat box would have a vtable; it's probably a class. I never thought about looking for method pointers like that before (I'm a complete nab at reverse-engineering stuff lol) so that's an awesome tip. I can't wait to get home tonight and see what else is lurking there. :D

Quote:
Originally Posted by dumbfck View Post
Been finding lots of cool stuff in the client ever since I found out about those tables hehe.
Awesome. Major props for finding the objects and vtables in the first place! :handsdown:
04/12/2012 23:32 dumbfck#137
[Only registered and activated users can see links. Click Here To Register...] :D
04/15/2012 21:19 amineurin#138
wow such a lot info in the last days, time to update the treasure map thread :)
will do it tomorrow, thanks to you all !
11/18/2012 13:17 AHTOLLlKA#139
dumbfck, how u find this offsets? can u give some manual pls :handsdown:
Quote:
Originally Posted by dumbfck View Post
[[[[[[[[[BASE_CALL]+1C]+18]+8]+2BC]+208]+150]+ i*5D0 + B0]+0]
11/19/2012 01:10 dumbfck#140
Quote:
Originally Posted by AHTOLLlKA View Post
dumbfck, how u find this offsets? can u give some manual pls
I won't go into great detail because:
A) Most of the GUI stuff has been covered in a few of my other threads
B) There's some instruction on finding these offsets in this very thread (albeit some background info is required for those)
C) They're a bastard to find from scratch
D) It's late and I'm drunk :P

However,
I think I've documented elsewhere on these forums that the main GUI/Dialogue object list (i.e., windows) is located at:
[[[[[baseCall]+0x1C]+0x18]+0x08]+0xC4]
So, that will give you an ordered list of all available dialogues. This is a bit better than my old method which uses an unordered list of windows located at GuiBase1 as documented in my [Only registered and activated users can see links. Click Here To Register...] thread.

I've also documentred somewhere on here that there are two incredibly useful offsets for GUI related stuff at:
[[[[[baseCall]+0x1C]+0x18]+0x8]+0x244]
and
[[[[[baseCall]+0x1C]+0x18]+0x8]+0x248]
Load these up in CE and when you hover over a dialogue object (window) in game, they will show you the window you're hovering over (the 0x244 one) and the inner object of that window that you're hovering over (the 0x248 one).
These offsets have not changed in as many updates as I can remember!

So, armed with this information, load up those two offset lists in CE, go to an auction house and open the auction window.
Hover your mouse somewhere in the auction listings window and look at the value shown in CE for the 0x244 offset (the hoverOuterObject, or window offset)
Make a note of this address!
At this point, when I'm just adjusting an offset chain I've already found before, I like to use [Only registered and activated users can see links. Click Here To Register...].
The screenshot shows stuff in memory at:
[[[[[baseCall]+0x1C]+0x18]+0x08]+0xC4]

[Only registered and activated users can see links. Click Here To Register...]

As you can see, it's an uninterrupted list. It's a list of window base addresses.
I know from my [Only registered and activated users can see links. Click Here To Register...], that the gold listings were at:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0x3C0]+0x208]+0x168] + i*0x800] + 0x0]
So I know the rough area to start looking.
Now when we look in ReClass, we just scroll down a bit from 0x3C0 until we find the offset for the gold listings window which we made a note of a minute ago.

[Only registered and activated users can see links. Click Here To Register...]

It's now at 0x40C
So, the new method has an extra offset in the middle of the chain (0xC4) so our new offset chain for the AH gold listing window is at:
[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x40C]
Fortunately, after that, the rest of the chain is the same as before!
So, we now have:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x40C]+0x208]+0x168] + i*0x800] + 0x0]
Which is the address for the tab-delimited text description of each line in the AH gold listings.

We can now apply the same methodology to find all the other AH stuff.


Item AH page, tab delimited string for each item:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x3D8]+0x208]+0x168] + i*0x800] + 0x0]

Item AH page, item IDs:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x3D8]+0x208]+0x168] + i*0x800 + 0xB0]

Gold listings page, Sell list, tab delimited string for each item:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x40C]+0x208]+0x168] + i*0x800] + 0x0]

Gold listings page, Buy list, tab delimited string for each item:
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0xC4]+0x40C]+0x20C]+0x168] + i*0x800] + 0x0]


So much for not going into detail lol :P
11/19/2012 15:40 AHTOLLlKA#141
dumbfck, dude, thx!
i think my server have another offsets and i try to find it.
adress of window is 00A3D414 right ?
[Only registered and activated users can see links. Click Here To Register...]

but i cant find it in [[[[baseCall]+0x1C]+0x18]+0x8]
what i do wrong ?
11/19/2012 15:56 dumbfck#142
Hrm... your reclass window looks a bit different to mine - The notation seems different lol.
It's not A3D414 though, it's the value just before that. I think it's the N39ED2480 value, so drop the N. However, 39ED2480 just "seems" a rather high number. That's not to say it's necessarily wrong though.
I find it easier to use the hover offsets in CE. It's a bit clearer to read in there!

I was going to ask if you've used ReClass before and if you've set up your base address properly, but, from the screenshot, the inner hover object seems to be correctly indicating a Lst_Item gui object.
11/19/2012 16:41 AHTOLLlKA#143
BA is correct, but anyway cant find 39ED2480 in [[[[baseCall]+0x1C]+0x18]+0x8]
in CE i get 4bytes -160715704
[Only registered and activated users can see links. Click Here To Register...]
11/19/2012 17:04 dumbfck#144
If you convert that to hex, that's 0x99453B8 which looks much more likely to be correct!
11/19/2012 19:57 AHTOLLlKA#145
Quote:
Originally Posted by dumbfck View Post
If you convert that to hex, that's 0x99453B8 which looks much more likely to be correct!
yep) its work, now i find list!
now i get
[[[[[[[[baseCall]+0x1C]+0x18]+0x8]+0x3C0]+0x208]+0x??] + i*0x???] + 0x0]
how find next offset? ur offset is 0x168, and i try many offsets after x208 but they wrong((



[Only registered and activated users can see links. Click Here To Register...]

UPD
wow i find all what i need o_O
thx dumbfck!

i try send packet to refresh AH list ... done
but i can get any information only when click at this list (set focus at listbox)
how i can get data without focus ??
11/20/2012 02:11 dumbfck#146
Do you mean the detailed item description, i.e., the popup box with information that you see when you hover over an item?
I can't remember if that information is already there or if it has to be fetched by injecting a function to update the description (this is how it works for items in inventory / shops / etc).
It's been a long time since I really played with all this stuff and It's a bit late at night for me to be delving into that now lol.
If there's something in the list that links directly to an item object, then most likely the update description function will be at:
[[[itemBase]+0]+0x40]
Once that's called, the actual item description would probably be at:
[[[itemBase]+0x40]

But again, this is just a guess lol, as that's how it works elsewhere in game.
11/20/2012 03:51 Murmuring#147
If you mean the Item Text of a Auction Hall Item, then a very wise Men showed me this Way for the PWI Descent Days:

The Full Line of Auction like Name, Price, Time...
Quote:
ItemString = baseCall+0x1C+0x18+0x8+0x2D8+0x208+0x168+ I*0x800 + 0x00+0x0, wchar[CharMax]
Description if you Hover Mouse over a Auction Hall Item:
Quote:
ItemText = baseCall+0x1C+0x18+0x8+0x2D8+0x208+0x168+ I*0x800 + 0x5C+0x0, wchar[CharMax]
11/20/2012 09:45 AHTOLLlKA#148
no, when i press REFRESH button in AH window i dont get any information
[Only registered and activated users can see links. Click Here To Register...]

but when i click at any line in listbox i get information
[Only registered and activated users can see links. Click Here To Register...]

UPD
my bad(( find wrong offsets, now its ok :D
but structure is different((
[Only registered and activated users can see links. Click Here To Register...]
800 dont have adress
11/20/2012 10:27 dumbfck#149
Bear in mind that after hitting the refresh button or sending a refresh packet, it takes a finite amount of time for the server to return the information to your client, then for the client to process that information and load it into the list and display it on your screen.
I think the way I used to check for the wait time was to keep checking if the ID of the last line (line 15, if starting at 0) had been loaded yet and was different from the last time I refreshed the page (because if you've already loaded the page before, that last line will already contain something. However, you probably don't want to bother re-reading the information if there is nothing new, so checking the auction ID number of the last line is a pretty good method).
You might run into trouble though when you reach the last page, or if you've applied filters, thus meaning there may be less than 16 items displayed!
I expect there's probably a variable somewhere though that contains the count for how many items are listed on the page. Either that or there might be a default value in one of the fields that means the row is empty. After all, the client itself needs to keep track of how many items are in the list for various purposes.

For very basic testing purposes though, just put a 1-2 second delay after sending the refresh packet before reading the list.

Or perhaps I've completely misinterpreted your question? :P
11/20/2012 11:46 AHTOLLlKA#150
yeah)) i know that ^^
i mean, i think i have wrong structure here > [Only registered and activated users can see links. Click Here To Register...]