[Help]Attack Call

03/03/2008 22:36 anthorng#1
0066CAEF CC int3
0066CAF0 . 83EC 08 sub esp, 8
0066CAF3 . 8B0D 70208400 mov ecx, dword ptr [842070]
0066CAF9 . 83CA FF or edx, FFFFFFFF
0066CAFC . 52 push edx
0066CAFD . 6A 00 push 0
0066CAFF . 8BC1 mov eax, ecx
0066CB01 . E8 AD0EE1FF call 0047D9B3
0066CB06 . 50 push eax
0066CB07 . 52 push edx
0066CB08 . 52 push edx
0066CB09 . 52 push edx
0066CB0A . 8BC1 mov eax, ecx
0066CB0C . E8 9B0EE1FF call 0047D9AC
0066CB11 . 50 push eax //Monster ID ; |Arg2
0066CB12 . 52 push edx //FFFFFFFF ; |Arg1
0066CB13 . 8BC2 mov eax, edx ; |
0066CB15 . B9 30C1C200 mov ecx, 00C2C130 ; |
0066CB1A . E8 EE03E7FF call 004DCF0D ; \NA-Cabal.004DCF0D
0066CB1F . 6A 00 push 0 ; /Arg4 = 00000000
0066CB21 . 8D4424 04 lea eax, dword ptr [esp+4] ; |
0066CB25 . 50 push eax ; |Arg3
0066CB26 . 8D4C24 0C lea ecx, dword ptr [esp+C] ; |
0066CB2A . 51 push ecx ; |Arg2
0066CB2B . 68 A0FFC500 push 00C5FFA0 ; |Arg1 = 00C5FFA0 ASCII "?~"
0066CB30 . 8BC2 mov eax, edx ; |
0066CB32 . 895424 14 mov dword ptr [esp+14], edx ; |
0066CB36 . 895424 10 mov dword ptr [esp+10], edx ; |
0066CB3A . E8 E14CFFFF call 00661820 ; \NA-Cabal.00661820
0066CB3F . 85C0 test eax, eax
0066CB41 . 74 1F je short 0066CB62
0066CB43 . 8B15 B8D78300 mov edx, dword ptr [83D7B8]
0066CB49 . 52 push edx ; /Arg1 => 11A67AC8 ASCII "鹂}"
0066CB4A . E8 0186EFFF call 00565150 ; \NA-Cabal.00565150
0066CB4F . 85C0 test eax, eax
0066CB51 . 74 15 je short 0066CB68
0066CB53 . A1 70208400 mov eax, dword ptr [842070]
0066CB58 . C780 7C340000>mov dword ptr [eax+347C], 1
0066CB62 > 33C0 xor eax, eax
0066CB64 . 83C4 08 add esp, 8
0066CB67 . C3 retn
0066CB68 > 6A 01 push 1
0066CB6A . 6A 53 push 53
0066CB6C . E8 5FF5FFFF call 0066C0D0
0066CB71 . B8 01000000 mov eax, 1 //here start
0066CB76 . 83C4 08 add esp, 8
0066CB79 . C3 retn


This Is My first time to make Korean Games Bot..
btw i can't find the attack call..does any one can help me?i guess it is here..
any pro can give some tips?
03/04/2008 20:56 faceofdevil#2
0066CB68 > 6A 01 push 1
try changing the push value see what happens trail and error instead of someone just ginving you the answer... Open a uCE add the address change the value see what happends... from the looks of it one of the push's is what your looking for... Without no dump or tracing would be my guess...