Hi,
ich habe ein Spiel(Airrivals) welches seine PID schützt weshalb man es nicht mit Cheat Engine oder sonstwas öffnen kann ... Somit kann ich nicht einfach nach Values suchen.. Kann ich das auch irgendwie mit ollydbg/ida pro machen?
klar, mit ollydbg dumper. ist aber net so schön.
erste idee ist doch immer, die pid freizugeben, oder?
wenn du mit ollydbg rankommst, kannst du ja nachschauen wo das ganze hakt.
ansonsten kannst du
1. Memory Hacking Software by L.Spiro probieren
2. einen simplen cheatengine nachbau als dll verpacken und injezieren (ce ist open src, da kannst du code rausrippen)
3. GetCurrentProcessId aus einer injezierten dll aufrufen.
Und was habe ich dann noch fuer Moeglichkeiten an den ( fuer mich wichtigen ) Speicher ranzukommen? Sagen wir ich suche nach dem Wert 50, wie kann ich diesen num finden? MFG
Ollydbg help 08/03/2009 - Dekaron - 23 Replies I am trying to get a GM hack working, but I am still pretty noob with olly and assembly language. Is there anybody who would be willing to help me along, or work on it with me? I'm not asking for somebody to tell me what to do, just for somebody to give me a few pointers and tips and such to get this going.
What I did was backtrack a few of the gm commands using the call tree, and I ended up at the same offset for each code (0050CE37). So, I'm assuming that is the line that determines if...
ollydbg 06/24/2009 - Dekaron - 3 Replies can i take the new adress with ollydbg?
is there any TUT?
Ollydbg TuT? 05/17/2009 - Metin2 - 2 Replies hey, gibt es vielleicht ein (einfaches, leicht zu verstehendes) tutorial darüber wie man mit dem Ollydbg P-server ins deutsche (und andersrum) übersetzen kann?
mfg Zorkas
speicheradresse -> gesetteten pointer auslesen wie?? 10/26/2008 - Guild Wars - 3 Replies hallo ich habe einen pointer gesettet
adress of pointer ist das 024E1F62
hex(offset) F94E0
wie kann ich also mit autoit den pointer auslesen?
Ollydbg 03/27/2007 - Planetside - 3 Replies I can't seem to attach the planetside process into ollydbg. Is there a workaround for this?