feat(anticheat): preliminary AC research

This commit is contained in:
maybegreat48
2025-06-17 15:41:47 -04:00
parent a237507799
commit 45cb721ad4
11 changed files with 100 additions and 3 deletions
+1
View File
@@ -21,6 +21,7 @@ namespace YimMenu
BaseHook::Add<Hooks::Anticheat::GetThreadContext>(new DetourHook("GetThreadContext", reinterpret_cast<void*>(GetProcAddress(LoadLibraryA("kernel32.dll"), "GetThreadContext")), Hooks::Anticheat::GetThreadContext));
BaseHook::Add<Hooks::Anticheat::HttpStartRequest>(new DetourHook("HttpStartRequest", Pointers.HttpStartRequest, Hooks::Anticheat::HttpStartRequest));
BaseHook::Add<Hooks::Anticheat::BattlEyeServerProcessPlayerJoin>(new DetourHook("BattlEyeServerProcessPlayerJoin", Pointers.BattlEyeServerProcessPlayerJoin, Hooks::Anticheat::BattlEyeServerProcessPlayerJoin));
BaseHook::Add<Hooks::Anticheat::GetAnticheatInitializedHash>(new DetourHook("GetAnticheatInitializedHash", Pointers.GetAnticheatInitializedHash, Hooks::Anticheat::GetAnticheatInitializedHash));
BaseHook::Add<Hooks::Script::RunScriptThreads>(new DetourHook("RunScriptThreads", Pointers.RunScriptThreads, Hooks::Script::RunScriptThreads));
BaseHook::Add<Hooks::Script::InitNativeTables>(new DetourHook("InitNativeTables", Pointers.InitNativeTables, Hooks::Script::InitNativeTables));
+18
View File
@@ -52,6 +52,7 @@ namespace YimMenu
continue;
patched = true;
// TODO: this is integrity checked now
reinterpret_cast<rage::gameSkeletonUpdateElement*>(group_child_node)->m_Function = reinterpret_cast<void (*)()>(Pointers.Nullsub);
}
break;
@@ -76,9 +77,26 @@ namespace YimMenu
}
}
void AnticheatBypass::RunOnStartupImpl()
{
bool loaded_late = false;
if (!*Pointers.AnticheatInitializedHash)
{
*Pointers.AnticheatInitializedHash = new rage::Obf32; // this doesn't get freed so we don't have to use the game allocator
(*Pointers.AnticheatInitializedHash)->setData(0x124EA49D);
}
else
{
(*Pointers.AnticheatInitializedHash)->setData(0x124EA49D);
loaded_late = true;
}
}
void AnticheatBypass::RunScriptImpl()
{
DefuseSigscanner();
NativeHooks::AddHook("shop_controller"_J, NativeIndex::NET_GAMESERVER_BEGIN_SERVICE, &TransactionHook);
m_IsFSLLoaded = CheckForFSL();
+6
View File
@@ -11,6 +11,7 @@ namespace YimMenu
return instance;
}
void RunOnStartupImpl();
void RunScriptImpl();
bool m_IsFSLLoaded = false;
@@ -20,6 +21,11 @@ namespace YimMenu
bool m_FSLProvidesBEBypass = false;
public:
static void RunOnStartup()
{
GetInstance().RunOnStartupImpl();
}
static void RunScript()
{
GetInstance().RunScriptImpl();
@@ -0,0 +1,10 @@
#include "core/hooking/DetourHook.hpp"
#include "game/hooks/Hooks.hpp"
namespace YimMenu::Hooks
{
std::uint32_t Anticheat::GetAnticheatInitializedHash()
{
return 0x124EA49D;
}
}
+1
View File
@@ -42,6 +42,7 @@ namespace YimMenu::Hooks
extern BOOL GetThreadContext(HANDLE hThread, LPCONTEXT lpContext);
extern void HttpStartRequest(void* request);
extern bool BattlEyeServerProcessPlayerJoin(CBattlEyePlayerModifyInterface* server_iface, CBattlEyePlayerModifyContext* context);
extern std::uint32_t GetAnticheatInitializedHash();
}
namespace Info
+4 -3
View File
@@ -395,9 +395,10 @@ namespace YimMenu
GameSkeleton = ptr.Add(0x9).Add(3).Rip().As<rage::gameSkeleton*>();
});
constexpr auto SetExplosiveAmmoOnlinePatchPtrn = Pattern<"48 83 EC 28 80 3D ? ? ? ? 00 0F 85 ? ? ? ? E9 ? ? ? ? 56 57 53 48 81 EC B0 00 00 00">("SetExplosiveAmmoOnlinePatch");
scanner.Add(SetExplosiveAmmoOnlinePatchPtrn, [this](PointerCalculator ptr) {
BytePatches::Add(ptr.Add(0xB).As<std::uint16_t*>(), 0x04EB)->Apply();
constexpr auto anticheatInitializedHashPtrn = Pattern<"89 9E C8 00 00 00 48 8B 0D ? ? ? ? 48 85 C9 74 46">("AnticheatInitializedHash");
scanner.Add(anticheatInitializedHashPtrn, [this](PointerCalculator ptr) {
AnticheatInitializedHash = ptr.Add(9).Rip().As<rage::Obf32**>();
GetAnticheatInitializedHash = ptr.Add(0x13).Rip().As<PVOID>();
});
if (!scanner.Scan())
+3
View File
@@ -3,6 +3,7 @@
#include <dxgi1_4.h>
#include <windows.h>
#include "types/script/scrNativeHandler.hpp"
#include "types/rage/ObfVar.hpp"
#include "core/memory/BytePatches.hpp"
namespace rage
@@ -156,6 +157,8 @@ namespace YimMenu
Functions::AssistedAimFindNewTarget AssistedAimFindNewTarget;
rage::gameSkeleton* GameSkeleton;
PVOID Nullsub;
rage::Obf32** AnticheatInitializedHash;
PVOID GetAnticheatInitializedHash;
};
struct Pointers : PointerData
+2
View File
@@ -48,6 +48,8 @@ namespace YimMenu
if (!Pointers.Init())
goto EARLY_UNLOAD;
AnticheatBypass::RunOnStartup();
if (!Renderer::Init())
goto EARLY_UNLOAD;
+50
View File
@@ -0,0 +1,50 @@
#pragma once
#include <cstdint>
#include <ctime>
namespace rage
{
template<typename T>
class ObfVar
{
private:
T m_unk1;
T m_unk2;
T m_unk3;
T m_unk4;
public:
T getData()
{
auto v105 = m_unk4;
auto v28 = m_unk1 & v105;
auto v94 = m_unk2 & ~v105;
return v28 | v94;
}
operator T()
{
return getData();
}
void setData(T val)
{
auto seed = time(nullptr);
m_unk3 = seed;
seed = time(nullptr);
m_unk4 = seed;
auto v48 = val & ~seed;
m_unk1 = seed & val;
m_unk2 = v48;
}
void operator=(T val)
{
setData(val);
}
};
using Obf16 = ObfVar<unsigned short>;
using Obf32 = ObfVar<unsigned int>;
}
+2
View File
@@ -21,6 +21,8 @@ namespace rage
{
virtual ~gameSkeletonUpdateBase() = default;
virtual void Run() = 0;
virtual bool ShouldIntegrityCheck() = 0;
uint64_t m_Pad; // 0x08
uint32_t m_Hash; // 0x10
gameSkeletonUpdateBase* m_Next; // 0x18
@@ -410,6 +410,9 @@ enum class eSimpleInteriorIndex
SIMPLE_INTERIOR_BAIL_OFFICE_WEST_VINEWOOD,
SIMPLE_INTERIOR_HACKER_DEN,
SIMPLE_INTERIOR_FIELD_HANGAR,
SIMPLE_INTERIOR_SMALL_BUSINESS_CAR_WASH,
SIMPLE_INTERIOR_SMALL_BUSINESS_WEED_SHOP,
SIMPLE_INTERIOR_SMALL_BUSINESS_HELI_TOURS,
SIMPLE_INTERIOR_MAX
};