Jump to content

Learn how to hack games with IDA, CodeInject and HooKfunction (with example!)


132 posts in this topic

Recommended Posts

Updated (edited)
Hello there:)
Today I want to tell you about Code Inject and MSHook Hacking.
I will explain with a practical example for clarity!
I thank this community and leave this guide. 
Thank you!
 
✔Requirements
Spoiler
IDA PRO
Knowledge about C++ 
 
✔Binary
Spoiler
1.Add this repo http://cydia.iphonecake.com/
2.Install CrackerXI.
3.Turn on all in Settings.
4.Slect app which you want to get binary in Applist.
5.It will save to /var/mobile/Documents/CrackerXI
 
✔Note about Tweak.xm
Spoiler
The latest version of Theos uses Tweak.x instead of Tweak.xm.
These differences are explained at this page:
This can cause errors when compiling code found on the net. (In my case when compiling the code for PrefBundle)
So follow this:
1.Change name from Tweak.x to Tweak.xm
2.Change <ProjectName> _FILES = Tweak.x to <ProjectName> _FILES = Tweak.xm in Makefile.
 
✔ASLR Slide
Spoiler

There is ASLR slide is ARM64 binary, so IDA offset and actual binary offset are shifted by ASLR value.

※You can give IDA offset to vm_WriteData because ASLR considered Automatically in vm_WriteData.h
#import <mach-o/dyld.h>
uint64_t getRealOffset(uint64_t offset){
return _dyld_get_image_vmaddr_slide(0)+offset;
}

✔ARM Insructions

Spoiler

Load

MOV r0, r1 
Move the value of r1 to r0
LDR r0, [r1]
Load from memory r1 to register r0
STR r0, [r1]
Store the value of r0 into r1
Store memory r1 with value of register r0 
 
Branch
Compare previous CMP values
BEQ label
jump to label if values are equal
BNE label
jump to label if values are not equal
etc...
CBZ r0, label
jump to label if r0 is 0
CBNZ r0, label
jump to label if r0 is not 0

 

 
✔CodeInject
Spoiler

Place vm_WriteData.h in your project.

And add this to beginning of the code  
#import <vm_writeData.h>
 
Identify the part to change
1.Change the return value
Look at the processing at the bottom of the function (the part load to X0)
MOV X0, 100
2.Change branch
BEQ X0, label
Change the branch to always jump to any label:
B X0, label (BAL is also ok)
Change the branch to never jump to any label:
NOP
Convert to Hex
1.Load
2.Branch
Enter ARM instruction and copy ARM64 HEX.
Apply Changes
vm_WriteData(0x100000000, 0x00000000);
Change the memory starting from 0x100000000 to 00000000.
 
Ex1:Change instruction to change damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

Ex2:Change branch to change accuracy of weapon

Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

Where should I actually write

Spoiler

It is good to write in %ctor. You can write it like this:

#import <vm_writeData.h>
%ctor {
  vm_WriteData(0x1002B55D8, 0x953E80D2);
}
 
✔MS(Object-C func)
Spoiler

Class name depends on the game Use class name which has applicationDidBecomeActive method!

(Easy to find on Flex)
%hook AppController // class name
-(void)applicationDidBecomeActive:(id)argument { // (type od return value) and method name and (type of argument)
    UIAlertView *alert = [[UIAlertView alloc] initWithTitle:@"test" message:@"Detected App opened!" delegate:nil cancelButtonTitle:@"Continue" otherButtonTitles:nil];
    [alert show];
    return %orig(argument);
}
%end
%orig holds the original function. Since we only want to add processing, we also call the original function.
※You can change the process by changing the argument.
This way is only available for Object-C functions, so if you want to hook a native function you can see in IDA and use MSHook!
 
✔MSHook(Native func)
Spoiler

Import substrate at beginning of code.

#import <substrate.h>
Hook function with offset
MSHookFunction((void *)getRealOffset(0x100000000), (void *)func, (void **)&org_func);
func
func - Function that has a process that you want to overwrite.
org_func - Function that keeps the original processing.
Since MSHookFuntion's void is cast and passed to void type, it is always void.
argument
Be sure to include this pointer first.
 
Ex1:Increase Damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

 

✔NSLog

Spoiler

To check NSLog on a device.

Add Flexing from the BigBoss repository.
You can display the log by pressing and holding three fingers on the application you want to see logs.
It can be used by tapping System Log and enabling it from Setting in the upper right.
NSLog(@"Your Log Text Here");
To display argument values:
%d int
%f float
%c unsigned char
%hi short
 
Ex:Display argument values
Spoiler

You can add it in the function definition that overrides like this.

int getDamage(void* this_, void* UserInfor, unsigned char arg0, float arg1) {
  NSLog(@"getDamage Called! arg0: %c, arg1: %f", arg0, arg1);
  return org_getDamage(this_, UserInfor, arg0, arg1);
}
 
✔Call the native func
 
Ex:Call a function to get user information
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

✔PrefBundle

Spoiler

https://iosgods.com/topic/444-tutorial-how-to-make-a-preference-bundle/

You can learn about PredBundle easily from the link above.
I only mention here how to add icons.
How to add icons
Add icon.png file to <project>/<prefbundl_project>/Resources/
You have to export with these size:
> icon.png - 29×29
[email protected] - 58×58
[email protected] - 87×87
You can export icon in here: https://appiconmaker.co/
 
p.s. A knowledgeable person would think why I don't talk about debuggers. Unfortunately gdb is displayed as BadCPUType in my environment and watch-point does not work properly in lldb.
Here are some great tutorials if you are interested in them:
 
If there are any mistakes please point in reply !
Enjoy :)
Updated by princessXZ
some stuff
  • Like 281
  • Winner 22
  • Thanks 26
  • Haha 6
  • Agree 9
  • Informative 21
Posted
7 hours ago, mafusuke said:
STR r0, [r1]
Load the value of r0 into r1

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Posted
3 hours ago, Ted2 said:

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Thank you! I'll fix that 🙂

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Solo Survivor IO Game v1.0.50.12.01 [ +18 APK MOD ] ADS NO
      Mod APK Game Name: Solo Survivor IO Game
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.fc.monster.survivor.io&hl=en

      🤩 Hack Features

      - ADS NO / Rewards Free
      - Unlimited ADS Tokens
      - Quick Patrol ADS / Claim Unlimited / Coins & Blueprint
      - Hero Unlocked
      - Achievement Claim Unlimited / Gems Get Easy
      - Daily Quest Claim Unlimited / Gems + More
      - Growth Fund Free Active
      - Growth Fund Premium Active
      - Growth Fund Super Active
      - Growth Fund Free / Claim Unlimited / Gems + More
      - Growth Fund Premium / Claim Unlimited / Gems + More
      - Growth Fund Super / Claim Unlimited / Gems + More
      - Battle Pass Free / Claim Unlimited / Gems + More
      Hero Status
      - Never Die
      - DMG / Linked Skill
      Enemy Status
      - ATK 0
      - HP 0
      - DEF 0
      • 0 replies
    • Cooking Diary Restaurant Game v2.48.0 Jailed Cheats +3
      Modded/Hacked App: Cooking Diary® Restaurant Game by MyTona Pte Ltd
      Bundle ID: com.mytonallc.cookingdiary
      iTunes Store Link: https://apps.apple.com/us/app/cooking-diary-restaurant-game/id1214763610?uo=4&at=1010lce4


      Hack Features:
      - Infinite Currencies (Get some)
      - Freeze Boosters


      iOS Hack Download Link: https://iosgods.com/topic/110310-arm64-cooking-diary-restaurant-game-v1160-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 714 replies
    • Chef & Friends: Cooking Game Cheats v1.39.1 +1
      Modded/Hacked App: Chef & Friends: Cooking Game By MYTONA Ltd.
      Bundle ID: com.mytona.cheftales
      iTunes Store Link: https://apps.apple.com/us/app/chef-friends-cooking-game/id1586951898?uo=4


      Hack Features:
      - Infinite Currencies (Hats, Coins, Gems)

      NOTE: May bug out the game so better try on your throw away account first 


      iOS Hack Download Link: https://iosgods.com/topic/178904-chef-friends-cooking-game-cheats-v141-1/
        • Haha
        • Thanks
        • Winner
        • Like
      • 38 replies
    • Pew Pew Slime - Idle RPG v32 Jailed Cheats +2
      Modded/Hacked App: Pew Pew Slime - Idle RPG By X-LEGEND ENTERTAINMENT CO., LTD.
      Bundle ID: com.xlegend.pewpewslime.global
      App Store Link: https://apps.apple.com/us/app/pew-pew-slime-idle-rpg/id6739420338?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - God Mode
      - Multiply Attack

      After in-game press Activate Cheat 1 time, then turn it off. Now you can use, if it not work after you relaunch the game next time, repeat the process

      For Multiply Attack do not set max value ortherwise it will revert back to default value, example max value is 10 set 9.8 or 9.9

       

      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/202589-pew-pew-slime-idle-rpg-v26-jailed-cheats-2/
        • Haha
        • Winner
        • Like
      • 17 replies
    • Avabel Online -Tower of Bonds- v12.5.1 Jailed Cheats +7
      Modded/Hacked App: Avabel Online -Tower of Bonds- By ASOBIMO,Inc.
      Bundle ID: com.asobimo.AvabelOnline
      iTunes Store Link: https://apps.apple.com/us/app/avabel-online-tower-of-bonds/id606800657?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Collision Range - x1 - 10
      - God Mode 
      - Cast Speed Multiplier
      - Charge Speed Multiplier
      - Approach Speed Multiplier
      - No Roll CoolDown
      - No Skills CoolDown

      NOTE: DO NOT BUY VIP FOR JUST THIS CHEAT. THIS IS A TEST VERSION


      iOS Hack Download IPA Link: https://iosgods.com/topic/187184-avabel-online-tower-of-bonds-v1230-jailed-cheats-7/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 119 replies
    • Travel Town - Merge Adventure v2.12.1376 Jailed Cheats +1
      Modded/Hacked App: Travel Town - Merge Adventure By Magmatic Games Ltd
      Bundle ID: io.randomco.travel
      iTunes Store Link: https://apps.apple.com/us/app/travel-town-merge-adventure/id1521236603?uo=4


      Hack Features:
      - Infinite Currencies


      iOS Hack Download Link: https://iosgods.com/topic/148953-travel-town-merge-adventure-v212287-jailed-cheats-1/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 876 replies
    • 1945 - Airplane shooting games v15.20 Jailed Cheats +3
      Modded/Hacked App: 1945 Air Force: Airplane Games By ONESOFT GLOBAL PTE. LTD.
      Bundle ID: com.os.airforce
      App Store Link: https://apps.apple.com/us/app/1945-air-force-airplane-games/id1460632826?uo=4

       


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/Mac/Linux with iTunes installed.


      Hack Features:
      - God Mode
      - One Hit Kill
      - Premium + No Ads


      iOS Hack Download Link: https://iosgods.com/topic/150679-1945-airplane-shooting-games-v1502-jailed-cheats-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 159 replies
    • PewDiePie's Tuber Simulator Cheats (Auto Update) +3
      Modded/Hacked App: PewDiePie's Tuber Simulator By Outerminds Inc.
      Bundle ID: com.outerminds.tubular
      iTunes Store Link: https://apps.apple.com/us/app/pewdiepies-tuber-simulator/id1093190533?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - Infinite Subscriber
      - Infinite Views
      - Infinite Bux

      NOTE: Please complete tutorial first before enabling the hacks otherwise it won't work

      NOTe 2: Please make a youtube video to get some views first (without hack) then before enable infinite views

       

      Non-Jailbroken Hack: https://iosgods.com/topic/86411-pewdiepies-tuber-simulator-v2450-jailed-cheats-3/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/86366-pewdiepies-tuber-simulator-cheats-v2460-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,183 replies
    • Idle Slayer: Pixel AFK RPG (Auto Update) Jailed Cheats +1
      Modded/Hacked App: Idle Slayer: Pixel AFK RPG By Pablo Leban
      Bundle ID: com.PabloLeban.IdleSlayer
      App Store Link: https://apps.apple.com/us/app/idle-slayer-pixel-afk-rpg/id1526599527?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Unlimited Gems (Increase when Use)

       

      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/183803-idle-slayer-pixel-afk-rpg-v645-jailed-cheats-1/
        • Informative
        • Agree
        • Haha
        • Like
      • 29 replies
    • Sword Master Story Cheats v4.164.599 +5
      Modded/Hacked App: Sword Master Story By SuperPlanet corp.
      Bundle ID: com.superplanet.swordmaster
      iTunes Store Link: https://apps.apple.com/us/app/sword-master-story/id1521447065?uo=4


      Hack Features:
      - Custom Player Stats
      - Weak Enemies
      - One Hit Kill
      - & More

      Press & Hold to read feature description


      iOS Hack Download Link: https://iosgods.com/topic/146819-sword-master-story-cheats-v42294-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,517 replies
    • [ Chiikawa Pocket JP ] ちいかわぽけっと v1.7.0 Jailed Cheats +3
      Modded/Hacked App: ちいかわぽけっと By Applibot Inc.
      Bundle ID: jp.co.applibot.chiikawapocket
      iTunes Store Link: https://apps.apple.com/jp/app/%E3%81%A1%E3%81%84%E3%81%8B%E3%82%8F%E3%81%BD%E3%81%91%E3%81%A3%E3%81%A8/id6596745408?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - God Mode
      - Multiply Attack
      - Custom Speed (Customize before Login or Clear stage to get apply)

       

      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/194281-chiikawa-pocket-jp-%E3%81%A1%E3%81%84%E3%81%8B%E3%82%8F%E3%81%BD%E3%81%91%E3%81%A3%E3%81%A8-v1111-jailed-cheats-3/
        • Haha
        • Like
      • 33 replies
    • Chiikawa Pocket Cheats v1.7.0 +3
      Modded/Hacked App: Chiikawa Pocket By Applibot Inc.
      Bundle ID: jp.co.applibot.chiikawapocketgl
      iTunes Store Link: https://apps.apple.com/us/app/chiikawa-pocket/id6740838442?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - God Mode
      - Multiply Attack

       

      Non-Jailbroken Hack: https://iosgods.com/topic/193718-chiikawa-pocket-v111-jailed-cheats-2/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/193717-chiikawa-pocket-cheats-v111-2/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 57 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines