Jump to content

IDA/GDB issue code inject crash ,help


Go to solution Solved by Oxytyramine,

19 posts in this topic

Recommended Posts

Posted (edited)

hey everybody,i need your help,please

I tried to hack Simcity via GDB/IDA .i found the offset is

0x498324  

orig:str r4, [r6, #152]

hack: str r7,[r6,#152]

as usually,i changed it to str r7,[r6,#152],   set *0x498324=E5867098

press c  enter return device make money change ,then app crash :wallbash: 

 

so,i tried to set $r4=oxVALUE,work now,

 

my quesion is :

1.is it possible to code inject directly like change r4 value ? if it is possible ,how to do.

2.why r4 to r7 will crash.

 

Hardware watchpoint 3: *257995816

Old value = 30
New value = 29
0x00498324 in g_s3e_code ()
3: x/i $pc 0x498324: 98 40 86 e5 str r4, [r6, #152]
2: $r0 = 484640170
1: x/i $pc 0x498324: 98 40 86 e5 str r4, [r6, #152]
(gdb) info r
r0 0x1ce305aa 484640170
r1 0xc6ef3720 -957401312
r2 0x88c110 8962320
r3 0x0 0
r4 0x1d 29
r5 0x88c118 8962328
r6 0xf60b390 257995664
r7 0x1 1
r8 0x6ce500cb 1826947275
r9 0x52ae977f 1387173759
r10 0x30317681 808547969
r11 0x0 0
r12 0x0 0
sp 0x52d1ab8 86842040
lr 0x4982d4 4817620
pc 0x498324 4817700
cpsr 0x280d0010 671940624
(gdb) set $r4=0x999999
warning: Unrecognized osabi 0 in arm_set_osabi_from_host_info
(gdb) c
Continuing.
warning: Unrecognized osabi 0 in arm_set_osabi_from_host_info
warning: Unrecognized osabi 0 in arm_set_osabi_from_host_info
Hardware watchpoint 3: *257995816

Old value = 29
New value = 10066329 :p 
0x00498324 in g_s3e_code ()
3: x/i $pc 0x498324: 98 40 86 e5 str r4, [r6, #152]
2: $r0 = 484640170
1: x/i $pc 0x498324: 98 40 86 e5 str r4, [r6, #152]
(gdb) c
Continuing.
game running image

 

symbolstub1:004982AC ; ---------------------------------------------------------------------------
__symbolstub1:004982AC
__symbolstub1:004982AC loc_4982AC ; CODE XREF: sub_49828C+14j
__symbolstub1:004982AC ADD R4, R0, #0xA0
__symbolstub1:004982B0 ADD R5, R0, #0x98
__symbolstub1:004982B4 MOV R0, R5
__symbolstub1:004982B8 MOV R1, R4
__symbolstub1:004982BC BL loc_496AC4
__symbolstub1:004982C0 CMP R0, R7
__symbolstub1:004982C4 BCC loc_4982A4
__symbolstub1:004982C8 MOV R0, R5
__symbolstub1:004982CC MOV R1, R4
__symbolstub1:004982D0 BL loc_496AC4
__symbolstub1:004982D4 LDR R5, =0x3F3E38
__symbolstub1:004982D8 ADD R5, PC, R5
__symbolstub1:004982DC LDR R10, [R5]
__symbolstub1:004982E0 CMP R10, #0
__symbolstub1:004982E4 RSB R4, R7, R0
__symbolstub1:004982E8 BNE loc_4982F4
__symbolstub1:004982EC BL sub_3C39EC
__symbolstub1:004982F0 LDR R10, [R5]
__symbolstub1:004982F4
__symbolstub1:004982F4 loc_4982F4 ; CODE XREF: sub_49828C+5Cj
__symbolstub1:004982F4 LDR R1, =0x3F3E0C
__symbolstub1:004982F8 LDR R2, =0x3F3E04
__symbolstub1:004982FC LDR R3, =0x3F3DFC
__symbolstub1:00498300 ADD R1, PC, R1
__symbolstub1:00498304 ADD R2, PC, R2
__symbolstub1:00498308 ADD R3, PC, R3
__symbolstub1:0049830C LDR R9, [R1]
__symbolstub1:00498310 MOV R12, #0
__symbolstub1:00498314 LDR R8, [R2]
__symbolstub1:00498318 LDR R1, =0xC6EF3720
__symbolstub1:0049831C LDR R0, [R3]
__symbolstub1:00498320 MOV R3, R12
__symbolstub1:00498324 STR R4, [R6,#0x98]
__symbolstub1:00498328
__symbolstub1:00498328 loc_498328 ; CODE XREF: sub_49828C+E0j
__symbolstub1:00498328 ADD R3, R3, #0x9E000000
__symbolstub1:0049832C ADD R3, R3, #0x374000
__symbolstub1:00498330 ADD R3, R3, #0x3980
__symbolstub1:00498334 ADD R3, R3, #0x39
__symbolstub1:00498338 ADD R11, R10, R12,LSL#4
__symbolstub1:0049833C ADD R2, R9, R12,LSR#5
__symbolstub1:00498340 ADD R5, R12, R3
__symbolstub1:00498344 EOR R2, R11, R2
__symbolstub1:00498348 EOR R2, R2, R5
__symbolstub1:0049834C ADD R4, R4, R2
__symbolstub1:00498350 ADD R5, R4, R3
__symbolstub1:00498354 ADD R11, R8, R4,LSL#4
__symbolstub1:00498358 ADD R2, R0, R4,LSR#5
__symbolstub1:0049835C EOR R2, R11, R2
__symbolstub1:00498360 EOR R2, R2, R5
__symbolstub1:00498364 CMP R3, R1
__symbolstub1:00498368 ADD R12, R12, R2
__symbolstub1:0049836C BNE loc_498328
__symbolstub1:00498370 MOV R2, #0
__symbolstub1:00498374 LDR R1, [R6,#0xBC]
__symbolstub1:00498378 ORR R2, R2, R12
__symbolstub1:0049837C MOV R3, R4
__symbolstub1:00498380 CMP R1, #0
__symbolstub1:00498384 STRD R2, [R6,#0xA0]
__symbolstub1:00498388 BEQ loc_4982A4
__symbolstub1:0049838C CMP R7, R1
__symbolstub1:00498390 MOVCS R7, R1
__symbolstub1:00498394 MOV R0, R7
__symbolstub1:00498398 RSB R7, R7, R1
__symbolstub1:0049839C STR R7, [R6,#0xBC]
__symbolstub1:004983A0 LDMFD SP!, {R3-R11,PC}
__symbolstub1:004983A0 ; End of function sub_49828C
__symbolstub1:004983A0
__symbolstub1:004983A0 ; 

Updated by zzmutu
Posted

Did u try set $r4=$r7 wothout 0x dude 0x is for when u set it to a new hex like set *0xoffset=0xhex

Or try set $r4=99999

i set $r4=0x99999 only 

 

whether "$r4=0x999" or "$r4=$r7"

how converted to just like [0xoffset,0xhex]

in this way ,make a patcher.

Posted

U mean u want to make it a tweak or a patcher?

yes,i think so 

 

because i learned code inject tut from DIDA/airmax  etc

 

they always found offset /funtion/data

 

then done such as :

 

offset:0xaddress

 

STR R4, [R6,#0x98] ----------->STR  R7, [R6,#0x98]

 

tweak like this:writeData(0xoffset, 0xhex)

 

because once run ,app will crash

_________________​_________________​_________________

if i want to change register value,(set $r4=0xhex  or set $r4=$r7) 

 

which is my offset and hex for make a patcher.

 

 

 

 

 

i am so sorry for pool english.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Galaxy Defense: Fortress TD v0.8.9 [+2 Cheats]
      Modded/Hacked App: Galaxy Defense: Fortress TD By CYBERJOY LIMITED
      Bundle ID: com.cyberjoy.galaxydefense
      App Store Link: https://apps.apple.com/us/app/galaxy-defense-fortress-td/id6740189002?uo=4



      🤩 Hack Features

      - One Hit Kill
      - Activate SVIP
       
        • Agree
        • Winner
        • Like
      • 20 replies
    • Galaxy Defense: Fortress TD v0.8.9 [+2 Jailed Cheats]
      Modded/Hacked App: Galaxy Defense: Fortress TD By CYBERJOY LIMITED
      Bundle ID: com.cyberjoy.galaxydefense
      App Store Link: https://apps.apple.com/us/app/galaxy-defense-fortress-td/id6740189002?uo=4



      🤩 Hack Features

      - One Hit Kill
      - Activate SVIP
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 5 replies
    • Run! Goddess v1.0.17 [+4 Jailed Cheats]
      Modded/Hacked App: Run! Goddess By TOP GAMES INC.
      Bundle ID: com.topgamesinc.rg
      iTunes Store Link: https://apps.apple.com/us/app/run-goddess/id6667111749?uo=4



      🤩 Hack Features

      - No Skill Cooldown
      - Slow Enemy
      - Enemy Can't Attack (Enemy Can't Do Damage)
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 75 replies
    • Run! Goddess v1.0.17 [+4 Cheats]
      Modded/Hacked App: Run! Goddess By TOP GAMES INC.
      Bundle ID: com.topgamesinc.rg
      iTunes Store Link: https://apps.apple.com/us/app/run-goddess/id6667111749?uo=4

       

      🤩 Hack Features

      - No Skill Cooldown
      - Slow Enemy
      - Enemy Can't Attack (Enemy Can't Do Damage)
       
        • Informative
        • Agree
        • Thanks
        • Winner
        • Like
      • 68 replies
    • Eternium Cheats v1.37.7 +11
      Modded/Hacked App: Eternium By Making Fun, Inc.
      Bundle ID: com.makingfun.mageandminions
      iTunes Store Link: https://apps.apple.com/us/app/eternium/id579931356?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - 5K Gems When Completed Stage
      - Infinite Gold
      - Infinite Cosmetic
      - Infinite Yellow Stone
      - Multiply Attack (Linked with Enemy)
      - No Skills Cooldown
      - No Consumable Cooldown
      - Multiply Attack Speed
      - Instant Regen Health
      - Always Crit
      - Material Drops (When you killed an Enemy it will drop materials for crafts)



      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/194526-eternium-cheats-v13355-6/
        • Informative
        • Agree
        • Winner
        • Like
      • 75 replies
    • Candy Crush Saga v1.304.1 Jailed Cheats +3
      Modded/Hacked App: Candy Crush Saga By King.com Limited
      Bundle ID: com.midasplayer.apps.candycrushsaga
      iTunes Store Link: https://apps.apple.com/us/app/candy-crush-saga/id553834731?uo=4


      Hack Features:
      - Infinite Life
      - Infinite Booster
      - Infinite Move


      Jailbreak required hack(s): https://iosgods.com/topic/190447-candy-crush-saga-cheats-v12941-3/


      iOS Hack Download IPA Link: https://iosgods.com/topic/190448-candy-crush-saga-v12941-jailed-cheats-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 96 replies
    • [ JP / Global/ KR] Puzzle & Dragons Cheats v22.3.0 +3
      Modded/Hacked App: Puzzle & Dragons (English) by GungHo Online Entertainment, INC.
      Bundle ID: jp.gungho.padEN
      iTunes Store Link: https://apps.apple.com/us/app/puzzle-dragons-english/id563474464?uo=4&at=1010lce4


      Hack Features:
      - God Mode
      - OHK
      - Frozen Enemies


      iOS Hack Download Link: https://iosgods.com/topic/133984-puzzle-dragons-jp-english-cheats-all-versions-3/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 454 replies
    • DomiNation Asia By NEXON Company v12.1480.1481 - [ Currencies Freeze & More ]
      Modded/Hacked App: ドミネーションズ -文明創造- (DomiNations) By NEXON Company
      Bundle ID: com.nexon.dominations.asia
      iTunes Store Link: https://itunes.apple.com/jp/app/ドミネーションズ-文明創造-dominations/id1012778321


      Hack Features:
      - Unlimited Crowns/Food/Oil/Gold -> Resources will add instead of subtracting. Works with Crowns. Read note inside the feature for more information! This does not work for speeding up buildings.
      - All Achievements Unlocked 
      - Freeze Crowns/Food/Oil/Gold -> Freezes Resources so they do not decrease when used! This does not work for speeding up buildings.
      - No Citizen Cost 
      - 0 Cost to Speed Up Training Troops
      - 0 Cost to Speed Up Tactics
      - 0 Food Cost to Train Troops
      - 0 Food Cost to Upgrade Troops
      - No Timer to Upgrade Troops
      - 0 Food Cost to Train Spells
      - 0 General Train Cost
      - No General Train CoolDown
      - 0 Food Cost to Build Wonder
      - 0 Food Cost to Research Troops
      - 0 Food Cost to Upgrade Tactics
      - No Timer to Library Research
      - No Timer to Upgrade Spells
      - 0 Cost to Upgrade Buildings
      - 0 Workers Required to Upgrade
      - 0 Crown Cost For Peace

      This hack works on the latest x64 or ARM64 & ARM64e iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, Xr, Xs, Xs Max, 11, 11 Pro, 11 Pro Max, 12, 12 Pro, 12 Pro Max, 12 Mini, 13, 13 Pro, 13 Pro Max, 13 Mini, 14, 14 Plus, 14 Pro, 14 Pro Max, SE, iPod Touch 6G, 7G, iPad Air, Air 2, iPad Pro & iPad Mini 2, 3, 4, 5, 6 and later.


      Global hack(s): https://iosgods.com/topic/50401-ultrahack-dominations-v6660661-40-cheats-iosgods-exclusive/?tab=comments#comment-1582742
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,100 replies
    • DomiNations v12.1480.1481 +40++ Cheats [ Exclusive ]
      Modded/Hacked App: DomiNations by NEXON M Inc.
      Bundle ID: com.nexonm.dominations
      iTunes Store Link: https://itunes.apple.com/us/app/dominations/id922558758


      Mod Requirements:
      - Jailbroken iPhone/iPad/iPod Touch.
      - iFile / Filza / iFunBox / iTools or any other file managers for iOS.
      - Cydia Substrate (from Cydia).
      - PreferenceLoader (from Cydia).


      Hack Features:
      - Unlimited Crowns/Food/Oil/Gold -> Resources will add instead of subtracting. Works with Crowns. Read note inside the feature for more information! This does not work for speeding up buildings.
      - All Achievements Unlocked
      - Freeze Crowns/Food/Oil/Gold -> Freezes Resources so they do not decrease when used! This does not work for speeding up buildings.
      - No Citizens Cost
      - Place Multiple of Same Building
      - 0 Cost to Speed Up Training Troops
      - 0 Cost to Speed Up Tactics
      - 0 Food Cost to Train Troops
      - 0 Food Cost to Upgrade Troops
      - No Timer to Upgrade Troops
      - 0 Food Cost to Train Spells
      - 0 General Train Cost
      - No General Train Cooldown
      - 0 Food Cost to Build Wonder
      - 0 Food Cost to Research Troops
      - 0 Food Cost to Upgrade Tactics
      - No Timer to Library Research
      - No Timer to Upgrade Spells
      - 0 Cost to Upgrade Buildings
      - 0 Workers Required to Upgrade
      This hack is an In-Game Mod Menu (iGMM). In order to activate the Mod Menu, tap on the iOSGods button found inside the app.
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 4,984 replies
    • Monster Legends: Collect all Cheats v17.9.5 +8
      Modded/Hacked App: Monster Legends: Merge RPG By Socialpoint
      Bundle ID: es.socialpoint.MonsterCity
      iTunes Store Link: https://apps.apple.com/us/app/monster-legends-merge-rpg/id653508448?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Cydia, Sileo or Zebra).

       

      🤩 Hack Features

      - 1 Hit Kill
      - Skip Enemy Turn
      - Multiply Attack
      - Multiply Defense
      - Insane Score (Always 3 Stars)
      - No Skill Cost
      - Auto Win
      - Auto Play Battle Enabled for All Maps


      🍏 For Non-Jailbroken & No Jailbreak required hacks: https://iosgods.com/topic/140543-monster-legends-collect-all-v1778-5-cheats-for-jailed-idevices/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/176914-monster-legends-collect-all-cheats-v1779-8/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 339 replies
    • Simply Piano: Learn Piano Fast Modded v9.10.14 +1
      Modded/Hacked App: Simply Piano: Learn Piano Fast By Simply Ltd
      Bundle ID: com.joytunes.asla
      iTunes Store Link: https://apps.apple.com/us/app/simply-piano-learn-piano-fast/id1019442026?uo=4


      Hack Features:
      - PREMIUM
       

      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/68652-simply-piano-v975-jailed-mod-1/


      Hack Download Link: https://iosgods.com/topic/83369-simply-piano-learn-piano-fast-modded-all-versions-1/
        • Informative
        • Agree
        • Haha
        • Thanks
        • Winner
        • Like
      • 1,540 replies
    • [ Chiikawa Pocket JP ] ちいかわぽけっと v1.2.0 Jailed Cheats +3
      Modded/Hacked App: ちいかわぽけっと By Applibot Inc.
      Bundle ID: jp.co.applibot.chiikawapocket
      iTunes Store Link: https://apps.apple.com/jp/app/%E3%81%A1%E3%81%84%E3%81%8B%E3%82%8F%E3%81%BD%E3%81%91%E3%81%A3%E3%81%A8/id6596745408?uo=4

       

      📌 Mod Requirements

      - Non-Jailbroken/Jailed or Jailbroken iPhone or iPad.
      - Sideloadly or alternatives.
      - Computer running Windows/macOS/Linux with iTunes installed.

       

      🤩 Hack Features

      - God Mode
      - Multiply Attack
      - Custom Speed (Customize before Login or Clear stage to get apply)

       

      ⬇️ iOS Hack Download IPA Link: https://iosgods.com/topic/194281-chiikawa-pocket-jp-%E3%81%A1%E3%81%84%E3%81%8B%E3%82%8F%E3%81%BD%E3%81%91%E3%81%A3%E3%81%A8-v1111-jailed-cheats-3/
        • Haha
        • Like
      • 23 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines