Register for your free account! | Forgot your password?

You last visited: Today at 04:57

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



OllyDBG & CO

Discussion on OllyDBG & CO within the CO2 Programming forum part of the Conquer Online 2 category.

Closed Thread
 
Old 11/13/2008, 06:55   #76
 
elite*gold: 0
Join Date: Feb 2006
Posts: 988
Received Thanks: 45
tanelipe i tried the run conquer directly doesnt work i think the assembly needs update and also i tried a couple times
Acidburncx is offline  
Old 11/13/2008, 13:51   #77
 
elite*gold: 0
Join Date: Mar 2008
Posts: 8
Received Thanks: 0
How about removing the clicker detection? i've been scanning thru the code but unable to locate the mouse click event monitor.
Catacomb187 is offline  
Old 11/13/2008, 15:16   #78
 
elite*gold: 20
Join Date: Aug 2005
Posts: 1,734
Received Thanks: 1,001
These addresses are only for reference, it's not likely that they'll work for the latest patch; However these tutorials show how the addresses are found.
tanelipe is offline  
Old 11/15/2008, 18:14   #79
 
elite*gold: 0
Join Date: Nov 2006
Posts: 38
Received Thanks: 7
awesome guide ty so much tanelipe very helpful and ty trash for the wall jump keep up the good work
shinobi14 is offline  
Old 11/16/2008, 14:03   #80
 
elite*gold: 0
Join Date: Dec 2005
Posts: 219
Received Thanks: 21
hi can you chek new Conquer.exe i can't edite it
new patch difrent sumthing i dont know i cant find nuthing
what i need cheng for multi work agen + time clock + data etc
ViRuSeXy is offline  
Old 11/16/2008, 18:25   #81
 
Zkiller110's Avatar
 
elite*gold: 0
Join Date: Mar 2008
Posts: 276
Received Thanks: 99
does these things work on patsh 5072.......when i search it say item not found............plz help
Zkiller110 is offline  
Thanks
1 User
Old 11/16/2008, 21:52   #82
 
elite*gold: 0
Join Date: Jan 2007
Posts: 331
Received Thanks: 361
Yes all of this w3orks for patch 5072 ^^ and you probably have case sensitive on ^^
David5646 is offline  
Old 11/17/2008, 21:20   #83
 
Azothoras's Avatar
 
elite*gold: 0
Join Date: Feb 2006
Posts: 209
Received Thanks: 455
Quote:
Originally Posted by tanelipe View Post
Sorry about the delay, had a fever for the most of the week (-> I was laying down most of the time)

I won't go in that much of details in this one, I'll give you guys the "tools" to keep it patched though.

[Making Conquer.exe NON-DC]
0. Backup the Conquer.exe
1. Open Conquer in OllyDBG and let it analyze the code.

2. Find a code block that looks like this
Code:
004A6830  |. 8B10                       MOV EDX,DWORD PTR DS:[EAX]
004A6832  |. 6A 00                      PUSH 0
004A6834  |. 6A 00                      PUSH 0
004A6836  |. 68 0000FF00                PUSH 0FF0000
004A683B  |. 68 D5070000                PUSH 7D5
004A6840  |. 68 B7860100                PUSH 186B7
004A6845  |> 8BC8                       MOV ECX,EAX
3. Easiest way to find that is, find command (Ctrl + F) for that PUSH 186B7

4. Couple lines above that there should be codeblock that looks like this
Code:
004A67FD  |. 89BD ECFEFFFF              MOV DWORD PTR SS:[EBP-114],EDI
004A6803  |. 8985 F8FEFFFF              MOV DWORD PTR SS:[EBP-108],EAX
004A6809  |. 899D FCFEFFFF              MOV DWORD PTR SS:[EBP-104],EBX
004A680F  |. E8 30560400                CALL <JMP.&WINMM.timeGetTime>
004A6814  |. 8D8D ECFEFFFF              LEA ECX,DWORD PTR SS:[EBP-114]
004A681A  |. 8985 14FFFFFF              MOV DWORD PTR SS:[EBP-EC],EAX
5. Notice the CALL to winmm jmp.

6. Next what we need to do is make the exe jump to our own code instead of that call.

7. We need to search a place that can have 20 bytes (example from 500000 to 500020)

8. Scroll to almost the bottom of the Conquer.exe module and you should see lines like this (note the addresses)
Code:
00524C54   . 8B4D F0                    MOV ECX,DWORD PTR SS:[EBP-10]
00524C57   . 83C1 08                    ADD ECX,8
00524C5A   .^E9 3B31FBFF                JMP Conquer.004D7D9A
00524C5F   . B8 108C5500                MOV EAX,Conquer.00558C10
00524C64   .^E9 C1B2FCFF                JMP <JMP.&MSVCRT.__CxxFrameHandler>
00524C69     00                         DB 00
00524C6A     0000                       ADD BYTE PTR DS:[EAX],AL
00524C6C     0000                       ADD BYTE PTR DS:[EAX],AL
00524C6E     0000                       ADD BYTE PTR DS:[EAX],AL
00524C70     0000                       ADD BYTE PTR DS:[EAX],AL
00524C72     0000                       ADD BYTE PTR DS:[EAX],AL
00524C74     0000                       ADD BYTE PTR DS:[EAX],AL
00524C76     0000                       ADD BYTE PTR DS:[EAX],AL
00524C78     0000                       ADD BYTE PTR DS:[EAX],AL
00524C7A     0000                       ADD BYTE PTR DS:[EAX],AL
00524C7C     0000                       ADD BYTE PTR DS:[EAX],AL
9. ADD BYTES PTR DS:[EAX],AL might be DB 00 for you guys ignore that.

10. We start writing our own code at 00524C6A

11. Hit Ctrl + E and write these to the HEX part of the window just came. You can't put those 0x's or the ','s
Code:
0x81, 0x05, 0xB0, 0xEF, 0x56, 0x00, 0x6A, 0x04, 
0x00, 0x00, 0xA1, 0xB0, 0xEF, 0x56, 0x00, 0xE9, 
0x96, 0x1B, 0xF8, 0xFF
12. So just write 81 05 B0 EF and so on..

13. After that the codeblock should look like this
Code:
00524C6A     8105 B0EF5600 6A040000     ADD DWORD PTR DS:[56EFB0],46A
00524C74     A1 B0EF5600                MOV EAX,DWORD PTR DS:[56EFB0]
00524C79    ^E9 961BF8FF                JMP Conquer.004A6814
14. Note that we add the 46A (hex) into a static location, after that we mov it to eax

15. Note the address it jumps to, it should be exactly one line BELOW the call to timeGetTime()

16. It jumps to code that looks like this (Should be familiar from before)
Code:
004A6814  |. 8D8D ECFEFFFF              LEA ECX,DWORD PTR SS:[EBP-114]
17. What we now need to do is, change the CALL thing to jump to our own code that we just wrote. Remember the address?

18. We replace this
Code:
004A680F  |. E8 30560400                CALL <JMP.&WINMM.timeGetTime>
with
Code:
004A680F     E9 56E40700                JMP Conquer.00524C6A
19. Now every time the jump function "trys" to call the old timeGetTime, it jumps to our code that holds the lastjumptime+46A and then moves it to eax at somepoint it'll add it to the packet (lazy mofos not doing server side check)

20. Now it'd be really nice if people didn't start making shitloads of these nondc things here, already couple working so.

If there is anything you'd like to ask me about, please go ahead
So I've now successfully done all of this to my conquer.exe but when I jump in conquer I get an error and my conquer crashes... It says that it can't write to 0x0056EFB0.... Do I need to change this to something other? I'm not that good with this shit but I've managed to get everything else working and I've managed to understand that I had to change the other addresses to fit my conquer version

But this I have no idea about ^^


Ty for all anyways
Azothoras is offline  
Old 11/17/2008, 21:54   #84
 
elite*gold: 20
Join Date: Aug 2005
Posts: 1,734
Received Thanks: 1,001
I'm not sure why that address doesn't work anymore, I advice you to find another place which can hold 2 bytes and is static. (Doesn't get accessed by any other part of the code) Finding this shouldn't be too hard. When you have done this only thing you need to do is to modify the addresses and it should work, I haven't updated it for myself yet so I don't have an example address.
tanelipe is offline  
Old 11/18/2008, 13:46   #85
 
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
Quote:
Originally Posted by tanelipe View Post
I'm not sure why that address doesn't work anymore, I advice you to find another place which can hold 2 bytes and is static. (Doesn't get accessed by any other part of the code) Finding this shouldn't be too hard. When you have done this only thing you need to do is to modify the addresses and it should work, I haven't updated it for myself yet so I don't have an example address.
Code:
004BB7C8              E8 ADAC0400          CALL <JMP.&WINMM.timeGetTime>


004BB7C8             /E9 33550800          JMP Conquer_.00540D00

00540D00              8105 C8275800 6A0400>ADD DWORD PTR DS:[5827C8],46A
00540D0A              A1 C8275800          MOV EAX,DWORD PTR DS:[5827C8]
00540D0F            ^ E9 B9AAF7FF          JMP Conquer_.004BB7CD
_fobos_ is offline  
Old 11/18/2008, 14:58   #86
 
Azothoras's Avatar
 
elite*gold: 0
Join Date: Feb 2006
Posts: 209
Received Thanks: 455
Quote:
Originally Posted by _fobos_ View Post
Code:
004BB7C8              E8 ADAC0400          CALL <JMP.&WINMM.timeGetTime>


004BB7C8             /E9 33550800          JMP Conquer_.00540D00

00540D00              8105 C8275800 6A0400>ADD DWORD PTR DS:[5827C8],46A
00540D0A              A1 C8275800          MOV EAX,DWORD PTR DS:[B][COLOR="Red"][SIZE="4"][5827C8][/SIZE][/COLOR][/B]
00540D0F            ^ E9 B9AAF7FF          JMP Conquer_.004BB7CD
What does this adress access? It doesn't access anything not in my conquer.exe or yours whatever version you've got... hehe and this is where the error occurs...
Azothoras is offline  
Old 11/18/2008, 19:22   #87
 
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
Quote:
Originally Posted by Azothoras View Post
What does this adress access? It doesn't access anything not in my conquer.exe or yours whatever version you've got... hehe and this is where the error occurs...
Did you test it?
I had no trouble updating it at all, download the multi I have released open it up in olly and go to the addresses u quoted, you will see it works just fine
hint: look it up in dump window
If you still have the old exe aswell load it up in olly and go to the one in tanelipe's guide
You will find the way I updated it
_fobos_ is offline  
Old 11/18/2008, 21:13   #88
 
elite*gold: 0
Join Date: Jun 2006
Posts: 965
Received Thanks: 576
This really isn't a tutorial, more of steps.
high6 is offline  
Old 11/19/2008, 12:27   #89
 
elite*gold: 0
Join Date: Jul 2006
Posts: 88
Received Thanks: 0
i do non dc and it work but when i jump more jump it's dc and i see in window msg "System:invalid jump"
can help me why it dc i finish upgrade CO YETI tool for patch 5072 but can't upload it for this reason
ace_heart is offline  
Old 11/19/2008, 19:50   #90
 
elite*gold: 0
Join Date: Sep 2008
Posts: 490
Received Thanks: 595
Oops my bad I messed up somewhere, I dont use speedhack myself
just tested my apologies
Im gonna look into it, i assumed it worked my bad
_fobos_ is offline  
Closed Thread


Similar Threads Similar Threads
How to use OllyDBG
12/13/2009 - 12Sky2 - 1 Replies
Is there any tutorial for this program? I want to learn how to hack 12Sky but I don't know how to use it. I know some basics but nothing more. I know to work in CE and in AutoIT really well.
[Help]Ollydbg.
12/10/2009 - Mabinogi - 4 Replies
I didnt have problems until today. For some reason, when i open any dll with ollydbg this error message pops up. If you dont mind, help me with this problem.
Ollydbg help
08/03/2009 - Dekaron - 23 Replies
I am trying to get a GM hack working, but I am still pretty noob with olly and assembly language. Is there anybody who would be willing to help me along, or work on it with me? I'm not asking for somebody to tell me what to do, just for somebody to give me a few pointers and tips and such to get this going. What I did was backtrack a few of the gm commands using the call tree, and I ended up at the same offset for each code (0050CE37). So, I'm assuming that is the line that determines if...
OllyDBG
07/16/2009 - Perfect World - 5 Replies
hey can i have question what can i do with ollydbg at pw all? can i change my atk or gold with them? pls tell me what all can i do with this programm at pw:handsdown:
OllyDBG Help
03/25/2008 - General Coding - 4 Replies
Hi,i recently heard you could dupe items in ROSE Online with OllyDBG,it's patched already,and i was wondering if this works with any game.If so,could someone release a Tutorial or something to help me understand how to use OllyDBG better? I'm sorry if there is one already posted,i searched and couldnt find any.



All times are GMT +1. The time now is 04:57.


Powered by vBulletin®
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2025 elitepvpers All Rights Reserved.