MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides

Homepage Register FAQ Members Mark Forums Read Advertise Marketplace FPSowned


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > World of Warcraft > Bots and Programs > WoW Memory Editing
Reload this Page [GUIDE] How to set up a simple jump and speed hack using CE *moved*
WoW Memory Editing WoW Memory Editing for learning purposes only.

Reply
 
LinkBack Thread Tools
(#46)
Old
Sychotix's Avatar
Sychotix is Offline
Contributor
Rep Power: 3
Reputation: 97
Sychotix will become famous soon enough
 
Posts: 664
Join Date: Apr 2006
07-14-2008

Quote:
Originally Posted by kynox View Post
The function thats reading from it is inside of Warden.

It reads offsets (yes, you could hook this , but it also reads other data)..
Though Warden is dynamically allocated, so that address is quite useless once its unloaded .
yeah i know. BUT the game has to know where Warden is located, thus there has to be a pointer somewhere. The only problem that I see is i think it is multi-level and i HATE multi-level pointers -.- I traced back the function and got to a place where there was a long (if not continual) loop. That must be the loop in which it keeps scanning. What if we simply changed that loop to where it just kept scanning and never leave that section of code? =P

EDIT: by the way kynox, it would be MUCH easier to talk over MSN instead of hijacking a thread such as we have done =P mind PMing me your MSN or AIM? (only two i use)

EDIT2: I think i may have it bypassed as well. I traced the function all the way back to where it was originally called. The address is static as well. Anyone let me know a way to get banned by warden instantly and I will tell them =P

EDIT3: I now have 2 different addresses in which the complete warden function is called.

Last edited by Sychotix; 07-14-2008 at 03:22 PM.
Reply With Quote

Donate to remove ads.
(#47)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 781
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,799
Join Date: Apr 2006
Location: Hiding in ur warden
07-14-2008

Quote:
Originally Posted by Sychotix View Post
yeah i know. BUT the game has to know where Warden is located, thus there has to be a pointer somewhere. The only problem that I see is i think it is multi-level and i HATE multi-level pointers -.- I traced back the function and got to a place where there was a long (if not continual) loop. That must be the loop in which it keeps scanning. What if we simply changed that loop to where it just kept scanning and never leave that section of code? =P

EDIT: by the way kynox, it would be MUCH easier to talk over MSN instead of hijacking a thread such as we have done =P mind PMing me your MSN or AIM? (only two i use)

EDIT2: I think i may have it bypassed as well. I traced the function all the way back to where it was originally called. The address is static as well. Anyone let me know a way to get banned by warden instantly and I will tell them =P

.text:00818D10 WardenAllocDealloc proc near ; CODE XREF: sub_4EA270+21Fp
.text:00818D10

Thats the function that handles allocating warden etc. If you hook that you can grab where it's being loaded in memory and even dump the entire module if you like.




Yes my old nick was Chazwazza, stop asking >.<
Reply With Quote
(#48)
Old
Sychotix's Avatar
Sychotix is Offline
Contributor
Rep Power: 3
Reputation: 97
Sychotix will become famous soon enough
 
Posts: 664
Join Date: Apr 2006
07-14-2008

nope that isn't where i found =P so far, I think jumping over my two addresses bypass the ban feature. Kinda like Maplestories Autoban thing... if you would normally have gotten banned, you just get disconnected. I changed both jumps and then changed my jump value. I jumped around for a little bit and then got randomly disconnected.

I will poke around that location though to see if i can find anything else out. maybe WoW will run without it?

EDIT: lol WoW ran fine for a while without warden "allocated" but it eventually disconnected. There is probably either a serversided or clientsided check. It could be like GG where the server sends a command or "hey are you there" and when it gets no response, it cuts the connection.

Last edited by Sychotix; 07-14-2008 at 03:40 PM.
Reply With Quote
(#49)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 781
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,799
Join Date: Apr 2006
Location: Hiding in ur warden
07-14-2008

Quote:
Originally Posted by Sychotix View Post
nope that isn't where i found =P so far, I think jumping over my two addresses bypass the ban feature. Kinda like Maplestories Autoban thing... if you would normally have gotten banned, you just get disconnected. I changed both jumps and then changed my jump value. I jumped around for a little bit and then got randomly disconnected.

I will poke around that location though to see if i can find anything else out. maybe WoW will run without it?

EDIT: lol WoW ran fine for a while without warden "allocated" but it eventually disconnected. There is probably either a serversided or clientsided check. It could be like GG where the server sends a command or "hey are you there" and when it gets no response, it cuts the connection.
Err, WoW won't run without Warden there. If WoW sends a scan request and doesn't get a reply you get kicked from the server (and maybe the banstick, unsure). Sorry, I think you changed something else.

Also, bans are serverside, there's no address you can 'jump' to stop getting banned. The servers request a scan, warden copies the memory in the requested location and sends it back to the server, the server checks if it's valid, if not, banstick. The only way to bypass the bans is to spoof the correct values to the server when it requests them by hooking wardens scanning functions.




Yes my old nick was Chazwazza, stop asking >.<
Reply With Quote
(#50)
Old
Sychotix's Avatar
Sychotix is Offline
Contributor
Rep Power: 3
Reputation: 97
Sychotix will become famous soon enough
 
Posts: 664
Join Date: Apr 2006
07-14-2008

hm.... guess i just put a jump on if it sends the data back or not so it disconnected me due to no data =P

Also. If it works like that, it can be bypassed sorta like GameGuard. How about creating a CEM for WoW and having Warden read from that instead of the actual WoW? OR if its not possible for Warden to read things outside of the program, allocate memory and have it scan that =P
Reply With Quote
(#51)
Old
-Lex is Offline
Banned
Rep Power: 0
Reputation: 1056
-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of-Lex has much to be proud of
 
Posts: 960
Join Date: Jun 2007
Location: Hyboria
4 Weeks Ago

Quote:
Originally Posted by kynox View Post
Just so you guys are aware, warden is scanning this memory offset, and the wallclimbing offset. Any editing of these on live will result in a ban.
Quote:
i got banned >:X
Quote:
This will get you banned
Do you guys pay any attention at all when those few around here, who ACTUALLY know what they're talking about says something?
Reply With Quote
(#52)
Old
Cypher's Avatar
Cypher is Offline
Kynox's Pimp OMGRECURSION
Legendary User
Rep Power: 8
Reputation: 781
Cypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to beholdCypher is a splendid one to behold
 
Posts: 1,799
Join Date: Apr 2006
Location: Hiding in ur warden
3 Weeks Ago

Quote:
Originally Posted by -Lex View Post
Do you guys pay any attention at all when those few around here, who ACTUALLY know what they're talking about says something?

Protip: Noone around here listens, we just like talking to ourselves.




Yes my old nick was Chazwazza, stop asking >.<
Reply With Quote
Reply

Donate to remove ads.

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327