Therdel/cssHack

Counter-Strike: Source hack for GNU/Linux and Windows

★ 25Forks 3C++GitHub ↗Compare
game-hackingreverse-engineering

README

Cross Platform Counter-Strike: Source hack

for GNU/Linux and Windows
360_hack.mp4

Features

  • Bunnyhop
  • Aimbot
    • 360 NoScope Aimbot
    • Aim by FOV / Distance
    • Aimkey
    • Autoshoot
    • No Recoil
    • No Visual Recoil
  • Triggerbot
    • 360 NoScope Triggerbot
  • Visuals
    • Real Crosshair / Effective Bullet Angles
    • Draw effective FOV
    • Player Position/Orientation
  • Ingame Cheat Menu
  • Panic Key (disable everything on button press)

Media

  • FOV Aimbot
  • 360 Aimbot
  • Bunnyhop
  • Player Position/Orientation
  • NoRecoil
  • Bullet ESP

Techniques used

  • Code injection
    • Windows: CreateRemoteThread/LoadLibrary Method
    • GNU/Linux: GDB attach/dlopen script
  • Detouring / Hooking
    • Detour to thiscall / generic lambda
    • Trampolines / Thunking
    • Mid function / jmp detour
    • Call redirection
  • Auto offsets (Game update resistance)

Credits

  • aixxe - GNU/Linux SO injection

Getting Started

Building

  1. [only for GNU/Linux]
    install compiler & tools
    sudo apt-get install cmake ninja clang clang-tools
    install packages for 32bit compilation (game is 32bit only)
    sudo apt-get install gcc-multilib g++-multilib
    install OpenGL dev lib used for rendering
    sudo apt-get install libgl-dev libxext-dev libudev-dev libxkbcommon-dev
    [only for Windows]
    install compiler, tools & Windows SDK
    winget install --id=Kitware.CMake -e
    winget install --id=Ninja-build.Ninja -e
    winget install -i LLVM.LLVM
    TODO TEST (doesn't work, no package matching input criteria) winget install -e --id Microsoft.WindowsSDK
    install latest Windows SDK by installing Visual Studio
  2. clone repository
    git clone https://github.com/Therdel/cssHack.git --recurse-submodules --shallow-submodules --depth=1
    cd cssHack
  3. build
    # configure build
    cmake -DCMAKE_BUILD_TYPE:STRING=Debug -DCMAKE_EXPORT_COMPILE_COMMANDS:BOOL=TRUE -DCMAKE_C_COMPILER:FILEPATH=/usr/bin/clang -DCMAKE_CXX_COMPILER:FILEPATH=/usr/bin/clang++ --no-warn-unused-cli -S . -B ./build -G Ninja
    
    # build
    cmake --build ./build --config Debug --target all --parallel

Injecting use at your own risk

Windows

Winject 1.7 is easy to use use at your own risk. Get it from e.g. oldschoolhack.me

GNU/Linux

  • I bundled three scripts in the scripts/ directory: inject.bash, eject.bash & reinject.bash. I adapted aixxe's idea for these.
  • You may have to adapt paths in the scripts.
  • These attach the GDB Debugger to the game process for injection. Doing this to a process we haven't started isn't allowed under normal circumstances. So execute scripts/disable_ptrace_scope.bash with sudo privileges once per login session to use these scripts.

Development & Debugging

VSCode extensions (see .vscode/extensions.json):

Counter-Strike: Source version

Working Cheat-Engine Version

Cheat-Engine 7.1

TODO

  • Fix Panic Key (now: works only directly after injecting)
  • bump all cmakelists versions
  • windows SDK without visual studio install
  • windows manifest
  • downgrading tutorial (from up-to-date to linux + windows)
  • isCrouching (better: BoneAim)
  • don't aim at kicked bots at (0,0,0)
  • Autopistol
    • using s_client_localplayer_shotsfired - if wearing a pistol, let go if it turns 1
  • BSP Parsing
  • Bone Matrix
    • implementation

      • manually
        1. get position of player head bone via footpos+viewHeight+-5
        2. find bonematrix candidate(s) base ptr
        3. repeat for a bot with bot_mimic - but have them on a different height and use their radar foot pos
        4. find that bonematrix candiate(s) base ptr
        5. do pointer scan for both
        6. both pointers must rely in a similar location - the entity list
      • ?location
      • Use source SDK, via CreateInterface
    • position: 2287AA2C maybe_bonelist 23533A9C probably_bonelist 23533800 bonelist_beg 2353415C short_bonelist_3x4x9 231EF568 > bonlist_beg 231EF800 > bonlist_beg 231EF810 > bonlist_beg

      231EF0E0 localplayer_viewoffsetZ 231EF258 localplayer_pos_feet

    • Features

      • All-bone aim (max dmg)
      • ESP: Skeleton
      • ESP: Correct Box ESP
  • Use Source SDK (also see Bone Matrix, duplicate info)
    • how to use CreateInterface to actually get interfaces?

      • use dlsym/MemoryUtils::getSymbolAddress(libNames::client, "CreateInterface")
      • source: sp/src/public/tier1/interface.h::DLL_EXPORT void* CreateInterface(const char *pName, int *pReturnCode)
      • use IDA to look for CreateInterface symbol or smth
    • filter Players: source0

      • IClientEntityList::GetClientEntity(int) for 0..64
      • check for null
      • static_cast to C_BaseEntity
      • check bool C_BaseEntity::IsPlayer()
      • get C_BaseAnimating* from C_BaseAnimating* C_BaseEntity::GetBaseAnimating()
        • CBoneAccessor C_BaseAnimating::m_BoneAccessor -> cast to derived class
        • const matrix3x4_t& CBoneAccessor::GetBone( int iBone ) const
        • ? ... bool C_BaseAnimating::SetupBones( matrix3x4_t *pBoneToWorldOut, int nMaxBones, [..])?
      • IPlayerInfo *CBasePlayer::GetPlayerInfo()
        • IPlayerInfo
          • getHealth()
          • getName()
          • GetTeamIndex()
          • IsConnected() (if the Player slot is valid)
          • GetArmorValue()
          • GetWeaponName()
          • GetLastUserCommand()
    • IBaseClientDLL::CreateMove

    • Interesting Interfaces

  • Netvars code frk1/hazedumper-rs

Contributors

Therdel

Issues