Jump to content

6 posts in this topic

Recommended Posts

Posted

Lately quite few people asked about branching, so I figured I make a little write up about it. 

It is not as advanced as it seems, if you understand the code flow and how branches manipulate that.

 

Think about it this way. Branches will break the code flow and execute whatever is at the address where it points to. Similar to water, as it runs in rivers, or turns to a different direction, maybe a new path opens up... Code flow is similar, but we can use conditions ?

Take a good look at this image. 

p88bAVu.png

 

So what we see in there kinda explains what branches are and what they mean. I normally ignore conditional branches as "CBZ, CBNZ, TBZ, TBNZ" as I can get the same effect with a simple unconditional branch "B" to the right loc or a NOP. You can play with them, as you change them around, you'd get the opposite effect "CBZ to CBNZ" and so on.

I'd stick with "B and BL" for now and some examples behind the logic.

 

B - unconditional branching

 

Branch hex value somehow looks like this:

05 00 00 14 

05 00 00 - This is the distance between the start offset and target offset.

14 - branch's opcode. 

1 - unconditional b

4 - branching to a forward address in binary

So basically we branching 5 instructions (or call it 5 lines) forward (underneath if you look at it in ida).

If it looked like this:

05 00 00 17 

7 - branching to a backwards address in the binary.

 

Some examples (note that this is most useful in binaries with symbols):

That word hack game I hacked the other day. Developer left debug functions in the game so I hooked up existing menu buttons with those functions with simple unconditional branching. 

you find the debug function:

BuyGem 100289D20

then find a button to hook it too. I normally search for "click, press" or if it has social media buttons you can search those.

InboxButtonClicked 100074DF8

From here on its pretty straight forward. Load up armconverter.com go to branch tab and add the offsets:

Current offset:  100074DF8 // inbox button

Instruction to write: B #0x100074DF8 // unconditionally branches to BuyGem

you get a hex value. Set that to first line of inbox button. 

 

Other example.

look at this image

AOgmijp.png

 

so we have two options. premium and premium plus. If we want to force premium, we can use branch but if you take a look the offsets, you see we'd have to branch 1 line under so we can just simply NOP the instruction. if we want to get premium + we'd have to branch to that loc address instead. This way we can manipulate the code to flow the way we want it to without conditionals.

 

BL - Branch with link

 

This one works slightly differently. It takes the code flow to another function, executes that and flow returns to the original one and carries on.

80 F6 4B 94

80 F6 4B - distance between the two address

94 - Branch with Link's opcode

9 - Branch with link

4 - branching forward

same as "B" if it was 97 it would branch backwards.

Example:

You find a game with cool down.

BL StartCooldown

Then you see this function: ResetCooldown

Change it to

BL ResetCooldown

What happens in game? When it should execute the function that starts the cool down, it will reset it instead.

 

 

 

  • Like 4
  • Winner 2
  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Our picks

    • Plants vs. Zombies™ 3: Evolved v26.3.6 +4 Mods [ Freeze Resources ]
      Mod APK Game Name: Plants vs. Zombies™ 3: Evolved By Electronic Arts
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.ea.gp.pvzn3xt&hl=en_GB

       

      🤩 Hack Features

      - Freeze Sun
      - Freeze Plant Food
      - Freeze Promotions
      - No Plant Spawn Cooldown
      • 1 reply
    • Resident Evil Survival Unit v1.2.2 +6 Mods [ Damage & Defence ]
      Mod APK Game Name: Resident Evil Survival Unit By Aniplex Inc.
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.aniplex.resu&hl=en_GB

       

      🤩 Hack Features

      - Damage Multiplier [ Battle ]
      - Defence Multiplier [ Battle ]
      - God Mode [ Battle ]
      - God Mode [ Explore ]
      - One-Hit Kill [ Explore ]
      - Freeze Items & Ammo [ Explore ]
      • 1 reply
    • Resident Evil Survival Unit v1.2.2 +6 Jailed Cheats [ Damage & Defence ]
      Modded/Hacked App: Resident Evil Survival Unit By Aniplex Inc.
      Bundle ID: com.aniplex.resu
      App Store Link: https://apps.apple.com/us/app/resident-evil-survival-unit/id6744668327?uo=4

       
       

      🤩 Hack Features

      - Damage Multiplier [ Battle ]
      - Defence Multiplier [ Battle ]
      - God Mode [ Battle ]
      - God Mode [ Explore ]
      - One-Hit Kill [ Explore ]
      - Freeze Items & Ammo
      • 59 replies
    • Resident Evil Survival Unit v1.2.2 +6 Cheats [ Damage & Defence ]
      Modded/Hacked App: Resident Evil Survival Unit By Aniplex Inc.
      Bundle ID: com.aniplex.resu
      App Store Link: https://apps.apple.com/us/app/resident-evil-survival-unit/id6744668327?uo=4

       


      🤩 Hack Features

      - Damage Multiplier [ Battle ]
      - Defence Multiplier [ Battle ]
      - God Mode [ Battle ]
      - God Mode [ Explore ]
      - One-Hit Kill [ Explore ]
      - Freeze Items & Ammo
      • 63 replies
    • Hunt Royale: Action RPG Battle v3.20.0 +3 Mods [ Damage & Defence ]
      Mod APK Game Name: Hunt Royale: Action RPG Battle By BoomBit, Inc.
      Rooted Device: Not Required.
      Google Play Store Link: https://play.google.com/store/apps/details?id=com.hunt.royale&hl=en_GB

       

      🤩 Hack Features

      - Damage Multiplier
      - Defence Multiplier
      - God Mode
      • 1 reply
    • Merge Cruise: Mystery Puzzle v0.37.130 [ +2 Cheats ] Currency Max
      Modded/Hacked App: Merge Cruise: Mystery Puzzle By STUDIO PEERPLAY GAMES LTD
      Bundle ID: com.peerplay.megamerge
      iTunes Store Link: https://apps.apple.com/us/app/merge-cruise-mystery-puzzle/id6459056553?uo=4
       

      🤩 Hack Features

      - Cash
      - Energy

      • 36 replies
    • Merge Cruise: Mystery Puzzle v0.37.130 [ +2 Jailed ] Currency Max
      Modded/Hacked App: Merge Cruise: Mystery Puzzle By STUDIO PEERPLAY GAMES LTD
      Bundle ID: com.peerplay.megamerge
      iTunes Store Link: https://apps.apple.com/us/app/merge-cruise-mystery-puzzle/id6459056553?uo=4
       

      🤩 Hack Features

      - Cash
      - Energy

      • 38 replies
    • Fallout Shelter v1.22.9 Unlimited Currency for Non-Jailbroken Devices!
      Modded/Hacked App: Fallout Shelter by Bethesda Softworks LLC
      Bundle ID: com.bethsoft.falloutshelter
      iTunes Store Link: https://apps.apple.com/us/app/fallout-shelter/id991153141


      Hack Features:
      - Freeze Food, Water, Power, Caps, Nukabottle, Medkits, Stimpex...
       

      This hack only supports x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Jailbroken version of this hack: https://iosgods.com/topic/43926-fallout-shelter-v1131-15-groundbreaking-cheats/
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 3,313 replies
    • Fallout Shelter v1.22.9 +16 Groundbreaking CHEATS
      Modded/Hacked App: Fallout Shelter By Bethesda
      Bundle ID: com.bethsoft.falloutshelter
      iTunes Link: https://itunes.apple.com/us/app/fallout-shelter/id991153141


      Hack Features:
      - Dwellers instant level up
      - Freeze All Currencies
      - One Hit Kill
      - Add Stuff Instead of removing

      - Dwellers Never Die / God Mode

      (DO NOT COLLECT FROM BUILDINGS WILL CAUSE CRASH GET YOU DESIRED AMOUNT THEN TURN THE HACK OFF AND ENABLE FREEZE)

      - FREEZE  FOOD/WATER/POWER/CAPS/NUKABOTTLE/MEDIKITS/STIMPEX
      - Unlock all rooms etc and auto complete objectives / unlimited lunch boxes cola caps etc 

       

      After logging in to your iOSGods account, tap your screen with 3 fingers to bring up the iGMM. This hack only works on x64 or ARM64 iDevices: iPhone 5s, 6, 6 Plus, 6s, 6s Plus, 7, 7 Plus, 8, 8 Plus, X, SE, iPod Touch 6G, iPad Air, Air 2, Pro & iPad Mini 2, 3, 4 and later.


      Non-Jailbroken & No Jailbreak required hack(s): https://iosgods.com/topic/43928-fallout-shelter-v1112-unlimited-currency-for-non-jailbroken-devices/?
      Modded Android APK(s): https://iosgods.com/forum/68-android-section/
      For more fun, check out the Club(s): https://iosgods.com/clubs/
      • 2,692 replies
    • Dummynation Cheats v3.4.7 +3
      Modded/Hacked App: Dummynation By ALEJANDRO HERNANDEZ FERRERO
      Bundle ID: ahf.dummynation
      iTunes Store Link: https://apps.apple.com/us/app/dummynation/id6444295551?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Cydia, Sileo or Zebra).

       

      🤩 Hack Features

      - Premium + No Ads
      - Infinite Research Point
      - Infinite Liquidity (Gold)


      🍏 For Non-Jailbroken & No Jailbreak required hacks: https://iosgods.com/topic/191828-dummynation-v313-jailed-cheats-3/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/191829-dummynation-cheats-v313-3/
      • 25 replies
    • Sniper 3D: Gun Shooting Games Cheats v6.9.0 +7
      Modded/Hacked App: Sniper 3D Assassin: FPS Battle By Fun Games For Free
      Bundle ID: com.fungames.sniper3d
      iTunes Store Link: https://itunes.apple.com/us/app/sniper-3d-assassin-fps-battle/id930574573?mt=8&uo=4&at=1010lce4



      Hack Features:
      - Infinite Coins Only (Upgrade Weapon and Speed up Delivery with Coins)
      - Infinite Energy
      - Infinite Ammo / No Reload
      - No Spread
      - Unlock Premium Weapon - Semi

      NOTE: The game diamond currency is completely server-sided so do not request


      Hack Download Link: https://iosgods.com/topic/74114-arm64-sniper-3d-fps-battle-shoot-to-kill-2018-cheats-all-versions-7/

      Credits:
      - @Laxus
      • 3,933 replies
    • Found It! Hidden Object Game Cheats v1.58.46 +4
      Modded/Hacked App: Found It! Hidden Object Game By Lion Studios Plus LLC
      Bundle ID: games.urmobi.found.it
      App Store Link: https://apps.apple.com/us/app/found-it-hidden-object-game/id1643547847?uo=4

       

      📌 Mod Requirements

      - Jailbroken iPhone or iPad.
      - iGameGod / Filza / iMazing.
      - Cydia Substrate, ElleKit, Substitute or libhooker depending on your jailbreak (from Sileo, Cydia or Zebra).

       

      🤩 Hack Features

      - Infinite Boosters
      - Free Store (not Free iAP)
      - No Ads Enabled
      - Premium Maps Enabled

       

      Free Non-Jailbroken Hack: https://iosgods.com/topic/196821-found-it-hidden-object-game-v148304-jailed-cheats-4/

       

      ⬇️ iOS Hack Download Link: https://iosgods.com/topic/196820-found-it-hidden-object-game-cheats-v148304-4/
      • 5 replies
×
  • Create New...

Important Information

We would like to place cookies on your device to help make this website better. The website cannot give you the best user experience without cookies. You can accept or decline our cookies. You may also adjust your cookie settings. Privacy Policy - Guidelines