how do i include move to position and warp on my clua with the your codes on the first page? tnx.
You will have to get the CLua source, get the game.bin from the katar update ( offset reference ), add and register the functions to the lua table, compile the source and set the Macro.lua to your needs. If you are not used to work with MSVC you can wait for the new CLua compilation, i am waiting for the next official game update to entirely patch CLua so i can try to update the old and newer codes.
Very nice Alain but i still think you are making your life very hard by not being in the process context, if you are using C/C++ why not perform a DLL injection?
Quote:
Originally Posted by ntKid
check if eax is valid to read before reading it, you may be trying to read something that it is still not created or being deleted, "IsBadReadPtr" eax before assuming it is a valid pointer. imagine if the eax = 0 and you do mov eax, [ eax ] it will try to read a invalid memory region.
If you are concerned about multithread you can detour the functions that you are going to call and add a critical section
INT ( WINAPI *pDetoured )( );
INT WINAPI myDetoured( )
{
INT dwRes = NULL;
EnterCriticalSection( &cs );
dwRes = pDetoured( );
LeaveCriticalSection( &cs );
return dwRes;
}
cheers.
Yeah I've switched from asm code to C code to make a ThreadSafeReadAddress function reading adresses safely. In another hand what I got in the crash I described was not a null address but an invalid address (either fucked addr or simply not commited addr) :'(. Can't do anything for this I suppose...
I'll try the EnterCriticalSection( &cs ); solution with detouring calls too. Seems a bit safer than calling game function like I did until now (additionnaly to my random crashes I got some crazy rendering bugs too like sort of thermic vision oO).
I tried today to detour dinput8's GetDeviceState() to be able to fake key presses and I'm completely shoked to see that the keyboard buffer returned
by each frame call from the game is always set to 0... How the hell do they treat their inputs ?!
I tried today to detour dinput8's GetDeviceState() to be able to fake key presses and I'm completely shoked to see that the keyboard buffer returned
by each frame call from the game is always set to 0... How the hell do they treat their inputs ?!
I tried this code on another game using dinput8 and it works perfectly...
They are using GetDeviceData to handle the keyboard not GetDeviceState. I think the send skill is responsible for your glitch, maybe we have to find the raw call for it inside the SendSkill function ( i mean the actual skill function does more things than what we want it to do, we need to find the right raw call inside it ).
Ok... Let's hook the GetDeviceData too ^^. About the glitch, yes. That's why I try to make the calls thread safe before trying any other raw game call. I traced the whole function above the one sending the skill in order to understand what drives the send.
I reached this part of the code :
Code:
/* if the jump occurs you skip the send of the skill
0088B10B mov edx,eax
0088B10D and edx,7
0088B110 mov cl,dl
0088B112 shr bl,cl
0088B114 test bl,1
0088B117 je 0088B1E7
*/
But I have no clue about what this test is really...
edit : Argh this stupid double post automerge again...
Failed to hook GetDeviceData()... Can't understand what happens here. Before I hook anything the normal call of GetDeviceData() is always performed with specific device through a specific callstack. But at the exact moment I hook the function, an unexpected call to my newly hooked function is performed through this crazy callstack with an unexpected unkown device and the game, (not my hooked function currently doing nothing else than recalling the original function), simply crash because it doesn't handle this case (unknown device return).
The unexpected callstack just right before calling GetDeviceData()
Honestly these hook failures start to make me really sick... I just simply don't understand wtf happens. I feel like loosing my few free time for... nothing exept headaches -_-.
temp = pGetDeviceData(lpDevice, cbObjectData, rgdod, pdwInOut, dwFlags); // original code
// if (temp == DI_OK)
// {
// for(DWORD i = 0; i < *pdwInOut; ++i)
// {
// if (rgdod[i].dwData & 0x80) // only key-down events are reported
// {
// add_log("Key 0x%X %s", rgdod[i].dwOfs, (rgdod[i].dwData & 0x80) ? "pressed" : "released");
// }
// }
// }
return temp;
}
[/code]
Honestly these hook failures start to make me really sick... I just simply don't understand wtf happens. I feel like loosing my few free time for... nothing exept headaches -_-.
DInput8 module memory page is cloned at device spawn part of the code is executed on the clone image and other part of it is for memcmp( kind of a anti cheat check ).
I think you should focus your energy into fixing the SendSkill function because even if you make the DInput8 Hook work you wont be able to multiclient bot.
Quote:
Originally Posted by pureleech
ntKid can u help me make it work to private server pleaese?
In theory CLua or the codes should work on the private server, since the client is the same.. You can try and ask Thr!ce to make the AFKLoader log into the private server instead of the official one.
Actually I just got the render glitch with read only functions + the setNearestTarget call. So I assume that the setNearestTarget can also lead to crash exactly as the sendSkill does. I'll try to detour it and add critical section.
@Omdihar, I only have the french client ones, but you can easily find the offset by using the code search in CE and looking for this unique opcode :
Code:
push eax
push eax
mov eax, [ esi + 0x00000008 ]
shr eax, 0x0C
and eax, 0x0000FFFF
push eax
mov ecx, edi
edit : lol too late...
edit 2014/03/04 :
OK small update to say that I pushed myself very hard last night trying to approach the problem differently. Instead of trying to lock the functions supposed to be called in our thread to avoid memory collapsing, and thus risk to create deadlocks, I tried to inject somewhere in the main loop of the main thread a function of mine using a detour.
The idea is to make the main thread call this function driven by a static DWORD activating parts of the game's code and controled from our thread.
In pseudo code it can be sumed up by :
Code:
#define CMD_1 0x1 // for example SetNearestTarget
#define CMD_2 0x2 // for example SendSkill
#define CMD_3 0x4 // and so on...
DWORD commands = 0;
void myHook()
{
if(commands&CMD_1)
SetNearestTarget();
if(commands&CMD_2)
SendSkill();
commands = 0;// treated for this frame
}
The tunnel is supposed to contain :
Code:
pusha
call myHook
popa
[instructions removed by the set of the detour]
ret/jmp origin// ret if the detour set a call or jmp origin if it is a jmp
I'm nearly done with this ; just a simple problem of address call after I changed all my jmp instructions to call ones because I was destroying the stack when jumping to a c declared function with a jump (yeah let's destroy the stack joyfully xD).
I'll finish this tonight when coming back home, and tell you if this worked (hope it will, cause I'm in a shortage of ideas after this one...)
From a little testing it seems that you can set your speed to about 30-50% higher than what it should be with no major side effects.
This should be useful for getting to mobs very fast (minimizing time travelling between things) and also lets you get clear of red carpet faster meaning more time smacking bosses As with the previous pointer I posed (for the coord system) I've tried to refine the pointer to the best of my (bad) ability, several reboots and client starts etc. Once again I hope this is useful
Python Functions von Mt2 per C++ Code Inject ausführen? 12/02/2011 - C/C++ - 5 Replies Hallo, wollte fragen, ob mir eventuell jemand beantworten kann, wie man Python Functions nützt, welche in den Metin2 - pack Files gespeichert sind.
Und ob das überhaupt so wie ich mir das vorstelle möglich ist.
[Code / C++] Basic hooking of API Functions 07/19/2010 - Coding Tutorials - 2 Replies Global:
typedef BOOL (__stdcall * ReadProcessMemory_t)(HANDLE hProcess,LPVOID lpBaseAddress,LPCVOID lpBuffer,SIZE_T nSize,SIZE_T *lpNumberOfBytesRead);
ReadProcessMemory_t pReadProcessMemory;
Functions:
//Credits to GD ; You can do it manually, too.
SOX findings, place ur sox findiings here 06/04/2007 - Silkroad Online - 8 Replies place ur sox finds here :D
i just found a sos lvl 8 glaive =P
<hr>Append on Jun 4 2007, 01:11<hr> 20 mins later i find another sos chest.. lvl 13