btb 發表於 2020-11-4 14:26:00

TWMS v229.4 CRC 無限Buff(Infinite Buff)

//TWMS v229.4 CRC 無限Buff(Infinite Buff)
//Infinite Buff

alloc(hook,64)
alloc(Original,64)
label(Return)
02DDD3DF:
jmp hook
Return:

hook:
cmp eax,04
jne Original
nop
nop
nop
nop
nop
nop
mov eax,00001000
jmp 02DDEA4E

Original:
cmp eax,000001C4
jmp Return


02DDD3DF:
cmp eax,000001C4

dealloc(hook)

btb 發表於 2020-11-4 14:26:08

//TWMS v229.4 CRC 無限buff(簡化版)
這個封包派發call裏面02DDD360的參數1是0x66時是伺服器要求客戶端檢查新增的buff,0x67是要求客戶端刷新過期的buff,沒辦法在這裏精確控制某些buff,在撿取到連擊球之後會斷線
簡化版本:

registersymbol(buff)
alloc(buff,64)
alloc(Original,64)

02DDD360:
jmp buff

buff:
cmp  ,67
jne Original
ret 8


Original:
db 55 8b ec 6a ff
jmp 02DDD360+5


02DDD360:
db 55 8b ec 6a ff
dealloc(buff)
頁: [1]
查看完整版本: TWMS v229.4 CRC 無限Buff(Infinite Buff)