360_hack.mp4
- Bunnyhop
- Aimbot
- 360 NoScope Aimbot
- Aim by FOV / Distance
- Aimkey
- Autoshoot
- No Recoil
- No Visual Recoil
- Triggerbot
- 360 NoScope Triggerbot
- Visuals
- Real Crosshair / Effective Bullet Angles
- Draw effective FOV
- Player Position/Orientation
- Ingame Cheat Menu
- Panic Key (disable everything on button press)
- FOV Aimbot
- 360 Aimbot
- Bunnyhop
- Player Position/Orientation
- NoRecoil
- Bullet ESP
- Code injection
- Windows: CreateRemoteThread/LoadLibrary Method
- GNU/Linux: GDB attach/dlopen script
- Detouring / Hooking
- Detour to thiscall / generic lambda
- Trampolines / Thunking
- Mid function / jmp detour
- Call redirection
- Auto offsets (Game update resistance)
- Signature Scanning to stay functional after game binary changes
(Own variation of BoyerMoore)
- Signature Scanning to stay functional after game binary changes
- aixxe - GNU/Linux SO injection
- [only for GNU/Linux]
install compiler & toolsinstall packages for 32bit compilation (game is 32bit only)sudo apt-get install cmake ninja clang clang-tools
install OpenGL dev lib used for renderingsudo apt-get install gcc-multilib g++-multilib
[only for Windows]sudo apt-get install libgl-dev libxext-dev libudev-dev libxkbcommon-dev
install compiler, tools & Windows SDKinstall latest Windows SDK by installingwinget install --id=Kitware.CMake -e winget install --id=Ninja-build.Ninja -e winget install -i LLVM.LLVM TODO TEST (doesn't work, no package matching input criteria) winget install -e --id Microsoft.WindowsSDKVisual Studio - clone repository
git clone https://github.com/Therdel/cssHack.git --recurse-submodules --shallow-submodules --depth=1 cd cssHack - build
# configure build cmake -DCMAKE_BUILD_TYPE:STRING=Debug -DCMAKE_EXPORT_COMPILE_COMMANDS:BOOL=TRUE -DCMAKE_C_COMPILER:FILEPATH=/usr/bin/clang -DCMAKE_CXX_COMPILER:FILEPATH=/usr/bin/clang++ --no-warn-unused-cli -S . -B ./build -G Ninja # build cmake --build ./build --config Debug --target all --parallel
Winject 1.7 is easy to use use at your own risk. Get it from e.g. oldschoolhack.me
- I bundled three scripts in the
scripts/directory: inject.bash, eject.bash & reinject.bash. I adapted aixxe's idea for these. - You may have to adapt paths in the scripts.
- These attach the GDB Debugger to the game process for injection. Doing this to a process we haven't started isn't allowed under normal circumstances. So execute
scripts/disable_ptrace_scope.bashwith sudo privileges once per login session to use these scripts.
VSCode extensions (see .vscode/extensions.json):
- C/C++ Extension Pack
- CodeLLDB debug using LLDB, as lib is built using Clang(LLVM)
- this hack was made for the 32bit version and thus broke with the 64bit update in Feb 2025
- you can try it out locally by downgrading to Build 17399420, the last 32bit version
- see this guide to downgrade with the Steam console
- see Linux version manifest in ./game_cfg/appmanifest_240.acf
Cheat-Engine 7.1
- Fix Panic Key (now: works only directly after injecting)
- bump all cmakelists versions
- windows SDK without visual studio install
- windows manifest
- downgrading tutorial (from up-to-date to linux + windows)
- isCrouching (better: BoneAim)
- don't aim at kicked bots at (0,0,0)
- Autopistol
- using s_client_localplayer_shotsfired - if wearing a pistol, let go if it turns 1
- BSP Parsing
- implementation
- Valve BSP docs
- algorithm
- source SDK 2013 Parser?
- source SDK 2013 Raytracer?
- ReactiioN1337/valve-bsp-parser
- access Bones: CBoneAccessor
- CSS-external cheat with BSP Parsing source
- Features
- Aimbot: Visible only
- Aimbot: Prioritize Enemies seeing me (90° FOV cone trace)/ aiming at me (narrower cone trace)
- ESP: Visibility
- ESP: Sees me
- ESP: Aims at me
- ESP: HEAD Emoji
- implementation
- Bone Matrix
-
implementation
- manually
- get position of player head bone via footpos+viewHeight+-5
- find bonematrix candidate(s) base ptr
- repeat for a bot with bot_mimic - but have them on a different height and use their radar foot pos
- find that bonematrix candiate(s) base ptr
- do pointer scan for both
- both pointers must rely in a similar location - the entity list
- ?location
- Use source SDK, via CreateInterface
- manually
-
position: 2287AA2C maybe_bonelist 23533A9C probably_bonelist 23533800 bonelist_beg 2353415C short_bonelist_3x4x9 231EF568 > bonlist_beg 231EF800 > bonlist_beg 231EF810 > bonlist_beg
231EF0E0 localplayer_viewoffsetZ 231EF258 localplayer_pos_feet
-
Features
- All-bone aim (max dmg)
- ESP: Skeleton
- ESP: Correct Box ESP
-
- Use Source SDK (also see Bone Matrix, duplicate info)
-
how to use CreateInterface to actually get interfaces?
- use dlsym/
MemoryUtils::getSymbolAddress(libNames::client, "CreateInterface") - source:
sp/src/public/tier1/interface.h::DLL_EXPORT void* CreateInterface(const char *pName, int *pReturnCode) - use IDA to look for CreateInterface symbol or smth
- use dlsym/
-
filter Players: source0
IClientEntityList::GetClientEntity(int)for 0..64- check for null
static_casttoC_BaseEntity- check
bool C_BaseEntity::IsPlayer() - get
C_BaseAnimating*fromC_BaseAnimating* C_BaseEntity::GetBaseAnimating()CBoneAccessor C_BaseAnimating::m_BoneAccessor-> cast to derived classconst matrix3x4_t& CBoneAccessor::GetBone( int iBone ) const- ? ...
bool C_BaseAnimating::SetupBones( matrix3x4_t *pBoneToWorldOut, int nMaxBones, [..])?
-
IPlayerInfo *CBasePlayer::GetPlayerInfo()- IPlayerInfo
getHealth()getName()GetTeamIndex()IsConnected()(if the Player slot is valid)GetArmorValue()GetWeaponName()GetLastUserCommand()
- IPlayerInfo
-
Interesting Interfaces
- mp/src/public/engine/IEngineTrace.h::IEngineTrace
- master: IEngineTrace
- mp/src/game/client/cliententitylist.cpp::IClientEntityList
- master: src/public/icliententitylist.h
- IVDebugOverlay
C_BaseEntity::TraceAttack()
- mp/src/public/engine/IEngineTrace.h::IEngineTrace
-
- Netvars code frk1/hazedumper-rs