Guest User

Untitled

a guest
May 21st, 2018
74
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.86 KB | None | 0 0
  1. 00945910
  2.  
  3. 016c63c4 -> +38 -> +0 -> +c -> value
  4. replace vtab at +0
  5.  
  6.  
  7. DWORD value = *(DWORD*)0x016c63c4;
  8. DWORD classy= *(DWORD*)(value + 0x38);
  9. *classy = fakeVT;
  10.  
  11.  
  12. mem found at 008073b6
  13. \x3B\xC3\x74\x00\x8B\x48\x00\x3B
  14. xxx?xx?x
  15. -0x4
  16.  
  17.  
  18. 008073B6 A1 C4636C01 MOV EAX,[16C63C4]
  19. 008073BB 3BC3 CMP EAX,EBX
  20. 008073BD 74 0E JE SHORT SC2.008073CD
  21. 008073BF 8B48 38 MOV ECX,[EAX+38]
  22. 008073C2 3BCB CMP ECX,EBX
  23. 008073C4 74 07 JE SHORT SC2.008073CD
  24. 008073C6 8B01 MOV EAX,[ECX] ; SC2.01451530
  25. 008073C8 8B50 0C MOV EDX,[EAX+C] ; SC2.00978ED0
  26. 008073CB FFD2 CALL NEAR EDX ; SC2.00978ED0
  27.  
  28.  
  29. function is 00978ed0
Add Comment
Please, Sign In to add comment