Jump to content

Learn how to hack games with IDA, CodeInject and HooKfunction (with example!)


133 posts in this topic

Recommended Posts

Updated (edited)
Hello there:)
Today I want to tell you about Code Inject and MSHook Hacking.
I will explain with a practical example for clarity!
I thank this community and leave this guide. 
Thank you!
 
✔Requirements
Spoiler
IDA PRO
Knowledge about C++ 
 
✔Binary
Spoiler
1.Add this repo http://cydia.iphonecake.com/
2.Install CrackerXI.
3.Turn on all in Settings.
4.Slect app which you want to get binary in Applist.
5.It will save to /var/mobile/Documents/CrackerXI
 
✔Note about Tweak.xm
Spoiler
The latest version of Theos uses Tweak.x instead of Tweak.xm.
These differences are explained at this page:
This can cause errors when compiling code found on the net. (In my case when compiling the code for PrefBundle)
So follow this:
1.Change name from Tweak.x to Tweak.xm
2.Change <ProjectName> _FILES = Tweak.x to <ProjectName> _FILES = Tweak.xm in Makefile.
 
✔ASLR Slide
Spoiler

There is ASLR slide is ARM64 binary, so IDA offset and actual binary offset are shifted by ASLR value.

※You can give IDA offset to vm_WriteData because ASLR considered Automatically in vm_WriteData.h
#import <mach-o/dyld.h>
uint64_t getRealOffset(uint64_t offset){
return _dyld_get_image_vmaddr_slide(0)+offset;
}

✔ARM Insructions

Spoiler

Load

MOV r0, r1 
Move the value of r1 to r0
LDR r0, [r1]
Load from memory r1 to register r0
STR r0, [r1]
Store the value of r0 into r1
Store memory r1 with value of register r0 
 
Branch
Compare previous CMP values
BEQ label
jump to label if values are equal
BNE label
jump to label if values are not equal
etc...
CBZ r0, label
jump to label if r0 is 0
CBNZ r0, label
jump to label if r0 is not 0

 

 
✔CodeInject
Spoiler

Place vm_WriteData.h in your project.

And add this to beginning of the code  
#import <vm_writeData.h>
 
Identify the part to change
1.Change the return value
Look at the processing at the bottom of the function (the part load to X0)
MOV X0, 100
2.Change branch
BEQ X0, label
Change the branch to always jump to any label:
B X0, label (BAL is also ok)
Change the branch to never jump to any label:
NOP
Convert to Hex
1.Load
2.Branch
Enter ARM instruction and copy ARM64 HEX.
Apply Changes
vm_WriteData(0x100000000, 0x00000000);
Change the memory starting from 0x100000000 to 00000000.
 
Ex1:Change instruction to change damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

Ex2:Change branch to change accuracy of weapon

Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

Where should I actually write

Spoiler

It is good to write in %ctor. You can write it like this:

#import <vm_writeData.h>
%ctor {
  vm_WriteData(0x1002B55D8, 0x953E80D2);
}
 
✔MS(Object-C func)
Spoiler

Class name depends on the game Use class name which has applicationDidBecomeActive method!

(Easy to find on Flex)
%hook AppController // class name
-(void)applicationDidBecomeActive:(id)argument { // (type od return value) and method name and (type of argument)
    UIAlertView *alert = [[UIAlertView alloc] initWithTitle:@"test" message:@"Detected App opened!" delegate:nil cancelButtonTitle:@"Continue" otherButtonTitles:nil];
    [alert show];
    return %orig(argument);
}
%end
%orig holds the original function. Since we only want to add processing, we also call the original function.
※You can change the process by changing the argument.
This way is only available for Object-C functions, so if you want to hook a native function you can see in IDA and use MSHook!
 
✔MSHook(Native func)
Spoiler

Import substrate at beginning of code.

#import <substrate.h>
Hook function with offset
MSHookFunction((void *)getRealOffset(0x100000000), (void *)func, (void **)&org_func);
func
func - Function that has a process that you want to overwrite.
org_func - Function that keeps the original processing.
Since MSHookFuntion's void is cast and passed to void type, it is always void.
argument
Be sure to include this pointer first.
 
Ex1:Increase Damage
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

 

✔NSLog

Spoiler

To check NSLog on a device.

Add Flexing from the BigBoss repository.
You can display the log by pressing and holding three fingers on the application you want to see logs.
It can be used by tapping System Log and enabling it from Setting in the upper right.
NSLog(@"Your Log Text Here");
To display argument values:
%d int
%f float
%c unsigned char
%hi short
 
Ex:Display argument values
Spoiler

You can add it in the function definition that overrides like this.

int getDamage(void* this_, void* UserInfor, unsigned char arg0, float arg1) {
  NSLog(@"getDamage Called! arg0: %c, arg1: %f", arg0, arg1);
  return org_getDamage(this_, UserInfor, arg0, arg1);
}
 
✔Call the native func
 
Ex:Call a function to get user information
Spoiler

Hidden Content

React or reply to this topic to see the hidden content & download link. 👀

✔PrefBundle

Spoiler

https://iosgods.com/topic/444-tutorial-how-to-make-a-preference-bundle/

You can learn about PredBundle easily from the link above.
I only mention here how to add icons.
How to add icons
Add icon.png file to <project>/<prefbundl_project>/Resources/
You have to export with these size:
> icon.png - 29×29
[email protected] - 58×58
[email protected] - 87×87
You can export icon in here: https://appiconmaker.co/
 
p.s. A knowledgeable person would think why I don't talk about debuggers. Unfortunately gdb is displayed as BadCPUType in my environment and watch-point does not work properly in lldb.
Here are some great tutorials if you are interested in them:
 
If there are any mistakes please point in reply !
Enjoy :)
Updated by princessXZ
some stuff
  • Like 282
  • Winner 22
  • Thanks 26
  • Haha 6
  • Agree 9
  • Informative 21
Posted
7 hours ago, mafusuke said:
STR r0, [r1]
Load the value of r0 into r1

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Posted
3 hours ago, Ted2 said:

Nicely written, note thought that STR stands for store, so it's storing it.
Generally, LDR is used to load something from memory to a register, and STR is used to store something from a register to a memory address.

Thank you! I'll fix that 🙂

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Mob Control +7 Mods [ Unlimited Currencies ]
      Mod APK Game Name: Mob Control
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.vincentb.MobControl

       

      🤩 Hack Features

      - Unlimited Coins -> Will increase instead of decrease.
      - Unlimited Skip'Its -> Will increase instead of decrease.
      - Unlimited Stars -> Earn some.
      - Unlimited Bricks
      - Unlimited Earnt Bricks
      - Unlimited Cards -> Will increase instead of decrease.
      - No Card Requirement
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 21 replies
    • Mob Control +7 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Mob Control By Voodoo
      Bundle ID: com.vincentb.MobControl
      iTunes Store Link: https://apps.apple.com/us/app/mob-control/id1562817072?uo=4


      Hack Features:
      - Unlimited Coins -> Earn or spend some.
      - Unlimited Skip'Its -> Earn or spend some.
      - Unlimited Stars -> Earn some.
      - Unlimited Bricks
      - Unlimited Earnt Bricks
      - Unlimited Cards -> Will increase instead of decrease.
      - No Card Requirement


      Jailbreak required hack(s): [Mod Menu Hack] Mob Control v2.78.0 +7 Cheats [ Unlimited Currencies ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 333 replies
    • (Dragon Ball Legends Japan)ドラゴンボール レジェンズ +13 Jailed Cheats
      Modded/Hacked App: ドラゴンボール レジェンズ By BANDAI NAMCO Entertainment Inc.
      Bundle ID: jp.co.bandainamcoent.BNEI0333
      iTunes Store Link: https://itunes.apple.com/jp/app/ドラゴンボール-レジェンズ/id1358232022?mt=8


      Mod Requirements:
      - Jailbroken or Non-Jailbroken iPhone/iPad/iPod Touch.
      - Cydia Impactor.
      - A Computer Running Windows/Mac/Linux.


      Hack Features:
      - Enemies Don't Attack
      - No Ki Cost
      - Unlimited Ki
      - No Character Swap CoolDown
      - No Vanish CoolDown
      - Auto Complete All Challenges - Currency/Chrono Crystals Hack! 
      - Always Critical
      - All Cards Give DragonBall 

       This hack only works on x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 3,214 replies
    • Rise of Eros: Desire +2 Jailed Cheats
      Modded/Hacked App: Rise of Eros: Desire By DarkWind Ltd.
      Bundle ID: com.darkwind.heroslite
      App Store Link: https://apps.apple.com/us/app/rise-of-eros-desire/id6479749976?uo=4

       

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier

       

      ⬇️ iOS Hack Download IPA Link


      Hidden Content

      Download via the iOSGods App







       

      📖 PC Installation Instructions

      STEP 1: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see our iOSGods App IPA Download Tutorial which includes a video example.
      STEP 2: Download Sideloadly and install it on your Windows or Mac.
      STEP 3: Open Sideloadly on your computer, connect your iOS device, and wait until your device name appears in Sideloadly.
      STEP 4: Once your iDevice is recognized, drag the modded .IPA file you downloaded and drop it into the Sideloadly application.
      STEP 5: Enter your Apple Account email, then press “Start.” You’ll then be asked to enter your password. Go ahead and provide the required information.
      STEP 6: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 7: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles / VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 8: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A
        • Informative
        • Agree
        • Thanks
        • Like
      • 12 replies
    • Hero Wars: Alliance +2 Cheats
      Mod APK Game Name: Hero Wars: Alliance Fantasy By Nexters Global LTD
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.nexters.herowars

       

      🤩 Hack Features

      - Damage Multiplier
      - Defense Multiplier

       

      ⬇️ Android Mod APK Download Link


      Hidden Content

      Download Modded APK







       

      📖 Android Installation Instructions

      STEP 1: Download the modded APK file from the link above using your preferred Android browser or download manager.
      STEP 2: Once the download is complete, open your file manager and locate the downloaded .apk file (usually in the Downloads folder).
      STEP 3: Tap the APK file, then select Install. If prompted, enable Install from Unknown Sources in your device settings.
      STEP 3A: If the mod includes an OBB file, extract it if it’s inside an archive. Then move the folder to: /Android/obb/
      STEP 3B: If the mod includes a DATA file, extract it if it’s archived. Then move the folder to: /Android/data/
      STEP 4: Once installed, open the game and toggle your desired cheats & features through the APK mod menu. Enjoy!

       

      NOTE: If you have any questions or issues, read our Frequently Asked Questions topic. If you still need help, post your issue below and we’ll assist you as soon as possible. If the mod works for you, please share your feedback to help other members!

       

      🙌 Credits

      - AlyssaX64

       

      📷 Cheat Video/Screenshots

      N/A

       

       iOS & iPadOS App Hacks
      If you’re looking for Non-Jailbroken & No Jailbreak required iOS IPA hacks, visit the iOS Game Cheats & Hacks or the iOSGods App for a variety of modded games and apps for non-jailbroken iOS devices.
        • Agree
        • Winner
        • Like
      • 38 replies
    • Crypto Miner Tycoon +2 Jailed Cheats [ Unlimited Gold ]
      Modded/Hacked App: Crypto Miner Tycoon By MTAG PUBLISHING LTD
      Bundle ID: com.mysterytag.cryptominer
      iTunes Store Link: https://apps.apple.com/us/app/crypto-miner-tycoon/id6450786835
       

      Hack Features:
      - No Upgrade Cost
      - Unlimited Gold -> Purchase a time warp via the shop.


      Jailbreak required hack(s): [Mod Menu Hack] Crypto Miner Tycoon v0.4 +2 Cheats [ Unlimited Gold ] - Free Jailbroken Cydia Cheats - iOSGods
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 56 replies
    • Dragon Fever TD v2.19.2 Jailed Cheats +3
      Modded/Hacked App: Dragon Fever TD By Guangzhou Polly Technology Co. , Ltd.
      Bundle ID: com.traverse.zhfx.en.ios
      App Store Link: https://apps.apple.com/us/app/dragon-fever-td/id6754828778?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - God Mode
      - Multiply Attack
      - Skip Ads



      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/208136-dragon-fever-td-v2192-jailed-cheats-3/
      • 0 replies
    • Golf Dreams +6 Jailed Cheats [ Unlock All ]
      Modded/Hacked App: Golf Dreams By Golf Dreams AB
      Bundle ID: com.ratherunique.bogeyball
      App Store Link: https://apps.apple.com/us/app/golf-dreams/id1551178669?uo=4

       

      🤩 Hack Features

      - Premium Enabled -> Unlocks all courses, tournaments and no ads.
      - Unlock All Clubs -> Buggy. Press on Unlock, back out then press Equip.
      - Unlimited Tickets -> Earn or spend some.
      - Unlimited Gold Markers -> Earn or spend some.
      - Unlimited Balls -> Earn or spend some.
      - Max Level -> Earn some XP.
      • 1 reply
    • Matchcreek Motors +5 Jailed Cheats [ Unlimited Currencies ]
      Modded/Hacked App: Matchcreek Motors: Custom Cars By Hutch Games Ltd
      Bundle ID: com.hutchgames.carsm3
      iTunes Store Link: https://apps.apple.com/us/app/matchcreek-motors-custom-cars/id6566187035?uo=4

       
       

      🤩 Hack Features

      - Unlimited Currencies -> Will increase instead of decrease.
      - Freeze Lives
      - Freeze Pre-Game Boosters
      - Freeze Boosters
      - Freeze Moves
        • Haha
        • Thanks
        • Winner
        • Like
      • 16 replies
    • Match Factory! +3 Jailed Cheats [ Unlimited Everything ]
      Modded/Hacked App: Match Factory! By Peak Games
      Bundle ID: net.peakgames.match
      iTunes Store Link: https://apps.apple.com/gb/app/match-factory/id6449094229?uo=4


      Hack Features:
      - Unlimited Everything -> Will increase instead of decrease. Use coins for energy.
      - Auto Win -> Pick up an item.
      - Unlimited Time -> Will not decrease.
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 85 replies
    • Hero Wars: Alliance +2 Jailed Cheats
      Modded/Hacked App: Hero Wars: Alliance By Nexters Global LTD
      Bundle ID: com.nexters.titanhunters
      iTunes Store Link: https://apps.apple.com/us/app/hero-wars-alliance/id1158967485?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Damage Multiplier
      - Defense Multiplier

      Note:
      Don't Use Hack In Tutorial


      Jailbreak required hack(s): 


      iOS Hack Download IPA Link:

      Hidden Content

      Download via the iOSGods App








      PC Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see this tutorial topic.
      STEP 3: Download Sideloadly and install it on your PC.
      STEP 4: Open/Run Sideloadly on your computer, connect your iOS Device, and wait until your device name shows up.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Sideloadly application.
      STEP 6: You will now have to enter your iTunes/Apple ID email login, press "Start" & then you will be asked to enter your password. Go ahead and enter the required information.
      STEP 7: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles/VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. Jailbroken iDevices can also use Sideloadly/Filza/IPA Installer to normally install the IPA with AppSync. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 269 replies
    • F Class Adventurer: AFK RPG +3 Jailed Cheats
      Modded/Hacked App: F Class Adventurer: AFK RPG By EK GAMES
      Bundle ID: net.ekgames.fclasshero
      iTunes Store Link: https://apps.apple.com/us/app/f-class-adventurer-afk-rpg/id6444598021?uo=4


      Mod Requirements:
      - Non-Jailbroken/Jailed or Jailbroken iPhone/iPad/iPod Touch.
      - Sideloadly / Cydia Impactor or alternatives.
      - A Computer Running Windows/macOS/Linux with iTunes installed.


      Hack Features:
      - Damage Multiplier
      - Never Die
      - Reward Multiplier


      Jailbreak required hack(s): 


      iOS Hack Download IPA Link:

      Hidden Content

      Download via the iOSGods App








      PC Installation Instructions:
      STEP 1: If necessary, uninstall the app if you have it installed on your iDevice. Some hacked IPAs will install as a duplicate app. Make sure to back it up so you don't lose your progress.
      STEP 2: Download the pre-hacked .IPA file from the link above to your computer. To download from the iOSGods App, see this tutorial topic.
      STEP 3: Download Sideloadly and install it on your PC.
      STEP 4: Open/Run Sideloadly on your computer, connect your iOS Device, and wait until your device name shows up.
      STEP 5: Once your iDevice appears, drag the modded .IPA file you downloaded and drop it inside the Sideloadly application.
      STEP 6: You will now have to enter your iTunes/Apple ID email login, press "Start" & then you will be asked to enter your password. Go ahead and enter the required information.
      STEP 7: Wait for Sideloadly to finish sideloading/installing the hacked IPA. If there are issues during installation, please read the note below.
      STEP 8: Once the installation is complete and you see the app on your Home Screen, you will need to go to Settings -> General -> Profiles/VPN & Device Management. Once there, tap on the email you entered from step 6, and then tap on 'Trust [email protected]'.
      STEP 9: Now go to your Home Screen and open the newly installed app and everything should work fine. You may need to follow further per app instructions inside the hack's popup in-game.

      NOTE: iOS/iPadOS 16 and later, you must enable Developer Mode. For free Apple Developer accounts, you will need to repeat this process every 7 days. Jailbroken iDevices can also use Sideloadly/Filza/IPA Installer to normally install the IPA with AppSync. If you have any questions or problems, read our Sideloadly FAQ section of the topic and if you don't find a solution, please post your issue down below and we'll do our best to help! If the hack does work for you, post your feedback below and help out other fellow members that are encountering issues.


      Credits:
      - AlyssaX64


      Cheat Video/Screenshots:

      N/A
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 197 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines