Jump to content

Learn how to hack games with IDA, CodeInject and HooKfunction (with example!)


princessXZ

127 posts in this topic

Recommended Posts

Hello there:)
Today I want to tell you about Code Inject and MSHook Hacking.
I will explain with a practical example for clarity!
I thank this community and leave this guide. 
Thank you!
 
✔Requirements
Spoiler
IDA PRO
Knowledge about C++ 
 
✔Binary
Spoiler
1.Add this repo http://cydia.iphonecake.com/
2.Install CrackerXI.
3.Turn on all in Settings.
4.Slect app which you want to get binary in Applist.
5.It will save to /var/mobile/Documents/CrackerXI
 
✔Note about Tweak.xm
Spoiler
The latest version of Theos uses Tweak.x instead of Tweak.xm.
These differences are explained at this page:
This can cause errors when compiling code found on the net. (In my case when compiling the code for PrefBundle)
So follow this:
1.Change name from Tweak.x to Tweak.xm
2.Change <ProjectName> _FILES = Tweak.x to <ProjectName> _FILES = Tweak.xm in Makefile.
 
✔ASLR Slide
Spoiler

There is ASLR slide is ARM64 binary, so IDA offset and actual binary offset are shifted by ASLR value.

※You can give IDA offset to vm_WriteData because ASLR considered Automatically in vm_WriteData.h
#import <mach-o/dyld.h>
uint64_t getRealOffset(uint64_t offset){
return _dyld_get_image_vmaddr_slide(0)+offset;
}

✔ARM Insructions

Spoiler

Load

MOV r0, r1 
Move the value of r1 to r0
LDR r0, [r1]
Load from memory r1 to register r0
STR r0, [r1]
Store the value of r0 into r1
Store memory r1 with value of register r0 
 
Branch
Compare previous CMP values
BEQ label
jump to label if values are equal
BNE label
jump to label if values are not equal
etc...
CBZ r0, label
jump to label if r0 is 0
CBNZ r0, label
jump to label if r0 is not 0

 

 
✔CodeInject
Spoiler

Place vm_WriteData.h in your project.

And add this to beginning of the code  
#import <vm_writeData.h>
 
Identify the part to change
1.Change the return value
Look at the processing at the bottom of the function (the part load to X0)
MOV X0, 100
2.Change branch
BEQ X0, label
Change the branch to always jump to any label:
B X0, label (BAL is also ok)
Change the branch to never jump to any label:
NOP
Convert to Hex
1.Load
2.Branch
Enter ARM instruction and copy ARM64 HEX.
Apply Changes
vm_WriteData(0x100000000, 0x00000000);
Change the memory starting from 0x100000000 to 00000000.
 
Ex1:Change instruction to change damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link.

Ex2:Change branch to change accuracy of weapon

Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link.

Where should I actually write

Spoiler

It is good to write in %ctor. You can write it like this:

#import <vm_writeData.h>
%ctor {
  vm_WriteData(0x1002B55D8, 0x953E80D2);
}
 
✔MS(Object-C func)
Spoiler

Class name depends on the game Use class name which has applicationDidBecomeActive method!

(Easy to find on Flex)
%hook AppController // class name
-(void)applicationDidBecomeActive:(id)argument { // (type od return value) and method name and (type of argument)
    UIAlertView *alert = [[UIAlertView alloc] initWithTitle:@"test" message:@"Detected App opened!" delegate:nil cancelButtonTitle:@"Continue" otherButtonTitles:nil];
    [alert show];
    return %orig(argument);
}
%end
%orig holds the original function. Since we only want to add processing, we also call the original function.
※You can change the process by changing the argument.
This way is only available for Object-C functions, so if you want to hook a native function you can see in IDA and use MSHook!
 
✔MSHook(Native func)
Spoiler

Import substrate at beginning of code.

#import <substrate.h>
Hook function with offset
MSHookFunction((void *)getRealOffset(0x100000000), (void *)func, (void **)&org_func);
func
func - Function that has a process that you want to overwrite.
org_func - Function that keeps the original processing.
Since MSHookFuntion's void is cast and passed to void type, it is always void.
argument
Be sure to include this pointer first.
 
Ex1:Increase Damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link.

 

✔NSLog

Spoiler

To check NSLog on a device.

Add Flexing from the BigBoss repository.
You can display the log by pressing and holding three fingers on the application you want to see logs.
It can be used by tapping System Log and enabling it from Setting in the upper right.
NSLog(@"Your Log Text Here");
To display argument values:
%d int
%f float
%c unsigned char
%hi short
 
Ex:Display argument values
Spoiler

You can add it in the function definition that overrides like this.

int getDamage(void* this_, void* UserInfor, unsigned char arg0, float arg1) {
  NSLog(@"getDamage Called! arg0: %c, arg1: %f", arg0, arg1);
  return org_getDamage(this_, UserInfor, arg0, arg1);
}
 
✔Call the native func
 
Ex:Call a function to get user information
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link.

✔PrefBundle

Spoiler

https://iosgods.com/topic/444-tutorial-how-to-make-a-preference-bundle/

You can learn about PredBundle easily from the link above.
I only mention here how to add icons.
How to add icons
Add icon.png file to <project>/<prefbundl_project>/Resources/
You have to export with these size:
> icon.png - 29×29
[email protected] - 58×58
[email protected] - 87×87
You can export icon in here: https://appiconmaker.co/
 
p.s. A knowledgeable person would think why I don't talk about debuggers. Unfortunately gdb is displayed as BadCPUType in my environment and watch-point does not work properly in lldb.
Here are some great tutorials if you are interested in them:
 
If there are any mistakes please point in reply !
Enjoy :)
Updated by princessXZ
some stuff
  • Like 259
  • Winner 21
  • Thanks 25
  • Haha 6
  • Agree 7
  • Informative 18
Link to comment
Share on other sites

7 hours ago, mafusuke said:
STR r0, [r1]
Load the value of r0 into r1

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Link to comment
Share on other sites

3 hours ago, Ted2 said:

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Thank you! I'll fix that 🙂

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below. For more information, please read our Posting Guidelines.
Reply to this topic... Posting Guidelines

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Our picks

    • CookieRun: Kingdom China - 冲呀!饼干人:王国 v1.3.2.845 +2 Cheats
      Modded/Hacked App: 冲呀!饼干人:王国 By Shenzhen Tencent Tianyou Technology Ltd
      Bundle ID: com.tencent.cookie
      iTunes Store Link: https://apps.apple.com/cn/app/%E5%86%B2%E5%91%80-%E9%A5%BC%E5%B9%B2%E4%BA%BA-%E7%8E%8B%E5%9B%BD/id1629375316?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Damage Multiplier
      - Defense Multiplier


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above. Use Safari/Google Chrome or other iOS browsers to download.
      STEP 2: Once the file has downloaded, tap on it and then you will be prompted on whether you want to open the deb with iGameGod or copy it to Filza.
      STEP 3: If necessary, tap on the downloaded file, and then, you will need to press 'Install' from the options on your screen.
      STEP 4: Let iGameGod/Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 5: If the hack is a Mod Menu — which is usually the case nowadays — the cheat features can be toggled in-game. Some cheats have options that can be enabled from your iDevice settings.
      STEP 6: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions & Answers topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, please post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
      • 58 replies
    • World Fishing v0.2.9 +2 Cheats
      Modded/Hacked App: World Fishing By MOBIRIX
      Bundle ID: com.mobirix.fht
      iTunes Store Link: https://apps.apple.com/us/app/world-fishing/id6474173564?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Freeze Currencies
      - Unlimited Currencies -> Increase When Use


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above. Use Safari/Google Chrome or other iOS browsers to download.
      STEP 2: Once the file has downloaded, tap on it and then you will be prompted on whether you want to open the deb with iGameGod or copy it to Filza.
      STEP 3: If necessary, tap on the downloaded file, and then, you will need to press 'Install' from the options on your screen.
      STEP 4: Let iGameGod/Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 5: If the hack is a Mod Menu — which is usually the case nowadays — the cheat features can be toggled in-game. Some cheats have options that can be enabled from your iDevice settings.
      STEP 6: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions & Answers topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, please post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
      • 18 replies
    • Knightcore Kingdom(ナイトコアキングダム)v2.0.2 +2 Cheats
      Modded/Hacked App: Knightcore Kingdom(ナイトコアキングダム) By SEVEN&EIGHT HOLDINGS CO., LTD.
      Bundle ID: knight.core.kingdom
      iTunes Store Link: https://apps.apple.com/jp/app/knightcore-kingdom-%E3%83%8A%E3%82%A4%E3%83%88%E3%82%B3%E3%82%A2%E3%82%AD%E3%83%B3%E3%82%B0%E3%83%80%E3%83%A0/id6450690418?uo=4


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iGameGod / Filza / iMazing or any other file managers for iOS.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak.
      - PreferenceLoader (from Cydia, Sileo or Zebra).


      Hack Features:
      - Damage Multiplier
      - Never Die


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/forum/79-no-jailbreak-section/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/


      iOS Hack Download Link:

      Hidden Content
      Download Hack







      Installation Instructions:
      STEP 1: Download the .deb Cydia hack file from the link above. Use Safari/Google Chrome or other iOS browsers to download.
      STEP 2: Once the file has downloaded, tap on it and then you will be prompted on whether you want to open the deb with iGameGod or copy it to Filza.
      STEP 3: If necessary, tap on the downloaded file, and then, you will need to press 'Install' from the options on your screen.
      STEP 4: Let iGameGod/Filza finish the cheat installation. Make sure it successfully installs, otherwise see the note below.
      STEP 5: If the hack is a Mod Menu — which is usually the case nowadays — the cheat features can be toggled in-game. Some cheats have options that can be enabled from your iDevice settings.
      STEP 6: Turn on the features you want and play the game. You may need to follow further instructions inside the hack's popup in-game.

       

      NOTE: If you have any questions or problems, read our Troubleshooting topic & Frequently Asked Questions & Answers topic. If you still haven't found a solution, post your issue down below and we'll do our best to help! If the hack does work for you, please post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
      • 3 replies
    • SuperStar SMTOWN Cheats v3.16.0 +3
      Modded/Hacked App: SuperStar SMTOWN By Dalcomsoft Inc.
      Bundle ID: kr.co.dalcomsoft.superstar.i
      iTunes Store Link: https://apps.apple.com/us/app/superstar-smtown/id890937532?uo=4


      Hack Features:
      - Auto Dance
      - Never Lose Combo


      iOS Hack Download Link: https://iosgods.com/topic/161038-superstar-smtown-cheats-v378-2/
      • 112 replies
    • Zooba: Zoo Battle Royale Game v4.37.1 Jailed Cheats +2
      Modded/Hacked App: Zooba: Zoo Battle Royale Games By Wildlife Studios Limited
      Bundle ID: com.fungames.battleroyale
      iTunes Store Link: https://apps.apple.com/us/app/zooba-zoo-battle-royale-games/id1459402952?uo=4


      Hack Features:
      - Map Hacks
      - Allow Shoot in Water


      Jailbreak required hack(s): https://iosgods.com/topic/131104-arm64-zooba-zoo-battle-royale-game-cheats-all-versions-2/


      iOS Hack Download Link: https://iosgods.com/topic/131134-arm64-zooba-zoo-battle-royale-game-v320-jailed-cheats-2/
        • Haha
      • 1,067 replies
    • Cooking Diary Restaurant Game v2.27.0 Jailed Cheats +3
      Modded/Hacked App: Cooking Diary® Restaurant Game by MyTona Pte Ltd
      Bundle ID: com.mytonallc.cookingdiary
      iTunes Store Link: https://apps.apple.com/us/app/cooking-diary-restaurant-game/id1214763610?uo=4&at=1010lce4


      Hack Features:
      - Infinite Currencies (Get some)
      - Freeze Boosters


      iOS Hack Download Link: https://iosgods.com/topic/110310-arm64-cooking-diary-restaurant-game-v1160-3/
        • Agree
      • 595 replies
    • NARUTO X BORUTO NINJA VOLTAGE Cheats v11.4.1 +4 Cheats
      Modded/Hacked App: NARUTO X BORUTO NINJA VOLTAGE by BANDAI NAMCO Entertainment Inc.
      Bundle ID: jp.co.bandainamcoent.BNEI0306
      iTunes Store Link: https://apps.apple.com/us/app/naruto-x-boruto-ninja-voltage/id1290010412?uo=4&at=1010lce4


      Hack Features:
      - Multiply Attack
      - Multiply Defense
      - Instant Skill
      - Infinite Mana


      iOS Hack Download Link: https://iosgods.com/topic/128155-arm64-naruto-x-boruto-ninja-voltage-cheats-v600-4/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 993 replies
    • Matchington Mansion v1.158.0 Jailed Cheats +3
      Modded/Hacked App: Matchington Mansion By Magic Tavern, Inc.
      Bundle ID: com.matchington.mansion
      iTunes Store Link: https://apps.apple.com/us/app/matchington-mansion/id1216575026?uo=4


      Hack Features:
      - Infinite Moves
      - Infinite Booster
      - Infinite Lives
       


      Jailbreak required hack(s): https://iosgods.com/topic/75127-arm64-matchington-mansion-cheats-all-versions-5/#


      Hack Download Link: https://iosgods.com/topic/75130-arm64-matchington-mansion-v1970-jailed-cheats-3/
        • Thanks
      • 584 replies
    • The Simpsons™: Tapped Out v4.67.5 +3 Cheats
      Modded/Hacked App: The Simpsons™: Tapped Out By Electronic Arts Inc.
      Bundle ID: com.ea.simpsonssocial.inc2
      iTunes Store Link: https://apps.apple.com/us/app/the-simpsons-tapped-out/id497595276?uo=4


      Hack Features:
      - Free Store
      - Free Skipping
      - Extra Rewards (Receive when enter the game)


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/83384-the-simpsons%E2%84%A2-tapped-out-v4648-3-cheats-for-jailed-idevices/


      Hack Download Link: https://iosgods.com/topic/79480-the-simpsons%E2%84%A2-tapped-out-v4648-3-cheats/
        • Informative
        • Winner
        • Like
      • 3,301 replies
    • My Fantasy: Choose Your Story v2.9.3 +3 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: My Fantasy: Choose Your Story By GM UNICORN CORPORATION LIMITED
      Bundle ID: gmem.episode
      iTunes Store Link: https://apps.apple.com/us/app/my-fantasy-choose-your-story/id1491717191


      Hack Features:
      - Unlimited Tickets -> Use some.
      - Unlimited Diamonds -> Use some.
      - Premium Enabled


      Jailbreak required hack(s): [Mod Menu Hack] My Fantasy: Choose Your Story v2.2.5 +2 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 133 replies
    • My Fantasy: Choose Your Story v2.9.3 +3 Cheats [ Unlimited Currencies ]
      Modded/Hacked App: My Fantasy: Choose Your Story By GM UNICORN CORPORATION LIMITED
      Bundle ID: gmem.episode
      iTunes Store Link: https://apps.apple.com/us/app/my-fantasy-choose-your-story/id1491717191
       

      Hack Features:
      - Unlimited Tickets -> Use some.
      - Unlimited Diamonds -> Use some.
      - Premium Enabled


      Non-Jailbroken & No Jailbreak required hack(s): [Non-Jailbroken Hack] My Fantasy: Choose Your Story v2.2.5 +2 Cheats [ Unlimited Currencies ] - Free Non-Jailbroken IPA Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Like
      • 79 replies
    • Zombie Idle Defense v2.5.4 +3 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Zombie Idle Defense By THAI DONG COMPANY LIMITED
      Bundle ID: com.tdcgame.idle.zombie
      iTunes Store Link: https://apps.apple.com/us/app/zombie-idle-defense/id1509441400?uo=4


      Hack Features:
      - Unlimited Cash -> Spend some.
      - Unlimited Coins -> Will increase instead of decrease.
      - Free In-App Purchases -> Toggle on via iGMenu.


      Jailbreak required hack(s): [Mod Menu Hack] Zombie Idle Defense ( All Versions ) +3 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 25 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines