Yo whatz up,
just a small release / open source / tutorial because i have found time in my break [ @someone ]
so we can start now
- Newbie's are wrong here <- Important
- It's really ugly coded and i give a fuck on people who have problems with it
So if you don't understand this ^ STOP READ
The Next Code is only for Reverse the Bytes ^-^
Now come an Important Part of the source
before u write it ..it looks like this
fld dword ptr [ebp-04]
mov esp,ebp
<- this are 5 bytes << D9 45 FC 8B E5
after this code it looks like this
jmp ???????? <- ???????? because it change at every start ( the reason why we calc )
E9 ?? ?? ?? ?? <- the Bytes now
"mov eax,[$MyHP]" Copy in the register eax the value of our own page ( the second ( $MyHP ))
89 45 FC - mov [ebp-04],eax
now we copy eax into [ebp-04] because we load it later
D9 45 FC - fld dword ptr [ebp-04]
8B E5 - mov esp,ebp
^the orginal code that we overwrite with our own jmp
E9 ???????? - jmp Back
^here we jmp back
We write the second parameter into our own page ( $MyHP )
This Part you must understand now without help
Functions
NomadMemory.au3
To Running the *.exe File
or
just a small release / open source / tutorial because i have found time in my break [ @someone ]
so we can start now
- Newbie's are wrong here <- Important
- It's really ugly coded and i give a fuck on people who have problems with it
Code:
Dim $byte[5];declare array $byte If Not $cmdline[0] = 2 Then ; if not $cmdline[0] ( size of called Parameter ) = 2 MsgBox(0, "Error", "Wrong Parameter") ; calling MessageBox Function ( User32.dll ) Exit ; Close the Programm EndIf ; end of If
Code:
SetPrivilege(0x0020, 0x0002); the name say all ( set privilege )
$process = _MemoryOpen(ProcessExists("S4Client.exe")) ; OpenProcessMemory from S4Client.exe
$page = _AllocMem(ProcessExists("S4Client.exe"), 2048) ; create a Writeable Page in S4Client.exe and return the address from the start of the page.
$MyHP = _AllocMem(ProcessExists("S4Client.exe"), 2048); create a Writeable Page in S4Client.exe and return the address from the start of the page.
Code:
$hex = Hex($MyHP, 8) $byte[0] = 4 $step = 1 For $i = 1 To 8 $byte[$step] = StringRight($hex, 2) $i += 1 $hex = StringLeft($hex, 8 - $i) $step += 1 Next
before u write it ..it looks like this
fld dword ptr [ebp-04]
mov esp,ebp
<- this are 5 bytes << D9 45 FC 8B E5
Code:
_MemoryWrite(0x00535F64, $process, "0xE9" & Byte_Reverse(Calc($page + 1, 0x00535F65)), "byte[5]") ; Write an Jmp from the orginal to the new page and calc the bytes for the page
after this code it looks like this
jmp ???????? <- ???????? because it change at every start ( the reason why we calc )
E9 ?? ?? ?? ?? <- the Bytes now
Code:
_MemoryWrite($page, $process, "0xA1" & $byte[1] & $byte[2] & $byte[3] & $byte[4], "byte[5]") ; Write in our own Page "mov eax,[$MyHP]"
Code:
_MemoryWrite($page + 0x5, $process, "0x8945FCD945FC8BE5E9" & Byte_Reverse(Calc($page + 0xD, 0x00535F69, 1)), "byte[13]")
now we copy eax into [ebp-04] because we load it later
D9 45 FC - fld dword ptr [ebp-04]
8B E5 - mov esp,ebp
^the orginal code that we overwrite with our own jmp
E9 ???????? - jmp Back
^here we jmp back
Code:
_MemoryWrite($MyHP, $process, $cmdline[2], "float")
This Part you must understand now without help
Code:
If $cmdline[1] = "1" Then _MemoryWrite(0x00535F04, $process, "0xE9" & Byte_Reverse(Calc($page + 1, 0x00535F65)), "byte[5]") Else _MemoryWrite(0x00535F04, $process, "0xD945FC8BE5", "Byte[5]") EndIf
NomadMemory.au3
To Running the *.exe File
Code:
#RequireAdmin ShellExecute(@ScriptDir & "\[S4L] HP Changer.exe","0 200");200 HP
Code:
#RequireAdmin ShellExecute(@ScriptDir & "\[S4L] HP Changer.exe","1 1337");1337 HP and Godmode