Jump to content

9 posts in this topic

Recommended Posts

Posted (edited)

So I'm trying to hack a game's currency and I've done all that lldb stuff and it gave me this

0x100354f78 <+264>: ldr    w8, [x20, #0x8]

Would I jump to address 0x100354f78 and change ldr    w8, [x20, #0x8] to ldr    w8, r7.

r7 is usually a big value, right?

And that means w8 is money?

Updated by NoHax
Posted (edited)

The offset you get from lldb, is probs right. But it's not always the exact thing lldb says, for you the ldr. If u could post a code/screenshot of the entire function, others (maybe me) can help more. 

 

Also r7 is in armv7 a big value, but it seems like you're hacking arm64, so that will be diffrent.

 

have a look at this post:

 

Updated by Ted2
Posted (edited)
9 minutes ago, Ted2 said:

The offset you get from lldb, is probs right. But it's not always the exact thing lldb says, for you the ldr. If u could post a code/screenshot of the entire function, others (maybe me) can help more. 

 

Also r7 is in armv7 a big value, but it seems like you're hacking arm64, so that will be diffrent.

 

have a look at this post:

 

Here's the whole function

ADD             X0, SP, #0x160+var_128

MOV             X1, X22

BL              __ZNSsC1ERKSs ; std::string::string(std::string const&)

ADD             X1, SP, #0x160+var_128

MOV             X0, X21

MOV             X2, X21

BL              __ZN3Rtt15ShaderComposite14SetNamedShaderESsPNS_6ShaderE ; Rtt::ShaderComposite::SetNamedShader(std::string,Rtt::Shader *)

LDR             X8, [SP,#0x160+var_128]

SUB             X0, X8, #0x18

ADRP            X20, #__ZNSs4_Rep20_S_empty_rep_storageE_ptr@PAGE

LDR             X20, [X20,#__ZNSs4_Rep20_S_empty_rep_storageE_ptr@PAGEOFF]

CMP             X0, X20

B.NE            loc_1003550FC

Also just incase heres what lldb gave me

->  0x100354f78 <+264>: ldr    w8, [x20, #0x8]

    0x100354f7c <+268>: str    w8, [x25, #0x8]

    0x100354f80 <+272>: strb   wzr, [x24, #0xa]

    0x100354f84 <+276>: ldr    w8, [x20, #0x8]

 

Updated by NoHax
Posted (edited)
2 minutes ago, NoHax said:

Here's the whole function

  Hide contents

ADD             X0, SP, #0x160+var_128

MOV             X1, X22

BL              __ZNSsC1ERKSs ; std::string::string(std::string const&)

ADD             X1, SP, #0x160+var_128

MOV             X0, X21

MOV             X2, X21

BL              __ZN3Rtt15ShaderComposite14SetNamedShaderESsPNS_6ShaderE ; Rtt::ShaderComposite::SetNamedShader(std::string,Rtt::Shader *)

LDR             X8, [SP,#0x160+var_128]

SUB             X0, X8, #0x18

ADRP            X20, #__ZNSs4_Rep20_S_empty_rep_storageE_ptr@PAGE

LDR             X20, [X20,#__ZNSs4_Rep20_S_empty_rep_storageE_ptr@PAGEOFF]

CMP             X0, X20

B.NE            loc_1003550FC

[/spoiler]

Also just incase here's what lldb gave me

  Reveal hidden contents

->  0x100354f78 <+264>: ldr    w8, [x20, #0x8]

    0x100354f7c <+268>: str    w8, [x25, #0x8]

    0x100354f80 <+272>: strb   wzr, [x24, #0xa]

    0x100354f84 <+276>: ldr    w8, [x20, #0x8]

Thank's for helping!

 

I'm not sure, u could try chane the SUB to an ADD, when u'll buy something the coins won't substract but they'll add it.

 

btw for arm64 u gotta remove aslr loaded offset. Now U got the wrong function in IDA.

 

how you do that is by type 'image list'  in lldb & then the above line. There's also a tutorial madr about how to do that, something called like 'how to defeat aslr.....'

Updated by Ted2
Posted (edited)
20 minutes ago, Ted2 said:

I'm not sure, u could try chane the SUB to an ADD, when u'll buy something the coins won't substract but they'll add it.

 

btw for arm64 u gotta remove aslr loaded offset. Now U got the wrong function in IDA.

 

how you do that is by type 'image list'  in lldb & then the above line. There's also a tutorial madr about how to do that, something called like 'how to defeat aslr.....'

Wait, so my offset from lldb was 0x100354f78, I just checked my alsr and its d8000, so I would do 0x100354f78-d8000 to find my offset?

Or do I have to do that watchpoint thing again and then take away my alsr value from the new offset I get?

Updated by NoHax
Posted
38 minutes ago, NoHax said:

Wait, so my offset from lldb was 0x100354f78, I just checked my alsr and its d8000, so I would do 0x100354f78-d8000 to find my offset?

Or do I have to do that watchpoint thing again and then take away my alsr value from the new offset I get?

Take the aslr from the lldb offset. See if that matches in IDA. 

Posted
On 7/6/2017 at 1:32 AM, Ted2 said:

The offset you get from lldb, is probs right. But it's not always the exact thing lldb says, for you the ldr. If u could post a code/screenshot of the entire function, others (maybe me) can help more. 

 

Also r7 is in armv7 a big value, but it seems like you're hacking arm64, so that will be diffrent.

 

have a look at this post:

 

 you don't reply inbox me ???

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Jacket Escape v1.1.0 [ +2 Cheats ] Currency Max
      Modded/Hacked App: Jacket Escape By 蕴绮 黄
      Bundle ID: com.simplegame.jetpack
      App Store Link: https://apps.apple.com/us/app/jacket-escape/id6450668807?uo=4

      🤩 Hack Features

      - Unlimited Coins
      - Bullet Size Max
      • 1 reply
    • Jacket Escape v1.1.0 [ +2 Jailed ] Currency Max
      Modded/Hacked App: Jacket Escape By 蕴绮 黄
      Bundle ID: com.simplegame.jetpack
      App Store Link: https://apps.apple.com/us/app/jacket-escape/id6450668807?uo=4

      🤩 Hack Features

      - Unlimited Coins
      - Bullet Size Max
      • 1 reply
    • Motor Capital v1.0.0 [ +1 Cheats ] Enough Resources
      Modded/Hacked App: Motor Capital By 24 HIT Riga SIA
      Bundle ID: com.motor.capital
      App Store Link: https://apps.apple.com/us/app/motor-capital/id6771701401?uo=4

      🤩 Hack Features

      Pre Activated
      - Enough Resources / Only Upgrades & Building Upgrade
      • 1 reply
    • Motor Capital v1.0.0 [ +1 Jailed ] Enough Resources
      Modded/Hacked App: Motor Capital By 24 HIT Riga SIA
      Bundle ID: com.motor.capital
      App Store Link: https://apps.apple.com/us/app/motor-capital/id6771701401?uo=4

      🤩 Hack Features

      Pre Activated
      - Enough Resources / Only Upgrades & Building Upgrade
      • 0 replies
    • SimCity BuildIt Cheats v1.79.0 +1 [ Freeze Currencies ]
      Modded/Hacked App: SimCity BuildIt By EA Swiss Sarl
      Bundle ID: com.ea.simcitymobile.bv
      iTunes Store Link: https://apps.apple.com/us/app/simcity-buildit/id913292932?uo=4


      Hack Features:
      - Infinite Currencies


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/124792-arm64-simcity-buildit-v1412-jailed-cheats-1/


      iOS Hack Download Link: https://iosgods.com/topic/157687-simcity-buildit-cheats-v1415-1/
      • 744 replies
    • Shoot & Hide v1.5.3 [ +6 Cheats ] Currency Max
      Modded/Hacked App: Shoot & Hide By CRAZY LABS BY TABTALE , G.P.
      Bundle ID: com.sniper.shoot.hide.game
      App Store Link: https://apps.apple.com/us/app/shoot-hide/id6747033069?uo=4

      🤩 Hack Features

      Pre Activated
      - Currency Max / Earn Then Get
      - Trophies Max Earn Then Get
      - Heroes Unlocked / Linked Trophies
      - Location Unlocked / Linked Trophies
      - Merge Anything
      - HP MAX / ON When Enemy Turn After Disable
      • 5 replies
    • Shoot & Hide v1.5.3 [ +6 Jailed ] Currency Max
      Modded/Hacked App: Shoot & Hide By CRAZY LABS BY TABTALE , G.P.
      Bundle ID: com.sniper.shoot.hide.game
      App Store Link: https://apps.apple.com/us/app/shoot-hide/id6747033069?uo=4

      🤩 Hack Features

      Pre Activated
      - Currency Max / Earn Then Get
      - Trophies Max Earn Then Get
      - Heroes Unlocked / Linked Trophies
      - Location Unlocked / Linked Trophies
      - Merge Anything
      - HP MAX / ON When Enemy Turn After Disable
      • 1 reply
    • Real War: Survival Game v0.1.4 [ +4 APK MOD ] Troops Max
      Mod APK Game Name: Real War: Survival Game
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.zc.action.war.survival.game

      🤩 Hack Features

      - Auto ADS NO
      - Upgrade Cost 0 / Easy To Get Coins - ATK - Fire Rate
      ::::::: VIP :::::::
      - Unlimited Troops / Hit Damage Then Use It / Just Hit 🟢🔴 Then Work
      - Max ATK
      • 3 replies
    • Real War: Survival Game v1.1.0 [ +4 Cheats ] Troops Max
      Modded/Hacked App: Real War: Survival Game By Rameez Rehmat
      Bundle ID: com.sku.action.war.survival.games
      App Store Link: https://apps.apple.com/us/app/real-war-survival-game/id6772532581?uo=4

      🤩 Hack Features

      - Auto ADS NO
      - Upgrade Cost 0 / Easy To Get Coins - ATK - Fire Rate
      ::::::: VIP :::::::
      - Unlimited Troops / Hit Damage Then Use It / Just Hit 🟢🔴 Then Work
      - Custom ATK 
      • 1 reply
    • Real War: Survival Game v1.1.0 [ +4 Jailed ] Troops Max
      Modded/Hacked App: Real War: Survival Game By Rameez Rehmat
      Bundle ID: com.sku.action.war.survival.games
      App Store Link: https://apps.apple.com/us/app/real-war-survival-game/id6772532581?uo=4

      🤩 Hack Features

      - Auto ADS NO
      - Upgrade Cost 0 / Easy To Get Coins - ATK - Fire Rate
      ::::::: VIP :::::::
      - Unlimited Troops / Hit Damage Then Use It / Just Hit 🟢🔴 Then Work
      - Custom ATK 
      • 0 replies
    • DRAGON BALL Z DOKKAN BATTLE Japan (ドラゴンボールZ ドッカンバトル) v6.2.5 +7 Cheats!
      Modded/Hacked App: ドラゴンボールZ ドッカンバトル By BANDAI NAMCO Entertainment Inc.
      Bundle ID: jp.co.bandainamcogames.BNGI0211
      iTunes Link: https://itunes.apple.com/jp/app/ドラゴンボールz-ドッカンバトル/id951627670


      Hack Features
      - Unlimited HP  -  (Put .0 at the back of your value: 1000.0)
      - Unlimited Damage  -  (Put .0 at the back of your value: 1000.0)
      - Unlimited Defense  -  (Put .0 at the back of your value: 1000.0)
      - Dice Hack -  [ONLY RANGE BETWEEN 1 - 6 or it will crash]  -  (Put .0 at the back of your value: 4.0)
      - Dice Hack 1, 2, 3
      - Dice Hack 4, 5, 6
      - Auto Win Battles -> Disable if you get errors.
      PUT .0 at the back of all values!
      • 8,075 replies
    • Mushroom War: Evolution TD v1.16.2 [ +8 APK MOD ] Currency Max
      Mod APK Game Name: Mushroom War: Evolution TD
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=rollingball.td.mushroom.warriors&hl=en

      🤩 Hack Features

      - ADS Skip Ticket Max / Rewards Free
      - Battle Food Speed
      ::::::: VIP :::::::
      - AI Freeze
      - Unlimited Gems
      - Unlimited Coins
      - Base HP MAX
      - Base HP Freeze
      - Hero HP Freeze
      • 1 reply
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines