死亡之夜吧 关注:4,853贴子:25,529

[CE]单机死亡之夜1.1.1.13

只看楼主收藏回复



IP属地:广西1楼2024-11-05 21:15回复


    IP属地:广西2楼2024-11-05 21:16
    回复
      { Game : NOTD
      Version:
      Date : 2024-10-27
      Author : Admin
      建筑不掉血
      }
      define(address,"LF-Win64-Shipping.exe"+47C2F90)
      define(bytes,F3 0F 5C C6 4C 89 BC 24 F0 00 00 00)
      [ENABLE]
      //code from here to '[DISABLE]' will be used to enable the cheat
      assert(address,bytes)
      alloc(newmem,$1000,"LF-Win64-Shipping.exe"+47C2F90)
      label(code)
      label(return)
      newmem:
      nop
      mov [rsp+000000F0],r15
      jmp return
      code:
      subss xmm0,xmm6
      mov [rsp+000000F0],r15
      jmp return
      address:
      jmp newmem
      nop 7
      return:
      [DISABLE]
      //code from here till the end of the code will be used to disable the cheat
      address:
      db bytes
      // subss xmm0,xmm6
      // mov [rsp+000000F0],r15
      dealloc(newmem)
      {
      // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+47C2F90
      LF-Win64-Shipping.exe+47C2F62: E8 F9 30 82 FE - call LF-Win64-Shipping.exe+2FE6060
      LF-Win64-Shipping.exe+47C2F67: 84 C0 - test al,al
      LF-Win64-Shipping.exe+47C2F69: 75 10 - jne LF-Win64-Shipping.exe+47C2F7B
      LF-Win64-Shipping.exe+47C2F6B: 48 8B CE - mov rcx,rsi
      LF-Win64-Shipping.exe+47C2F6E: E8 2D 31 82 FE - call LF-Win64-Shipping.exe+2FE60A0
      LF-Win64-Shipping.exe+47C2F73: 84 C0 - test al,al
      LF-Win64-Shipping.exe+47C2F75: 0F 84 AE 02 00 00 - je LF-Win64-Shipping.exe+47C3229
      LF-Win64-Shipping.exe+47C2F7B: 80 BE FE 03 00 00 00 - cmp byte ptr [rsi+000003FE],00
      LF-Win64-Shipping.exe+47C2F82: 0F 85 A1 02 00 00 - jne LF-Win64-Shipping.exe+47C3229
      LF-Win64-Shipping.exe+47C2F88: F3 0F 10 86 4C 05 00 00 - movss xmm0,[rsi+0000054C]
      // ---------- INJECTING HERE ----------
      LF-Win64-Shipping.exe+47C2F90: F3 0F 5C C6 - subss xmm0,xmm6
      // ---------- DONE INJECTING ----------
      LF-Win64-Shipping.exe+47C2F94: 4C 89 BC 24 F0 00 00 00 - mov [rsp+000000F0],r15
      LF-Win64-Shipping.exe+47C2F9C: F3 0F 11 86 4C 05 00 00 - movss [rsi+0000054C],xmm0
      LF-Win64-Shipping.exe+47C2FA4: 80 BE 51 01 00 00 02 - cmp byte ptr [rsi+00000151],02
      LF-Win64-Shipping.exe+47C2FAB: 75 0C - jne LF-Win64-Shipping.exe+47C2FB9
      LF-Win64-Shipping.exe+47C2FAD: 48 8B 06 - mov rax,[rsi]
      LF-Win64-Shipping.exe+47C2FB0: 48 8B CE - mov rcx,rsi
      LF-Win64-Shipping.exe+47C2FB3: FF 90 C0 06 00 00 - call qword ptr [rax+000006C0]
      LF-Win64-Shipping.exe+47C2FB9: F3 0F 10 86 4C 05 00 00 - movss xmm0,[rsi+0000054C]
      LF-Win64-Shipping.exe+47C2FC1: F3 0F 5E 86 88 04 00 00 - divss xmm0,[rsi+00000488]
      LF-Win64-Shipping.exe+47C2FC9: 0F 2F 05 54 CB AD 01 - comiss xmm0,[LF-Win64-Shipping.exe+629FB24]
      }


      IP属地:广西3楼2024-11-05 21:18
      回复
        { Game : NOTD
        Version:
        Date : 2024-10-27
        Author : Admin
        攻击次数
        }
        define(address,"LF-Win64-Shipping.exe"+47E60C7)
        define(bytes,8B 81 F8 08 00 00)
        [ENABLE]
        //code from here to '[DISABLE]' will be used to enable the cheat
        assert(address,bytes)
        alloc(newmem,$1000,"LF-Win64-Shipping.exe"+47E60C7)
        label(code)
        label(return)
        newmem:
        cmp [rcx+000008F8],0
        jg code
        mov [rcx+000008F8],10
        code:
        mov eax,[rcx+000008F8]
        jmp return
        address:
        jmp newmem
        nop
        return:
        [DISABLE]
        //code from here till the end of the code will be used to disable the cheat
        address:
        db bytes
        // mov eax,[rcx+000008F8]
        dealloc(newmem)
        {
        // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+47E60C7
        LF-Win64-Shipping.exe+47E60B7: C3 - ret
        LF-Win64-Shipping.exe+47E60B8: CC - int 3
        LF-Win64-Shipping.exe+47E60B9: CC - int 3
        LF-Win64-Shipping.exe+47E60BA: CC - int 3
        LF-Win64-Shipping.exe+47E60BB: CC - int 3
        LF-Win64-Shipping.exe+47E60BC: CC - int 3
        LF-Win64-Shipping.exe+47E60BD: CC - int 3
        LF-Win64-Shipping.exe+47E60BE: CC - int 3
        LF-Win64-Shipping.exe+47E60BF: CC - int 3
        LF-Win64-Shipping.exe+47E60C0: 80 B9 90 09 00 00 00 - cmp byte ptr [rcx+00000990],00
        // ---------- INJECTING HERE ----------
        LF-Win64-Shipping.exe+47E60C7: 8B 81 F8 08 00 00 - mov eax,[rcx+000008F8]
        // ---------- DONE INJECTING ----------
        LF-Win64-Shipping.exe+47E60CD: 74 12 - je LF-Win64-Shipping.exe+47E60E1
        LF-Win64-Shipping.exe+47E60CF: 85 C0 - test eax,eax
        LF-Win64-Shipping.exe+47E60D1: 75 0B - jne LF-Win64-Shipping.exe+47E60DE
        LF-Win64-Shipping.exe+47E60D3: 38 81 F1 09 00 00 - cmp [rcx+000009F1],al
        LF-Win64-Shipping.exe+47E60D9: 75 03 - jne LF-Win64-Shipping.exe+47E60DE
        LF-Win64-Shipping.exe+47E60DB: B0 01 - mov al,01
        LF-Win64-Shipping.exe+47E60DD: C3 - ret
        LF-Win64-Shipping.exe+47E60DE: 32 C0 - xor al,al
        LF-Win64-Shipping.exe+47E60E0: C3 - ret
        LF-Win64-Shipping.exe+47E60E1: 85 C0 - test eax,eax
        }


        IP属地:广西4楼2024-11-05 21:19
        回复
          { Game : NOTD
          Version:
          Date : 2024-10-27
          Author : Admin
          物品栏 不减物品 [吃的不算]
          }
          define(address,"LF-Win64-Shipping.exe"+4819F5B)
          define(bytes,41 2B C0 89 87 E8 00 00 00)
          [ENABLE]
          //code from here to '[DISABLE]' will be used to enable the cheat
          assert(address,bytes)
          alloc(newmem,$1000,"LF-Win64-Shipping.exe"+4819F5B)
          label(code)
          label(return)
          newmem:
          nop
          mov [rdi+000000E8],eax
          jmp return
          code:
          sub eax,r8d
          mov [rdi+000000E8],eax
          jmp return
          address:
          jmp newmem
          nop 4
          return:
          [DISABLE]
          //code from here till the end of the code will be used to disable the cheat
          address:
          db bytes
          // sub eax,r8d
          // mov [rdi+000000E8],eax
          dealloc(newmem)
          {
          // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+4819F5B
          LF-Win64-Shipping.exe+4819F36: 7D 1C - jnl LF-Win64-Shipping.exe+4819F54
          LF-Win64-Shipping.exe+4819F38: 4D 8B C5 - mov r8,r13
          LF-Win64-Shipping.exe+4819F3B: 49 8B FC - mov rdi,r12
          LF-Win64-Shipping.exe+4819F3E: 48 FF C1 - inc rcx
          LF-Win64-Shipping.exe+4819F41: 48 81 C2 00 01 00 00 - add rdx,00000100
          LF-Win64-Shipping.exe+4819F48: 49 3B CE - cmp rcx,r14
          LF-Win64-Shipping.exe+4819F4B: 7D 7A - jnl LF-Win64-Shipping.exe+4819FC7
          LF-Win64-Shipping.exe+4819F4D: 48 8B 44 24 30 - mov rax,[rsp+30]
          LF-Win64-Shipping.exe+4819F52: EB AC - jmp LF-Win64-Shipping.exe+4819F00
          LF-Win64-Shipping.exe+4819F54: 48 8B 8D 78 01 00 00 - mov rcx,[rbp+00000178]
          // ---------- INJECTING HERE ----------
          LF-Win64-Shipping.exe+4819F5B: 41 2B C0 - sub eax,r8d
          // ---------- DONE INJECTING ----------
          LF-Win64-Shipping.exe+4819F5E: 89 87 E8 00 00 00 - mov [rdi+000000E8],eax
          LF-Win64-Shipping.exe+4819F64: 48 8B 01 - mov rax,[rcx]
          LF-Win64-Shipping.exe+4819F67: FF 90 98 00 00 00 - call qword ptr [rax+00000098]
          LF-Win64-Shipping.exe+4819F6D: 48 8B C8 - mov rcx,rax
          LF-Win64-Shipping.exe+4819F70: 48 8B D7 - mov rdx,rdi
          LF-Win64-Shipping.exe+4819F73: E8 38 69 B6 FF - call LF-Win64-Shipping.exe+43808B0
          LF-Win64-Shipping.exe+4819F78: 39 9F E8 00 00 00 - cmp [rdi+000000E8],ebx
          LF-Win64-Shipping.exe+4819F7E: 7F 40 - jg LF-Win64-Shipping.exe+4819FC0
          LF-Win64-Shipping.exe+4819F80: 48 8D 4C 24 40 - lea rcx,[rsp+40]
          LF-Win64-Shipping.exe+4819F85: E8 96 2F B2 FF - call LF-Win64-Shipping.exe+433CF20
          }


          IP属地:广西5楼2024-11-05 21:19
          回复
            { Game : NOTD
            Version:
            Date : 2024-10-27
            Author : Admin
            生命 活力
            }
            define(address,"LF-Win64-Shipping.exe"+45F1B5E)
            define(bytes,49 8B 80 00 01 00 00)
            [ENABLE]
            //code from here to '[DISABLE]' will be used to enable the cheat
            assert(address,bytes)
            alloc(newmem,$1000,"LF-Win64-Shipping.exe"+45F1B5E)
            label(code)
            label(return)
            //以下人造指针1
            //alloc(zhi_02,8) // [rax] 人造指针1(64位需要8字节)
            //registersymbol(zhi_02) //人造指针,存放??地址
            newmem:
            mov [r8+00000110],(float)400.0
            mov [r8+00000114],(float)200.0
            mov rax,[r8+00000100]
            mov [rax+c],(float)200.0
            //mov [zhi_02],rcx
            code:
            mov rax,[r8+00000100]
            jmp return
            address:
            jmp newmem
            nop 2
            return:
            [DISABLE]
            //code from here till the end of the code will be used to disable the cheat
            address:
            db bytes
            // mov rax,[r8+00000100]
            dealloc(newmem)
            {
            // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+45F1B5E
            LF-Win64-Shipping.exe+45F1B40: C3 - ret
            LF-Win64-Shipping.exe+45F1B41: 80 FA 01 - cmp dl,01
            LF-Win64-Shipping.exe+45F1B44: 75 09 - jne LF-Win64-Shipping.exe+45F1B4F
            LF-Win64-Shipping.exe+45F1B46: F3 0F 10 81 10 01 00 00 - movss xmm0,[rcx+00000110]
            LF-Win64-Shipping.exe+45F1B4E: C3 - ret
            LF-Win64-Shipping.exe+45F1B4F: 0F B6 C2 - movzx eax,dl
            LF-Win64-Shipping.exe+45F1B52: 3B 81 08 01 00 00 - cmp eax,[rcx+00000108]
            LF-Win64-Shipping.exe+45F1B58: 7C 04 - jl LF-Win64-Shipping.exe+45F1B5E
            LF-Win64-Shipping.exe+45F1B5A: 0F 57 C0 - xorps xmm0,xmm0
            LF-Win64-Shipping.exe+45F1B5D: C3 - ret
            // ---------- INJECTING HERE ----------
            LF-Win64-Shipping.exe+45F1B5E: 49 8B 80 00 01 00 00 - mov rax,[r8+00000100]
            // ---------- DONE INJECTING ----------
            LF-Win64-Shipping.exe+45F1B65: 0F B6 CA - movzx ecx,dl
            LF-Win64-Shipping.exe+45F1B68: E9 93 E4 9D FB - jmp 7FF7C93E0000
            LF-Win64-Shipping.exe+45F1B6D: C3 - ret
            LF-Win64-Shipping.exe+45F1B6E: CC - int 3
            LF-Win64-Shipping.exe+45F1B6F: CC - int 3
            LF-Win64-Shipping.exe+45F1B70: 40 56 - push rsi
            LF-Win64-Shipping.exe+45F1B72: 48 83 EC 30 - sub rsp,30
            LF-Win64-Shipping.exe+45F1B76: 0F B6 F2 - movzx esi,dl
            LF-Win64-Shipping.exe+45F1B79: 3B B1 E8 00 00 00 - cmp esi,[rcx+000000E8]
            LF-Win64-Shipping.exe+45F1B7F: 0F 8D 8D 00 00 00 - jnl LF-Win64-Shipping.exe+45F1C12
            }


            IP属地:广西6楼2024-11-05 21:20
            回复
              { Game : NOTD
              Version:
              Date : 2024-11-05
              Author : Admin
              武器耐久
              }
              define(address,"LF-Win64-Shipping.exe"+46A09F3)
              define(bytes,F3 0F 2C 42 70)
              [ENABLE]
              //code from here to '[DISABLE]' will be used to enable the cheat
              assert(address,bytes)
              alloc(newmem,$1000,"LF-Win64-Shipping.exe"+46A09F3)
              label(code)
              label(return)
              newmem:
              mov [rdx+70],(float)2000//武器耐久
              code:
              cvttss2si eax,[rdx+70]
              jmp return
              address:
              jmp newmem
              return:
              [DISABLE]
              //code from here till the end of the code will be used to disable the cheat
              address:
              db bytes
              // cvttss2si eax,[rdx+70]
              dealloc(newmem)
              {
              // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+46A09F3
              LF-Win64-Shipping.exe+46A09DB: 33 42 0C - xor eax,[rdx+0C]
              LF-Win64-Shipping.exe+46A09DE: 0B C8 - or ecx,eax
              LF-Win64-Shipping.exe+46A09E0: 8B C3 - mov eax,ebx
              LF-Win64-Shipping.exe+46A09E2: 33 02 - xor eax,[rdx]
              LF-Win64-Shipping.exe+46A09E4: 0B C8 - or ecx,eax
              LF-Win64-Shipping.exe+46A09E6: 74 0B - je LF-Win64-Shipping.exe+46A09F3
              LF-Win64-Shipping.exe+46A09E8: 8B 42 78 - mov eax,[rdx+78]
              LF-Win64-Shipping.exe+46A09EB: 83 F8 FF - cmp eax,-01
              LF-Win64-Shipping.exe+46A09EE: 75 D0 - jne LF-Win64-Shipping.exe+46A09C0
              LF-Win64-Shipping.exe+46A09F0: 48 8B D7 - mov rdx,rdi
              // ---------- INJECTING HERE ----------
              LF-Win64-Shipping.exe+46A09F3: F3 0F 2C 42 70 - cvttss2si eax,[rdx+70]
              // ---------- DONE INJECTING ----------
              LF-Win64-Shipping.exe+46A09F8: EB 0E - jmp LF-Win64-Shipping.exe+46A0A08
              LF-Win64-Shipping.exe+46A09FA: 33 FF - xor edi,edi
              LF-Win64-Shipping.exe+46A09FC: B8 FF FF FF 7F - mov eax,7FFFFFFF
              LF-Win64-Shipping.exe+46A0A01: 80 7D 0C 01 - cmp byte ptr [rbp+0C],01
              LF-Win64-Shipping.exe+46A0A05: 0F 46 C7 - cmovbe eax,edi
              LF-Win64-Shipping.exe+46A0A08: 48 8B 5C 24 50 - mov rbx,[rsp+50]
              LF-Win64-Shipping.exe+46A0A0D: 48 8B 6C 24 58 - mov rbp,[rsp+58]
              LF-Win64-Shipping.exe+46A0A12: 48 8B 74 24 60 - mov rsi,[rsp+60]
              LF-Win64-Shipping.exe+46A0A17: 48 83 C4 30 - add rsp,30
              LF-Win64-Shipping.exe+46A0A1B: 41 5F - pop r15
              }


              IP属地:广西7楼2024-11-05 21:21
              回复
                { Game : NOTD
                Version:
                Date : 2024-11-05
                Author : Admin
                装备枪子弹
                }
                define(address,"LF-Win64-Shipping.exe"+45D5720)
                define(bytes,41 89 46 28 45 89 6E 2C)
                [ENABLE]
                //code from here to '[DISABLE]' will be used to enable the cheat
                assert(address,bytes)
                alloc(newmem,$1000,"LF-Win64-Shipping.exe"+45D5720)
                label(code)
                label(return)
                newmem:
                mov [r14+28],#5//装备枪子弹
                code:
                //mov [r14+28],eax
                mov [r14+2C],r13d
                jmp return
                address:
                jmp newmem
                nop 3
                return:
                [DISABLE]
                //code from here till the end of the code will be used to disable the cheat
                address:
                db bytes
                // mov [r14+28],eax
                // mov [r14+2C],r13d
                dealloc(newmem)
                {
                // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+45D5720
                LF-Win64-Shipping.exe+45D56F8: 74 30 - je LF-Win64-Shipping.exe+45D572A
                LF-Win64-Shipping.exe+45D56FA: 49 8B 4C 24 08 - mov rcx,[r12+08]
                LF-Win64-Shipping.exe+45D56FF: 49 8B 04 24 - mov rax,[r12]
                LF-Win64-Shipping.exe+45D5703: 0F 10 00 - movups xmm0,[rax]
                LF-Win64-Shipping.exe+45D5706: 41 0F 11 06 - movups [r14],xmm0
                LF-Win64-Shipping.exe+45D570A: 0F 10 01 - movups xmm0,[rcx]
                LF-Win64-Shipping.exe+45D570D: 41 0F 11 46 10 - movups [r14+10],xmm0
                LF-Win64-Shipping.exe+45D5712: F2 0F 10 49 10 - movsd xmm1,[rcx+10]
                LF-Win64-Shipping.exe+45D5717: F2 41 0F 11 4E 20 - movsd [r14+20],xmm1
                LF-Win64-Shipping.exe+45D571D: 8B 41 18 - mov eax,[rcx+18]
                // ---------- INJECTING HERE ----------
                LF-Win64-Shipping.exe+45D5720: 41 89 46 28 - mov [r14+28],eax
                // ---------- DONE INJECTING ----------
                LF-Win64-Shipping.exe+45D5724: 45 89 6E 2C - mov [r14+2C],r13d
                LF-Win64-Shipping.exe+45D5728: EB 03 - jmp LF-Win64-Shipping.exe+45D572D
                LF-Win64-Shipping.exe+45D572A: 45 33 F6 - xor r14d,r14d
                LF-Win64-Shipping.exe+45D572D: BA 10 00 00 00 - mov edx,00000010
                LF-Win64-Shipping.exe+45D5732: 49 8B CE - mov rcx,r14
                LF-Win64-Shipping.exe+45D5735: E8 56 6C 5B FC - call LF-Win64-Shipping.exe+B8C390
                LF-Win64-Shipping.exe+45D573A: 8B 4B 08 - mov ecx,[rbx+08]
                LF-Win64-Shipping.exe+45D573D: 4C 8B C8 - mov r9,rax
                LF-Win64-Shipping.exe+45D5740: 2B 4B 34 - sub ecx,[rbx+34]
                LF-Win64-Shipping.exe+45D5743: 44 8B E7 - mov r12d,edi
                }


                IP属地:广西8楼2024-11-05 21:22
                回复
                  { Game : NOTD
                  Version:
                  Date : 2024-11-05
                  Author : Admin
                  自动加油
                  }
                  define(address,"LF-Win64-Shipping.exe"+46875CA)
                  define(bytes,8B 87 E8 00 00 00)
                  [ENABLE]
                  //code from here to '[DISABLE]' will be used to enable the cheat
                  assert(address,bytes)
                  alloc(newmem,$1000,"LF-Win64-Shipping.exe"+46875CA)
                  label(code)
                  label(return)
                  newmem:
                  cmp [rdi+000000E8],0//要加1的油
                  je code
                  mov [rdi+000000E8],190//自动加油
                  code:
                  mov eax,[rdi+000000E8]
                  jmp return
                  address:
                  jmp newmem
                  nop
                  return:
                  [DISABLE]
                  //code from here till the end of the code will be used to disable the cheat
                  address:
                  db bytes
                  // mov eax,[rdi+000000E8]
                  dealloc(newmem)
                  {
                  // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+46875CA
                  LF-Win64-Shipping.exe+46875A5: 4C 03 26 - add r12,[rsi]
                  LF-Win64-Shipping.exe+46875A8: 74 51 - je LF-Win64-Shipping.exe+46875FB
                  LF-Win64-Shipping.exe+46875AA: 49 8B 45 00 - mov rax,[r13+00]
                  LF-Win64-Shipping.exe+46875AE: 48 89 7C 24 78 - mov [rsp+78],rdi
                  LF-Win64-Shipping.exe+46875B3: 49 8B 7D 08 - mov rdi,[r13+08]
                  LF-Win64-Shipping.exe+46875B7: 48 8B D7 - mov rdx,rdi
                  LF-Win64-Shipping.exe+46875BA: 8B 08 - mov ecx,[rax]
                  LF-Win64-Shipping.exe+46875BC: 41 89 0C 24 - mov [r12],ecx
                  LF-Win64-Shipping.exe+46875C0: 49 8D 4C 24 08 - lea rcx,[r12+08]
                  LF-Win64-Shipping.exe+46875C5: E8 36 58 CB FF - call LF-Win64-Shipping.exe+433CE00
                  // ---------- INJECTING HERE ----------
                  LF-Win64-Shipping.exe+46875CA: 8B 87 E8 00 00 00 - mov eax,[rdi+000000E8]
                  // ---------- DONE INJECTING ----------
                  LF-Win64-Shipping.exe+46875D0: 41 89 84 24 F0 00 00 00 - mov [r12+000000F0],eax
                  LF-Win64-Shipping.exe+46875D8: 0F 10 87 EC 00 00 00 - movups xmm0,[rdi+000000EC]
                  LF-Win64-Shipping.exe+46875DF: 48 8B 7C 24 78 - mov rdi,[rsp+78]
                  LF-Win64-Shipping.exe+46875E4: 41 0F 11 84 24 F4 00 00 00 - movups [r12+000000F4],xmm0
                  LF-Win64-Shipping.exe+46875ED: 41 C7 84 24 08 01 00 00 FF FF FF FF - mov [r12+00000108],FFFFFFFF
                  LF-Win64-Shipping.exe+46875F9: EB 03 - jmp LF-Win64-Shipping.exe+46875FE
                  LF-Win64-Shipping.exe+46875FB: 45 33 E4 - xor r12d,r12d
                  LF-Win64-Shipping.exe+46875FE: 41 8B 1C 24 - mov ebx,[r12]
                  LF-Win64-Shipping.exe+4687602: 4C 8D 4C 24 70 - lea r9,[rsp+70]
                  LF-Win64-Shipping.exe+4687607: 48 8B 84 24 88 00 00 00 - mov rax,[rsp+00000088]
                  }


                  IP属地:广西9楼2024-11-05 21:23
                  回复
                    { Game : NOTD
                    Version:
                    Date : 2024-11-05
                    Author : Admin
                    车HP
                    }
                    define(address,"LF-Win64-Shipping.exe"+47F89F7)
                    define(bytes,F3 0F 10 83 F0 08 00 00)
                    [ENABLE]
                    //code from here to '[DISABLE]' will be used to enable the cheat
                    assert(address,bytes)
                    alloc(newmem,$1000,"LF-Win64-Shipping.exe"+47F89F7)
                    label(code)
                    label(return)
                    newmem:
                    mov [rbx+000008F0],(float)5000.0//车HP
                    code:
                    movss xmm0,[rbx+000008F0]
                    jmp return
                    address:
                    jmp newmem
                    nop 3
                    return:
                    [DISABLE]
                    //code from here till the end of the code will be used to disable the cheat
                    address:
                    db bytes
                    // movss xmm0,[rbx+000008F0]
                    dealloc(newmem)
                    {
                    // ORIGINAL CODE - INJECTION POINT: LF-Win64-Shipping.exe+47F89F7
                    LF-Win64-Shipping.exe+47F89C4: 0F 10 44 24 58 - movups xmm0,[rsp+58]
                    LF-Win64-Shipping.exe+47F89C9: 48 8B CB - mov rcx,rbx
                    LF-Win64-Shipping.exe+47F89CC: F2 0F 10 4C 24 68 - movsd xmm1,[rsp+68]
                    LF-Win64-Shipping.exe+47F89D2: 0F 11 83 C0 0B 00 00 - movups [rbx+00000BC0],xmm0
                    LF-Win64-Shipping.exe+47F89D9: F2 0F 11 8B D0 0B 00 00 - movsd [rbx+00000BD0],xmm1
                    LF-Win64-Shipping.exe+47F89E1: E8 BA 35 F0 FF - call LF-Win64-Shipping.exe+46FBFA0
                    LF-Win64-Shipping.exe+47F89E6: 84 C0 - test al,al
                    LF-Win64-Shipping.exe+47F89E8: 0F 84 82 00 00 00 - je LF-Win64-Shipping.exe+47F8A70
                    LF-Win64-Shipping.exe+47F89EE: 40 38 AB 58 09 00 00 - cmp [rbx+00000958],bpl
                    LF-Win64-Shipping.exe+47F89F5: 75 79 - jne LF-Win64-Shipping.exe+47F8A70
                    // ---------- INJECTING HERE ----------
                    LF-Win64-Shipping.exe+47F89F7: F3 0F 10 83 F0 08 00 00 - movss xmm0,[rbx+000008F0]
                    // ---------- DONE INJECTING ----------
                    LF-Win64-Shipping.exe+47F89FF: F3 0F 5C C6 - subss xmm0,xmm6
                    LF-Win64-Shipping.exe+47F8A03: 0F 2F C7 - comiss xmm0,xmm7
                    LF-Win64-Shipping.exe+47F8A06: F3 0F 11 83 F0 08 00 00 - movss [rbx+000008F0],xmm0
                    LF-Win64-Shipping.exe+47F8A0E: 77 48 - ja LF-Win64-Shipping.exe+47F8A58
                    LF-Win64-Shipping.exe+47F8A10: 48 85 F6 - test rsi,rsi
                    LF-Win64-Shipping.exe+47F8A13: 74 35 - je LF-Win64-Shipping.exe+47F8A4A
                    LF-Win64-Shipping.exe+47F8A15: 49 8B 3E - mov rdi,[r14]
                    LF-Win64-Shipping.exe+47F8A18: 48 85 FF - test rdi,rdi
                    LF-Win64-Shipping.exe+47F8A1B: 74 2D - je LF-Win64-Shipping.exe+47F8A4A
                    LF-Win64-Shipping.exe+47F8A1D: E8 CE 7A B3 FF - call LF-Win64-Shipping.exe+43304F0
                    }


                    IP属地:广西10楼2024-11-05 21:24
                    回复
                      牛逼,继续,世界时间静止,跳转到指定日期时间,移动加速度,空中无限连跳都安排上啊。


                      IP属地:湖北11楼2024-11-06 06:25
                      收起回复

                        有一个不是很对齐,
                        大改装甲装甲车


                        IP属地:广西12楼2024-11-07 17:32
                        回复


                          IP属地:广西13楼2024-11-07 17:52
                          回复


                            IP属地:广西14楼2024-11-08 02:28
                            回复
                              { 枪子弹 }
                              define(address,"LF-Win64-Shipping.exe"+4611581)
                              define(bytes,66 42 0F 6E 74 36 28)
                              [ENABLE]
                              assert(address,bytes)
                              alloc(newmem,$1000,"LF-Win64-Shipping.exe"+4611581)
                              label(code)
                              label(return)
                              newmem:
                              mov [rsi+r14+28],a//修改数量
                              code:
                              movd xmm6,[rsi+r14+28]
                              jmp return
                              address:
                              jmp newmem
                              nop 2
                              return:
                              [DISABLE]
                              address:
                              db bytes
                              dealloc(newmem)


                              IP属地:广西15楼2024-11-08 02:33
                              回复