MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides

Homepage Register FAQ Members Mark Forums Read Advertise Marketplace FPSowned


Go Back   MMOwned - World of Warcraft Exploits, Hacks, Bots and Guides > World of Warcraft > Bots and Programs > WoW Memory Editing
Reload this Page Attempting to make Glider restarter with ReadProcessMemory
WoW Memory Editing WoW Memory Editing for learning purposes only.

Reply
 
LinkBack Thread Tools
Attempting to make Glider restarter with ReadProcessMemory
(#1)
Old
airlinedev is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 0
Reputation: 1
airlinedev is an unknown quantity at this point
 
Posts: 3
Join Date: May 2008
Attempting to make Glider restarter with ReadProcessMemory - 05-13-2008

Hello,

I'm currently in need of a program that will restart Glider when it stops. In my situation, I am gliding Alterac Valley with a nice PPather task file. But as any of you Glider Eliter's out there know, Glider stops running when it changes zone. So, I thought I make a program that would click the Start Glide button everytime it enters or leave AV. I could just have it click the Start Glide button every 10 seconds but then I'd run into the problem where it will shrink the game and then enlarge it when it's not stopped. I'm trying to find out when it joins and leaves AV by reading the process memory.

I've been using Delphi for a few years and was pleased when I found Delphi sniplets here on the forums. However, I don't like how some people use libraries in order to port their program to an OS that doesn't have Windows NT API files.

To click the button, I'd simpy do the following:

Code:
SetCursorPos(X,Y); //X,Y = coordinates of the Start Glide button
Mouse_Event(MOUSEEVENTF_LEFTDOWN, 0, 0, 0, 0);
Sleep(150);
Mouse_Event(MOUSEEVENTF_LEFTUP, 0, 0, 0, 0);
Reading the memory is where I'm having troubles. After analyzing WoW.exe with IDA really quickly, I've gotten the following value for TlsIndex: $E8AA84

I started off by trying to just read one chunk of memory (size 1000), but got a return read value of 0.

Code:
I have a standard form with a memo box renamed to "status" and a button named Button1 with the following OnClick code:

procedure TForm1.Button1Click(Sender: TObject);
var
  processid,threadid: integer;
  buf: pchar;
  hwindow, wname: integer;
  read: cardinal;
begin
  wname := FindWindow(nil, 'World of Warcraft');
  if wname = 0 then begin
    status.Lines.Add('Failed to get window handle.');
    exit;
  end;
  status.lines.add('Window handle: ' + inttostr(wname));
  threadid := getwindowthreadprocessid(wname, @processid);
  hwindow := openprocess(PROCESS_ALL_ACCESS, false, processid);
  if processid = 0 then begin
    status.lines.Add('Failed to get process id.');
    exit;
  end;
  status.lines.add('PID: ' + inttostr(processid));
  status.lines.add('beginning to read memory...');
  getmem(buf, 1000);
  readprocessmemory(processid, Pointer($E8AA84), buf, 1000, read); //note the TLSINDEX
  status.lines.Add(inttostr(read));
  freemem(buf);
  closehandle(hwindow);
end;
Can anyone with experience please help me out? Also, I hope this code becomes useful for anyone else in my situation. If I get it working, given that someone provides me with help of knowing when I leave/join AV, I will make the complete source/program available to all. Thank you in advanced.
Reply With Quote

Donate to remove ads.
(#2)
Old
=sinister='s Avatar
=sinister= is Offline
Contributor
Rep Power: 3
Reputation: 142
=sinister= will become famous soon enough=sinister= will become famous soon enough
 
Posts: 219
Join Date: Jun 2006
Location: Texas
05-13-2008

Glidermonkey...............
Reply With Quote
(#3)
Old
airlinedev is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 0
Reputation: 1
airlinedev is an unknown quantity at this point
 
Posts: 3
Join Date: May 2008
05-13-2008

no, glidermonkey crashes way too often. and, i'm making this a project of mine so i don't want to use any other premade glider restarters.
Reply With Quote
(#4)
Old
laurens is Offline
Site n00b.. (A leecher if I've been here for more than a month and can't earn 5 rep)
Rep Power: 2
Reputation: 1
laurens is an unknown quantity at this point
 
Posts: 15
Join Date: Nov 2006
05-24-2008

kill the process?

thatprocess.CloseMainWindow();

this could work though
Reply With Quote
Reply

Donate to remove ads.

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341