fix(anticheat): improve anticheat bypass

This commit is contained in:
maybegreat48
2025-06-19 02:05:21 -04:00
parent 16509bcc7d
commit 68bbf17ff4
9 changed files with 75 additions and 3 deletions
+1 -1
View File
@@ -58,6 +58,6 @@ namespace YimMenu
std::shared_ptr<Submenu> m_ActiveSubmenu;
std::vector<std::shared_ptr<Submenu>> m_Submenus;
ImFont* m_OptionsFont = nullptr;
bool m_ShowContentWindow = false;
bool m_ShowContentWindow = true;
};
}
+1
View File
@@ -22,6 +22,7 @@ namespace YimMenu
BaseHook::Add<Hooks::Anticheat::HttpStartRequest>(new DetourHook("HttpStartRequest", Pointers.HttpStartRequest, Hooks::Anticheat::HttpStartRequest));
BaseHook::Add<Hooks::Anticheat::BattlEyeServerProcessPlayerJoin>(new DetourHook("BattlEyeServerProcessPlayerJoin", Pointers.BattlEyeServerProcessPlayerJoin, Hooks::Anticheat::BattlEyeServerProcessPlayerJoin));
BaseHook::Add<Hooks::Anticheat::GetAnticheatInitializedHash>(new DetourHook("GetAnticheatInitializedHash", Pointers.GetAnticheatInitializedHash, Hooks::Anticheat::GetAnticheatInitializedHash));
BaseHook::Add<Hooks::Anticheat::GetAnticheatInitializedHash2>(new DetourHook("GetAnticheatInitializedHash2", Pointers.GetAnticheatInitializedHash2, Hooks::Anticheat::GetAnticheatInitializedHash2));
BaseHook::Add<Hooks::Script::RunScriptThreads>(new DetourHook("RunScriptThreads", Pointers.RunScriptThreads, Hooks::Script::RunScriptThreads));
BaseHook::Add<Hooks::Script::InitNativeTables>(new DetourHook("InitNativeTables", Pointers.InitNativeTables, Hooks::Script::InitNativeTables));
+2 -1
View File
@@ -6,7 +6,8 @@
#include "game/backend/NativeHooks.hpp"
#include "game/gta/Natives.hpp"
#include "types/rage/gameSkeleton.hpp"
#include "types/anticheat/CAnticheatContext.hpp"
#include "types/game_files/CGameDataHash.hpp"
using FnGetVersion = int (*)();
using FnLocalSaves = bool (*)();
@@ -0,0 +1,17 @@
#include "core/hooking/DetourHook.hpp"
#include "game/hooks/Hooks.hpp"
#include "game/pointers/Pointers.hpp"
#include "types/anticheat/CAnticheatContext.hpp"
namespace YimMenu::Hooks
{
std::uint32_t Anticheat::GetAnticheatInitializedHash2(void* ac_var, std::uint32_t seed)
{
auto orig = (*Pointers.AnticheatContext) ? (*Pointers.AnticheatContext)->m_BattlEyeEnabled : false;
(*Pointers.AnticheatContext)->m_BattlEyeEnabled = true; // integ checks will boot us out if we set this outside this function
auto ret = BaseHook::Get<Anticheat::GetAnticheatInitializedHash2, DetourHook<decltype(&Anticheat::GetAnticheatInitializedHash2)>>()->Original()(ac_var, seed);
if (*Pointers.AnticheatContext)
(*Pointers.AnticheatContext)->m_BattlEyeEnabled = orig;
return ret;
}
}
+1
View File
@@ -43,6 +43,7 @@ namespace YimMenu::Hooks
extern void HttpStartRequest(void* request);
extern bool BattlEyeServerProcessPlayerJoin(CBattlEyePlayerModifyInterface* server_iface, CBattlEyePlayerModifyContext* context);
extern std::uint32_t GetAnticheatInitializedHash();
extern std::uint32_t GetAnticheatInitializedHash2(void* ac_var, std::uint32_t seed);
}
namespace Info
+11 -1
View File
@@ -395,12 +395,22 @@ namespace YimMenu
GameSkeleton = ptr.Add(0x9).Add(3).Rip().As<rage::gameSkeleton*>();
});
constexpr auto anticheatInitializedHashPtrn = Pattern<"89 9E C8 00 00 00 48 8B 0D ? ? ? ? 48 85 C9 74 46">("AnticheatInitializedHash");
constexpr auto anticheatInitializedHashPtrn = Pattern<"89 9E C8 00 00 00 48 8B 0D ? ? ? ? 48 85 C9 74 46">("AnticheatInitializedHash&GetAnticheatInitializedHash");
scanner.Add(anticheatInitializedHashPtrn, [this](PointerCalculator ptr) {
AnticheatInitializedHash = ptr.Add(9).Rip().As<rage::Obf32**>();
GetAnticheatInitializedHash = ptr.Add(0x13).Rip().As<PVOID>();
});
constexpr auto anticheatContextPtrn = Pattern<"48 8D BB 70 0A 00 00 4C 8D 35 ? ? ? ? 66 90">("AnticheatContext");
scanner.Add(anticheatContextPtrn, [this](PointerCalculator ptr) {
AnticheatContext = ptr.Sub(0x12).Add(3).Rip().As<CAnticheatContext**>();
});
constexpr auto getAnticheatInitializedHash2Ptrn = Pattern<"89 9E E8 00 00 00 89 C2 E8 ? ? ? ? 69">("GetAnticheatInitializedHash2");
scanner.Add(getAnticheatInitializedHash2Ptrn, [this](PointerCalculator ptr) {
GetAnticheatInitializedHash2 = ptr.Add(0x9).Rip().As<PVOID>();
});
if (!scanner.Scan())
{
LOG(FATAL) << "Some patterns could not be found, unloading.";
+3
View File
@@ -43,6 +43,7 @@ class CStatsMgr;
class CNetShopTransaction;
class CNetworkSession;
class CStatsMpCharacterMappingData;
class CAnticheatContext;
namespace YimMenu
{
@@ -159,6 +160,8 @@ namespace YimMenu
PVOID Nullsub;
rage::Obf32** AnticheatInitializedHash;
PVOID GetAnticheatInitializedHash;
PVOID GetAnticheatInitializedHash2;
CAnticheatContext** AnticheatContext;
};
struct Pointers : PointerData
+26
View File
@@ -0,0 +1,26 @@
#pragma once
#include "types/rage/ObfVar.hpp"
struct CAnticheatContext
{
rage::Obf32 m_LastScanTime;
rage::Obf32 m_ScanInterval;
void* m_ScanData;
rage::Obf32 m_ScanDataSize;
rage::Obf32 m_ScanDataSize2;
rage::Obf32 m_GameBuild;
std::uint64_t qword58;
std::uint32_t dword60;
char gap64[2572];
std::uint32_t dwordA70;
std::uint64_t qwordA78;
std::uint32_t dwordA80;
char gapA84[3];
char byteA87[9];
bool m_DebugBattlEyeEnabled;
bool m_BattlEyeEnabled;
bool m_IsDebugMode;
volatile __int32 m_CurrentScanIndex;
std::uint64_t qwordA98;
};
static_assert(sizeof(CAnticheatContext) == 0xAA0);
+13
View File
@@ -0,0 +1,13 @@
#pragma once
#include "types/rage/ObfVar.hpp"
#include <array>
#pragma pack(push, 8)
class CGameDataHash
{
public:
bool m_IsJapaneseVersion;
std::array<rage::Obf32, 16> m_Data;
};
static_assert(sizeof(CGameDataHash) == 0x104);
#pragma pack(pop)