Register for your free account! | Forgot your password?

You last visited: Today at 06:12

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



[Aimbot] 6981

Discussion on [Aimbot] 6981 within the CO2 Programming forum part of the Conquer Online 2 category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Nov 2007
Posts: 128
Received Thanks: 39
[Aimbot] 6981

After messing around with different programs in a VM i found an working aim bot, but it also does some questionable stuff like downloading .net programs into the /c folder that are flagged by malware analysis tools

So for anyone that wants to learn/study how an aimbot works in the latest patch:


Code:
[720] Conquer.exe!Conquer.exe+0x284CC3 || [0x00684CC3] => 0x0109FFFB               || Inline - Detour [5 Bytes]        || mov eax , dword ptr [eax+00000170h] || jmp 010A0000h
A3 00100A01           - mov [010A1000],eax { (0) }
8B 80 70010000        - mov eax,[eax+00000170]
E9 B94C5EFF           - jmp Conquer.exe+284CC9

[720] Conquer.exe!Conquer.exe+0x284CC8 || [0x00684CC8]                             || Custom Patch [1 Bytes]           || 00 89                               || 90 89
NOP

[720] Conquer.exe!Conquer.exe+0x39B119 || [0x0079B119] => 0x0112FFFB               || Inline - Detour [5 Bytes]        || mov ebx , dword ptr [ebp-20h]       || jmp 01130000h
01130000 - 8B 0D 00100A01        - mov ecx,[010A1000] { (0) }
01130006 - 9C                    - pushfd 
01130007 - 60                    - pushad 
01130008 - 6A 04                 - push 04 { 4 }
0113000A - 8D 81 70010000        - lea eax,[ecx+00000170]
01130010 - 50                    - push eax
01130011 - E8 2A15FA73           - call KERNEL32.IsBadReadPtr
01130016 - 83 F8 00              - cmp eax,00 { 0 }
01130019 - 0F85 DE010000         - jne 011301FD
0113001F - 8B 0D 00100B01        - mov ecx,[010B1000] { (0) }
01130025 - 8B 89 5C1A0000        - mov ecx,[ecx+00001A5C]
0113002B - 81 F9 302F0000        - cmp ecx,00002F30 { 12080 }
01130031 - 0F84 A2010000         - je 011301D9
01130037 - 81 F9 74170000        - cmp ecx,00001774 { 6004 }
0113003D - 0F84 96010000         - je 011301D9
01130043 - 81 F9 72170000        - cmp ecx,00001772 { 6002 }
01130049 - 0F84 8A010000         - je 011301D9
0113004F - 81 F9 E8030000        - cmp ecx,000003E8 { 1000 }
01130055 - 0F84 7E010000         - je 011301D9
0113005B - 81 F9 E9030000        - cmp ecx,000003E9 { 1001 }
01130061 - 0F84 72010000         - je 011301D9
01130067 - 81 F9 EA030000        - cmp ecx,000003EA { 1002 }
0113006D - 0F84 66010000         - je 011301D9
01130073 - 81 F9 ED030000        - cmp ecx,000003ED { 1005 }
01130079 - 0F84 5A010000         - je 011301D9
0113007F - 81 F9 0E040000        - cmp ecx,0000040E { 1038 }
01130085 - 0F84 4E010000         - je 011301D9
0113008B - 81 F9 E4340000        - cmp ecx,000034E4 { 13540 }
01130091 - 0F84 42010000         - je 011301D9
01130097 - 81 F9 8C2D0000        - cmp ecx,00002D8C { 11660 }
0113009D - 0F84 36010000         - je 011301D9
011300A3 - 81 F9 BC340000        - cmp ecx,000034BC { 13500 }
011300A9 - 0F84 2A010000         - je 011301D9
011300AF - 81 F9 AC2B0000        - cmp ecx,00002BAC { 11180 }
011300B5 - 0F84 1E010000         - je 011301D9
011300BB - 81 F9 8D280000        - cmp ecx,0000288D { 10381 }
011300C1 - 0F84 12010000         - je 011301D9
011300C7 - 81 F9 8C2D0000        - cmp ecx,00002D8C { 11660 }
011300CD - 0F84 06010000         - je 011301D9
011300D3 - 81 F9 32320000        - cmp ecx,00003232 { 12850 }
011300D9 - 0F84 FA000000         - je 011301D9
011300DF - 81 F9 82320000        - cmp ecx,00003282 { 12930 }
011300E5 - 0F84 EE000000         - je 011301D9
011300EB - 81 F9 15040000        - cmp ecx,00000415 { 1045 }
011300F1 - 0F84 E2000000         - je 011301D9
011300F7 - 81 F9 32320000        - cmp ecx,00003232 { 12850 }
011300FD - 0F84 D6000000         - je 011301D9
01130103 - 81 F9 16040000        - cmp ecx,00000416 { 1046 }
01130109 - 0F84 CA000000         - je 011301D9
0113010F - 81 F9 71170000        - cmp ecx,00001771 { 6001 }
01130115 - 0F84 BE000000         - je 011301D9
0113011B - 81 F9 3E300000        - cmp ecx,0000303E { 12350 }
01130121 - 0F84 B2000000         - je 011301D9
01130127 - 81 F9 B2340000        - cmp ecx,000034B2 { 13490 }
0113012D - 0F84 A6000000         - je 011301D9
01130133 - 81 F9 6C2F0000        - cmp ecx,00002F6C { 12140 }
01130139 - 0F84 9A000000         - je 011301D9
0113013F - 81 F9 622F0000        - cmp ecx,00002F62 { 12130 }
01130145 - 0F84 8E000000         - je 011301D9
0113014B - 81 F9 582F0000        - cmp ecx,00002F58 { 12120 }
01130151 - 0F84 82000000         - je 011301D9
01130157 - 81 F9 262F0000        - cmp ecx,00002F26 { 12070 }
0113015D - 0F84 76000000         - je 011301D9
01130163 - 81 F9 662B0000        - cmp ecx,00002B66 { 11110 }
01130169 - 0F84 6A000000         - je 011301D9
0113016F - 81 F9 162B0000        - cmp ecx,00002B16 { 11030 }
01130175 - 0F84 5E000000         - je 011301D9
0113017B - 81 F9 8D040000        - cmp ecx,0000048D { 1165 }
01130181 - 0F84 52000000         - je 011301D9
01130187 - 81 F9 C23D0000        - cmp ecx,00003DC2 { 15810 }
0113018D - 0F84 46000000         - je 011301D9
01130193 - 81 F9 9A3D0000        - cmp ecx,00003D9A { 15770 }
01130199 - 0F84 3A000000         - je 011301D9
0113019F - 81 F9 543D0000        - cmp ecx,00003D54 { 15700 }
011301A5 - 0F84 2E000000         - je 011301D9
011301AB - 81 F9 3E2B0000        - cmp ecx,00002B3E { 11070 }
011301B1 - 0F84 22000000         - je 011301D9
011301B7 - 81 F9 B62B0000        - cmp ecx,00002BB6 { 11190 }
011301BD - 0F84 16000000         - je 011301D9
011301C3 - 81 F9 58390000        - cmp ecx,00003958 { 14680 }
011301C9 - 0F84 0A000000         - je 011301D9
011301CF - 8B 5D E0              - mov ebx,[ebp-20]
011301D2 - 85 DB                 - test ebx,ebx
011301D4 - E9 45AF66FF           - jmp Conquer.exe+39B11E
011301D9 - 83 3D 00080D01 1E     - cmp dword ptr [010D0800],1E { (0),30 }
011301E0 - 0F85 0D000000         - jne 011301F3
011301E6 - 8B 1D 00100A01        - mov ebx,[010A1000] { (0) }
011301EC - 85 DB                 - test ebx,ebx
011301EE - E9 2BAF66FF           - jmp Conquer.exe+39B11E
011301F3 - 8B 5D E0              - mov ebx,[ebp-20]
011301F6 - 85 DB                 - test ebx,ebx
011301F8 - E9 21AF66FF           - jmp Conquer.exe+39B11E
011301FD - 61                    - popad 
011301FE - 9D                    - popfd 
011301FF - 8B 5D E0              - mov ebx,[ebp-20]
01130202 - 85 DB                 - test ebx,ebx
01130204 - E9 15AF66FF           - jmp Conquer.exe+39B11E


[720] Conquer.exe!Conquer.exe+0x39CF13 || [0x0079CF13] => Conquer.exe [0x0079CF27] || Inline - Relative [2 Bytes]      || jne 0079CF29h                       || jmp 0079CF29h
Conquer.exe+39CF27 - EB DE                 - jmp Conquer.exe+39CF07

[720] Conquer.exe!Conquer.exe+0x401156 || [0x00801156] => 0x0114FFFB               || Inline - Detour [5 Bytes]        || mov eax , dword ptr [esi+48h]       || jmp 01150000h
01150000 - 8B 0D 00100B01        - mov ecx,[010B1000] { (0) }
01150006 - 8B 89 5C1A0000        - mov ecx,[ecx+00001A5C]
0115000C - 81 F9 15040000        - cmp ecx,00000415 { 1045 }
01150012 - 0F84 52000000         - je 0115006A
01150018 - 81 F9 16040000        - cmp ecx,00000416 { 1046 }
0115001E - 0F84 46000000         - je 0115006A
01150024 - 81 F9 82320000        - cmp ecx,00003282 { 12930 }
0115002A - 0F84 3A000000         - je 0115006A
01150030 - 81 F9 3E300000        - cmp ecx,0000303E { 12350 }
01150036 - 0F84 2E000000         - je 0115006A
0115003C - 81 F9 C23D0000        - cmp ecx,00003DC2 { 15810 }
01150042 - 0F84 22000000         - je 0115006A
01150048 - 81 F9 9A3D0000        - cmp ecx,00003D9A { 15770 }
0115004E - 0F84 16000000         - je 0115006A
01150054 - 81 F9 B62B0000        - cmp ecx,00002BB6 { 11190 }
0115005A - 0F84 0A000000         - je 0115006A
01150060 - 8B 46 48              - mov eax,[esi+48]
01150063 - 85 C0                 - test eax,eax
01150065 - E9 F1106BFF           - jmp Conquer.exe+40115B
0115006A - 83 3D 00080D01 1E     - cmp dword ptr [010D0800],1E { (0),30 }
01150071 - 0F85 35000000         - jne 011500AC
01150077 - 83 3D 00100A01 00     - cmp dword ptr [010A1000],00 { (0),0 }
0115007E - 0F84 28000000         - je 011500AC
01150084 - 3B 35 00100A01        - cmp esi,[010A1000] { (0) }
0115008A - 0F85 1C000000         - jne 011500AC
01150090 - 81 BE 1C020000 82000000 - cmp [esi+0000021C],00000082 { 130 }
0115009A - 0F85 0C000000         - jne 011500AC
011500A0 - B8 01000000           - mov eax,00000001 { 1 }
011500A5 - 85 C0                 - test eax,eax
011500A7 - E9 AF106BFF           - jmp Conquer.exe+40115B
011500AC - 8B 46 48              - mov eax,[esi+48]
011500AF - 85 C0                 - test eax,eax
011500B1 - E9 A5106BFF           - jmp Conquer.exe+40115B


[720] Conquer.exe!Conquer.exe+0x42A116 || [0x0082A116] => 0x010BFFFB               || Inline - Detour + MORE [6 Bytes] || mov eax , dword ptr [ebp-04h]       || jmp 010C0000h
010C0000 - 3B 35 00100A01        - cmp esi,[010A1000] { (0) }
010C0006 - 0F84 22000000         - je 010C002E
010C000C - 83 3D 00100A01 00     - cmp dword ptr [010A1000],00 { (0),0 }
010C0013 - 0F84 15000000         - je 010C002E
010C0019 - C7 86 DE000000 00000000 - mov [esi+000000DE],00000000 { 0 }
010C0023 - 8B 45 FC              - mov eax,[ebp-04]
010C0026 - 99                    - cdq 
010C0027 - 29 D0                 - sub eax,edx
010C0029 - E9 EEA076FF           - jmp Conquer.exe+42A11C
010C002E - 3B 35 00100A01        - cmp esi,[010A1000] { (0) }
010C0034 - 0F85 15000000         - jne 010C004F
010C003A - C7 86 DE000000 50000000 - mov [esi+000000DE],00000050 { 80 }
010C0044 - 8B 45 FC              - mov eax,[ebp-04]
010C0047 - 99                    - cdq 
010C0048 - 29 D0                 - sub eax,edx
010C004A - E9 CDA076FF           - jmp Conquer.exe+42A11C
010C004F - 8B 45 FC              - mov eax,[ebp-04]
010C0052 - 99                    - cdq 
010C0053 - 29 D0                 - sub eax,edx
010C0055 - E9 C2A076FF           - jmp Conquer.exe+42A11C

[720] Conquer.exe!Conquer.exe+0x44C38A || [0x0084C38A] => 0x010AFFFB               || Inline - Detour [5 Bytes]        || lea eax , dword ptr [esi+000015ACh] || jmp 010B0000h
010C0000 - 3B 35 00100A01        - cmp esi,[010A1000] { (0) }
010C0006 - 0F84 22000000         - je 010C002E
010C000C - 83 3D 00100A01 00     - cmp dword ptr [010A1000],00 { (0),0 }
010C0013 - 0F84 15000000         - je 010C002E
010C0019 - C7 86 DE000000 00000000 - mov [esi+000000DE],00000000 { 0 }
010C0023 - 8B 45 FC              - mov eax,[ebp-04]
010C0026 - 99                    - cdq 
010C0027 - 29 D0                 - sub eax,edx
010C0029 - E9 EEA076FF           - jmp Conquer.exe+42A11C
010C002E - 3B 35 00100A01        - cmp esi,[010A1000] { (0) }
010C0034 - 0F85 15000000         - jne 010C004F
010C003A - C7 86 DE000000 50000000 - mov [esi+000000DE],00000050 { 80 }
010C0044 - 8B 45 FC              - mov eax,[ebp-04]
010C0047 - 99                    - cdq 
010C0048 - 29 D0                 - sub eax,edx
010C004A - E9 CDA076FF           - jmp Conquer.exe+42A11C
010C004F - 8B 45 FC              - mov eax,[ebp-04]
010C0052 - 99                    - cdq 
010C0053 - 29 D0                 - sub eax,edx
010C0055 - E9 C2A076FF           - jmp Conquer.exe+42A11C

[720] Conquer.exe!Conquer.exe+0x44C38F || [0x0084C38F]                             || Custom Patch [1 Bytes]           || 00 80                               || 90 80
nop
[720] Conquer.exe!Conquer.exe+0x52F78D || [0x0092F78D]                             || Custom Patch [6 Bytes]           || mov esi , dword ptr [eax+10h]       || mov esi , 0000000Fh
Conquer.exe+52F78D - BE 0F000000           - mov esi,0000000F { 15 }

[720] Conquer.exe!Conquer.exe+0x5873AC || [0x009873AC] => 0x0113FFFB               || Inline - Detour + MORE [8 Bytes] || mov eax , dword ptr [eax+1Ch]       || jmp 01140000h

01140000 - 9C                    - pushfd 
01140001 - 60                    - pushad 
01140002 - 6A 02                 - push 02 { 2 }
01140004 - E8 478EDE74           - call USER32.GetAsyncKeyState
01140009 - 66 D1 E0              - shl ax,1
0114000C - 0F82 0F000000         - jb 01140021
01140012 - 61                    - popad 
01140013 - 9D                    - popfd 
01140014 - 8B 40 1C              - mov eax,[eax+1C]
01140017 - E9 A17584FF           - jmp Conquer.exe+5875BD
0114001C - E9 937384FF           - jmp Conquer.exe+5873B4
01140021 - 61                    - popad 
01140022 - 9D                    - popfd 
01140023 - 83 3D 00080D01 1E     - cmp dword ptr [010D0800],1E { (0),30 }
0114002A - 0F85 3B010000         - jne 0114016B
01140030 - 8B 0D 00100B01        - mov ecx,[010B1000] { (0) }
01140036 - 8B 89 5C1A0000        - mov ecx,[ecx+00001A5C]
0114003C - 81 F9 15040000        - cmp ecx,00000415 { 1045 }
01140042 - 0F84 85000000         - je 011400CD
01140048 - 81 F9 16040000        - cmp ecx,00000416 { 1046 }
0114004E - 0F84 79000000         - je 011400CD
01140054 - 81 F9 82320000        - cmp ecx,00003282 { 12930 }
0114005A - 0F84 6D000000         - je 011400CD
01140060 - 81 F9 3E300000        - cmp ecx,0000303E { 12350 }
01140066 - 0F84 61000000         - je 011400CD
0114006C - 81 F9 C23D0000        - cmp ecx,00003DC2 { 15810 }
01140072 - 0F84 55000000         - je 011400CD
01140078 - 81 F9 9A3D0000        - cmp ecx,00003D9A { 15770 }
0114007E - 0F84 49000000         - je 011400CD
01140084 - 81 F9 662B0000        - cmp ecx,00002B66 { 11110 }
0114008A - 0F84 3D000000         - je 011400CD
01140090 - 81 F9 3E2B0000        - cmp ecx,00002B3E { 11070 }
01140096 - 0F84 31000000         - je 011400CD
0114009C - 81 F9 71170000        - cmp ecx,00001771 { 6001 }
011400A2 - 0F84 25000000         - je 011400CD
011400A8 - 81 F9 B62B0000        - cmp ecx,00002BB6 { 11190 }
011400AE - 0F84 19000000         - je 011400CD
011400B4 - 81 F9 58390000        - cmp ecx,00003958 { 14680 }
011400BA - 0F84 0D000000         - je 011400CD
011400C0 - 8B 40 1C              - mov eax,[eax+1C]
011400C3 - E9 F57484FF           - jmp Conquer.exe+5875BD
011400C8 - E9 E77284FF           - jmp Conquer.exe+5873B4
011400CD - 83 78 1C 04           - cmp dword ptr [eax+1C],04 { 4 }
011400D1 - 0F84 85000000         - je 0114015C
011400D7 - 83 78 1C 70           - cmp dword ptr [eax+1C],70 { 112 }
011400DB - 0F84 7B000000         - je 0114015C
011400E1 - 83 78 1C 1B           - cmp dword ptr [eax+1C],1B { 27 }
011400E5 - 0F84 71000000         - je 0114015C
011400EB - 83 78 1C 0E           - cmp dword ptr [eax+1C],0E { 14 }
011400EF - 0F84 67000000         - je 0114015C
011400F5 - 83 78 1C 47           - cmp dword ptr [eax+1C],47 { 71 }
011400F9 - 0F84 5D000000         - je 0114015C
011400FF - 83 78 1C 3D           - cmp dword ptr [eax+1C],3D { 61 }
01140103 - 0F84 53000000         - je 0114015C
01140109 - 83 78 1C 40           - cmp dword ptr [eax+1C],40 { 64 }
0114010D - 0F84 49000000         - je 0114015C
01140113 - 83 78 1C 3C           - cmp dword ptr [eax+1C],3C { 60 }
01140117 - 0F84 3F000000         - je 0114015C
0114011D - 83 78 1C 38           - cmp dword ptr [eax+1C],38 { 56 }
01140121 - 0F84 35000000         - je 0114015C
01140127 - 83 78 1C 05           - cmp dword ptr [eax+1C],05 { 5 }
0114012B - 0F84 2B000000         - je 0114015C
01140131 - 83 78 1C 06           - cmp dword ptr [eax+1C],06 { 6 }
01140135 - 0F84 21000000         - je 0114015C
0114013B - 83 78 1C 08           - cmp dword ptr [eax+1C],08 { 8 }
0114013F - 0F84 17000000         - je 0114015C
01140145 - 83 78 1C 59           - cmp dword ptr [eax+1C],59 { 89 }
01140149 - 0F84 0D000000         - je 0114015C
0114014F - 8B 40 1C              - mov eax,[eax+1C]
01140152 - E9 667484FF           - jmp Conquer.exe+5875BD
01140157 - E9 587284FF           - jmp Conquer.exe+5873B4
0114015C - B8 01000000           - mov eax,00000001 { 1 }
01140161 - E9 577484FF           - jmp Conquer.exe+5875BD
01140166 - E9 497284FF           - jmp Conquer.exe+5873B4
0114016B - 8B 40 1C              - mov eax,[eax+1C]
0114016E - E9 4A7484FF           - jmp Conquer.exe+5875BD
01140173 - E9 3C7284FF           - jmp Conquer.exe+5873B4



One Tap is offline  
Thanks
1 User
Old 11/15/2019, 02:17   #2
 
elite*gold: 0
Join Date: Nov 2019
Posts: 1
Received Thanks: 0
how to use this i have no idea


erngerona is offline  
Old 11/23/2019, 03:13   #3
 
elite*gold: 0
Join Date: Nov 2019
Posts: 17
Received Thanks: 0
@ I'm new in programming, i just need copy and paste in vs and create a executable? idk
Noycers is offline  
Old 11/24/2019, 13:56   #4
 
elite*gold: 28
Join Date: Jun 2010
Posts: 2,217
Received Thanks: 865
Quote:
Originally Posted by Noycers View Post
@ I'm new in programming, i just need copy and paste in vs and create a executable? idk
hes showing u what he did to the client assembly


_DreadNought_ is offline  
Old 11/25/2019, 02:22   #5
 
elite*gold: 0
Join Date: Nov 2019
Posts: 17
Received Thanks: 0
Quote:
Originally Posted by _DreadNought_ View Post
hes showing u what he did to the client assembly
Oh, thank you

Anyway, idk what to do
Noycers is offline  
Old 11/25/2019, 16:59   #6
 
elite*gold: 28
Join Date: Jun 2010
Posts: 2,217
Received Thanks: 865
Quote:
Originally Posted by Noycers View Post
Oh, thank you

Anyway, idk what to do
then no aimbot its gonna take a very long time to learn the skills required to use what he has given you to make it work

google olydbg & assembly (highlighting inline, detours & patching)


_DreadNought_ is offline  
Reply



« Helo, a little help on itemstacking | Requesting advice! »

Similar Threads
I Search a Aimbot | Ich suche ein Aimbot
12/12/2010 - Combat Arms - 11 Replies
Hi ich suche nen Aimbot der funktioniert und ungepatcht ist wie auch immer da ich wenn ich die zahlreich aufgelisteten aimbots in epvp versuche runterzuladen kommt bei mir immer error und ich kann ihn nicht starten ich bitte um ein aimbot bei dem sowas evtl. nicht auftrtit wer super wer mir so einen link rein setzt bekommt ein dickes THX Hi I am looking nen Aimbot that works and is unpatched as well as I always when I try to download the numerous listed in aimbots epvp come with...
[AimBot] I Need AimBot For Patch 5065
08/21/2009 - Conquer Online 2 - 15 Replies
Hello, Can u Let Me Know Where Can I Get AimBot And If U Know Where They Have It Can U Send Me The Site Thnks xD:pimp:
Detect aimbot without asking to type in #aimbot
02/14/2008 - Conquer Online 2 - 11 Replies
I learned that recently aimbot got patched, well so i've heard, not absolutely sure if its patched or not. But is there any other way of detecting and proving aimbots without having to ask them to type in #bladebot or !bladebot ? cus alot of time i will get hit in midair without them being throwing a linear fastblade towards my jump path. they would throw it at me in a T position and land it on me numerous times, but when asking them to type in #bladebot or !bladebot they do type it...



All times are GMT +1. The time now is 06:12.


Powered by vBulletin®
Copyright ©2000 - 2019, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.

BTC: 33E6kMtxYa7dApCFzrS3Jb7U3NrVvo8nsK
ETH: 0xc6ec801B7563A4376751F33b0573308aDa611E05

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2019 elitepvpers All Rights Reserved.