Breeze search all RW memory but don't search code region. I guess there is really not much gain to exclude code region since it is very small. Next release I shall make it search all readable region.any idea why Breeze was not able to search in main non asm region? start search using main only or start search with search main only = 1 couldn't find the value
edizon se was able to find the value
yeah, it probably only take 1 secondsBreeze search all RW memory but don't search code region. I guess there is really not much gain to exclude code region since it is very small. Next release I shall make it search all readable region.
Hi @TomSwitch
thanks godbol link i did looking around seem like write in C++ and it will convert to arm64, i have 0 knowledge in C++
with X30 i can just find the X30 then b.eq to what ever i want to hack seem like it work but with the new alternative stack i did the same, it seem only the very first b.eq work the second one will not.
the game is THE TAKEOVER the line
ldr s0, [x19, #0x38] seem like it do all the floats for the game like hp, timer, ect......
ldr w0, [x19, #0x38] seem to do all u32
i try this and only hp seem to work and find the power up and it not work at all, how to write it to work if it were you?
stp x25, x26, [sp,#-0x90]
movz w25,#0x0888, lsl #16 <----- this seem only get the hp all player and enermies
ldr x26, [sp,#0x18]
lsl w26,w26,16
cmp w25, w26
b.eq hp
movz w25,#0x399c, lsl #16 <----- this is for power bar and along with it another 2 more hits (no idea what it does)
ldr x26, [sp,#0x18]
cmp w25, w26
b.eq power
original:
ldr s0, [x19, #0x38]
ldp x25, x26, [sp,#-0x90]
b code1+4
hp:
ldr w26, [x19, #0x68] <----- check 1 sometime enemy is 0
cbz w26,original
ldr w26, [x19, #0x88] <----- check 2 most of enemy is 0
cbz w26, original
movz w25,#0x4348, lsl #16
str w25, [x19, #0x38]
b original
power:
ldr w26, [x19, #0x88] <------ the other hits got 0 at this point
cbz w26, original
movz w25,#0x4000, lsl #16
str w25, [x19, #0x38]
b original
can i have an example so i can just base on it in the future similar game only 1 code line, i can use it to pick out multiple cheats
thanks Tom
thanks godbol link i did looking around seem like write in C++ and it will convert to arm64, i have 0 knowledge in C++
with X30 i can just find the X30 then b.eq to what ever i want to hack seem like it work but with the new alternative stack i did the same, it seem only the very first b.eq work the second one will not.
the game is THE TAKEOVER the line
ldr s0, [x19, #0x38] seem like it do all the floats for the game like hp, timer, ect......
ldr w0, [x19, #0x38] seem to do all u32
i try this and only hp seem to work and find the power up and it not work at all, how to write it to work if it were you?
stp x25, x26, [sp,#-0x90]
movz w25,#0x0888, lsl #16 <----- this seem only get the hp all player and enermies
ldr x26, [sp,#0x18]
lsl w26,w26,16
cmp w25, w26
b.eq hp
movz w25,#0x399c, lsl #16 <----- this is for power bar and along with it another 2 more hits (no idea what it does)
ldr x26, [sp,#0x18]
cmp w25, w26
b.eq power
original:
ldr s0, [x19, #0x38]
ldp x25, x26, [sp,#-0x90]
b code1+4
hp:
ldr w26, [x19, #0x68] <----- check 1 sometime enemy is 0
cbz w26,original
ldr w26, [x19, #0x88] <----- check 2 most of enemy is 0
cbz w26, original
movz w25,#0x4348, lsl #16
str w25, [x19, #0x38]
b original
power:
ldr w26, [x19, #0x88] <------ the other hits got 0 at this point
cbz w26, original
movz w25,#0x4000, lsl #16
str w25, [x19, #0x38]
b original
can i have an example so i can just base on it in the future similar game only 1 code line, i can use it to pick out multiple cheats
thanks Tom
Last edited by ranma99vn,
@dsrules beta94b prerelease has the GrabA assist and search all readable region
The Set GrabA button requires gen2 menu to have been visited before in the current breeze session to work.
The Set GrabA button requires gen2 menu to have been visited before in the current breeze session to work.
Post automatically merged:
Give me the code to watch. That would save time.Hi @TomSwitch
thanks godbol link i did looking around seem like write in C++ and it will convert to arm64, i have 0 knowledge in C++
with X30 i can just find the X30 then b.eq to what ever i want to hack seem like it work but with the new alternative stack i did the same, it seem only the very first b.eq work the second one will not.
the game is THE TAKEOVER the line
ldr s0, [x19, #0x38] seem like it do all the floats for the game like hp, timer, ect......
ldr w0, [x19, #0x38] seem to do all u32
i try this and only hp seem to work and find the power up and it not work at all, how to write it to work if it were you?
stp x25, x26, [sp,#-0x90]
movz w25,#0x0888, lsl #16 <----- this seem only get the hp all player and enermies
ldr x26, [sp,#0x18]
lsl w26,w26,16
cmp w25, w26
b.eq hp
movz w25,#0x399c, lsl #16 <----- this is for power bar and along with it another 2 more hits (no idea what it does)
ldr x26, [sp,#0x18]
cmp w25, w26
b.eq power
original:
ldr s0, [x19, #0x38]
ldp x25, x26, [sp,#-0x90]
b code1+4
hp:
ldr w26, [x19, #0x68] <----- check 1 sometime enemy is 0
cbz w26,original
ldr w26, [x19, #0x88] <----- check 2 most of enemy is 0
cbz w26, original
movz w25,#0x4348, lsl #16
str w25, [x19, #0x38]
b original
power:
ldr w26, [x19, #0x88] <------ the other hits got 0 at this point
cbz w26, original
movz w25,#0x4000, lsl #16
str w25, [x19, #0x38]
b original
can i have an example so i can just base on it in the future similar game only 1 code line, i can use it to pick out multiple cheats
thanks Tom
Last edited by TomSwitch,
[hp]@dsrules beta94b prerelease has the GrabA assist and search all readable region
The Set GrabA button requires gen2 menu to have been visited before in the current breeze session to work.
Post automatically merged:
Give me the code to watch. That would save time.
04000000 01BBD8F0 BD403A60
[bullet]
04000000 01BBE480 B9403A60
those are pretty much using 2 lines one is for float one is for u32
Thanks Tom
Only looked at hp, this looks like a method that access some attribute of a class that is common between your hero and the enemy. This routine access more than hp, for one it is also your super meter.[hp]
04000000 01BBD8F0 BD403A60
[bullet]
04000000 01BBE480 B9403A60
those are pretty much using 2 lines one is for float one is for u32
Thanks Tom
[Breeze beta94b THE TAKEOVER 1.0.1 TID: 0100CAE01021A000 BID: 0368F0652164E647]
[auto asm 1]
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142503D8
04000000 024FE850 A9376BF9
04000000 024FE854 18000119
04000000 024FE858 794033FA
04000000 024FE85C 6B1A033F
04000000 024FE860 54000041
04000000 024FE864 BD403A60
04000000 024FE868 BD403A60
04000000 024FE86C A9776BF9
04000000 024FE870 17DAFC21
04000000 024FE874 00003DDC
[ hp]
04000000 0168FDCC F9402A93
80000300
04000000 0168FDCC F9402A93
04000000 0168FDCC 1439BAAB
04000000 024FE878 F9402A93
04000000 024FE87C 1C000060
04000000 024FE880 BD003A60
04000000 024FE884 17C64553
04000000 024FE888 42C80000
20000000

Taking one of the stack value and generate a code and I see the super for our hero, his hp, enemy's hp and maybe something else. Next_stack_check=1 means the first stack value on the line selected.
I look at the caller (don't have to, stack match will do just fine), I made a simplified code to fill it and it will fill up enemy's hp too.
What you need is some way to identify friend or foe and perhaps what attribute it is. It lies in the data. Maybe it is possible to find code that only access our hero, there is quite a number of routine to try to see if it gives you that.

Here X20 is a step back and possibly from X20 can get to some friend or foe identifier.

From here it is clear that the caller is at offset 3. (0x10+8) as x30 is the second of the ldp. Look at first screen shot there are many return address at offset 3. Only tested one.
The one I made is a lazy hack. You can have an advantage when you are able to recover you hp and get full super meter anytime you choose but the price is enemy get a full up too. Maybe boss hp is normally higher than 100 so you also get to reduce it to 100.
I suppose you already tired pointer?
Last edited by TomSwitch,
I did try again and this time i be able to get it to work so far need to testing more with other 2 characters very interesting. i was giving up on this game before with your alternative stack it is open up so much can be look intoOnly looked at hp, this looks like a method that access some attribute of a class that is common between your hero and the enemy. This routine access more than hp, for one it is also your super meter.
[Breeze beta94b THE TAKEOVER 1.0.1 TID: 0100CAE01021A000 BID: 0368F0652164E647]
[auto asm 1]
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142503D8
04000000 024FE850 A9376BF9
04000000 024FE854 18000119
04000000 024FE858 794033FA
04000000 024FE85C 6B1A033F
04000000 024FE860 54000041
04000000 024FE864 BD403A60
04000000 024FE868 BD403A60
04000000 024FE86C A9776BF9
04000000 024FE870 17DAFC21
04000000 024FE874 00003DDC
[ hp]
04000000 0168FDCC F9402A93
80000300
04000000 0168FDCC F9402A93
04000000 0168FDCC 1439BAAB
04000000 024FE878 F9402A93
04000000 024FE87C 1C000060
04000000 024FE880 BD003A60
04000000 024FE884 17C64553
04000000 024FE888 42C80000
20000000
View attachment 460102
Taking one of the stack value and generate a code and I see the super for our hero, his hp, enemy's hp and maybe something else. Next_stack_check=1 means the first stack value on the line selected.
I look at the caller (don't have to, stack match will do just fine), I made a simplified code to fill it and it will fill up enemy's hp too.
What you need is some way to identify friend or foe and perhaps what attribute it is. It lies in the data. Maybe it is possible to find code that only access our hero, there is quite a number of routine to try to see if it gives you that.
View attachment 460103
Here X20 is a step back and possibly from X20 can get to some friend or foe identifier.
View attachment 460105
From here it is clear that the caller is at offset 3. (0x10+8) as x30 is the second of the ldp. Look at first screen shot there are many return address at offset 3. Only tested one.
The one I made is a lazy hack. You can have an advantage when you are able to recover you hp and get full super meter anytime you choose but the price is enemy get a full up too. Maybe boss hp is normally higher than 100 so you also get to reduce it to 100.
stp x25, x26, [sp,#-0x90]
movz w25,#0x0888, lsl #16
ldr x26, [sp,#0x18]
lsl w26,w26,16
cmp w25, w26
b.eq hp
movz w25,#0x399c, lsl #16
ldr x26, [sp,#0x18]
lsl w26,w26,16
cmp w25, w26
b.ne ret
ldr w26, [x19, #0x60]
cbnz w26, pow <------- got to do a compare here then it recognize
ret:
ldr s0, [x19, #0x38]
ldp x25, x26, [sp,#-0x90]
b code1+4
hp: <------- 2 compares works no problem
ldr w26, [x19, #0x68]
cbz w26, ret
ldr w26, [x19, #0x88]
cbz w26, ret
movz w25,#0x4348, lsl #16
str w25, [x19, #0x38]
b ret
pow:
ldr w26, [x19, #0x88] <------ another compare this time it works
cbnz w26, ret
movz w25,#0x4000, lsl #16
str w25, [x19, #0x38]
b ret
Thanks Tom i just keep trying and learning
@ranma99vn Made by brute force with beta94c. Did not check if all the matching are required
[Breeze beta94c THE TAKEOVER 1.0.1 TID: 0100CAE01021A000 BID: 0368F0652164E647]
[auto asm HP fixed at 100]
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142504B8
04000000 024FEBD0 A9376BF9
04000000 024FEBD4 180003B9
04000000 024FEBD8 53103FDA
04000000 024FEBDC 6B1A033F
04000000 024FEBE0 540002E1
04000000 024FEBE4 18000359
04000000 024FEBE8 794013FA
04000000 024FEBEC 6B1A033F
04000000 024FEBF0 54000261
04000000 024FEBF4 180002F9
04000000 024FEBF8 794033FA
04000000 024FEBFC 6B1A033F
04000000 024FEC00 540001E1
04000000 024FEC04 18000299
04000000 024FEC08 794073FA
04000000 024FEC0C 6B1A033F
04000000 024FEC10 54000161
04000000 024FEC14 18000239
04000000 024FEC18 794153FA
04000000 024FEC1C 6B1A033F
04000000 024FEC20 540000E1
04000000 024FEC24 180001D9
04000000 024FEC28 794173FA
04000000 024FEC2C 6B1A033F
04000000 024FEC30 54000061
04000000 024FEC34 1C000160
04000000 024FEC38 BD003A60
04000000 024FEC3C BD403A60
04000000 024FEC40 A9776BF9
04000000 024FEC44 17DAFB2C
04000000 024FEC48 18C80000
04000000 024FEC4C 0000DA90
04000000 024FEC50 0000CFD8
04000000 024FEC54 0000AEE4
04000000 024FEC58 0000A958
04000000 024FEC5C 00004E30
04000000 024FEC60 42C80000
[Breeze beta94c THE TAKEOVER 1.0.1 TID: 0100CAE01021A000 BID: 0368F0652164E647]
[auto asm HP fixed at 100]
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142504B8
04000000 024FEBD0 A9376BF9
04000000 024FEBD4 180003B9
04000000 024FEBD8 53103FDA
04000000 024FEBDC 6B1A033F
04000000 024FEBE0 540002E1
04000000 024FEBE4 18000359
04000000 024FEBE8 794013FA
04000000 024FEBEC 6B1A033F
04000000 024FEBF0 54000261
04000000 024FEBF4 180002F9
04000000 024FEBF8 794033FA
04000000 024FEBFC 6B1A033F
04000000 024FEC00 540001E1
04000000 024FEC04 18000299
04000000 024FEC08 794073FA
04000000 024FEC0C 6B1A033F
04000000 024FEC10 54000161
04000000 024FEC14 18000239
04000000 024FEC18 794153FA
04000000 024FEC1C 6B1A033F
04000000 024FEC20 540000E1
04000000 024FEC24 180001D9
04000000 024FEC28 794173FA
04000000 024FEC2C 6B1A033F
04000000 024FEC30 54000061
04000000 024FEC34 1C000160
04000000 024FEC38 BD003A60
04000000 024FEC3C BD403A60
04000000 024FEC40 A9776BF9
04000000 024FEC44 17DAFB2C
04000000 024FEC48 18C80000
04000000 024FEC4C 0000DA90
04000000 024FEC50 0000CFD8
04000000 024FEC54 0000AEE4
04000000 024FEC58 0000A958
04000000 024FEC5C 00004E30
04000000 024FEC60 42C80000
Thanks Tom i'll check it out@ranma99vn Made by brute force with beta94c. Did not check if all the matching are required
[Breeze beta94c THE TAKEOVER 1.0.1 TID: 0100CAE01021A000 BID: 0368F0652164E647]
[auto asm HP fixed at 100]
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142504B8
04000000 024FEBD0 A9376BF9
04000000 024FEBD4 180003B9
04000000 024FEBD8 53103FDA
04000000 024FEBDC 6B1A033F
04000000 024FEBE0 540002E1
04000000 024FEBE4 18000359
04000000 024FEBE8 794013FA
04000000 024FEBEC 6B1A033F
04000000 024FEBF0 54000261
04000000 024FEBF4 180002F9
04000000 024FEBF8 794033FA
04000000 024FEBFC 6B1A033F
04000000 024FEC00 540001E1
04000000 024FEC04 18000299
04000000 024FEC08 794073FA
04000000 024FEC0C 6B1A033F
04000000 024FEC10 54000161
04000000 024FEC14 18000239
04000000 024FEC18 794153FA
04000000 024FEC1C 6B1A033F
04000000 024FEC20 540000E1
04000000 024FEC24 180001D9
04000000 024FEC28 794173FA
04000000 024FEC2C 6B1A033F
04000000 024FEC30 54000061
04000000 024FEC34 1C000160
04000000 024FEC38 BD003A60
04000000 024FEC3C BD403A60
04000000 024FEC40 A9776BF9
04000000 024FEC44 17DAFB2C
04000000 024FEC48 18C80000
04000000 024FEC4C 0000DA90
04000000 024FEC50 0000CFD8
04000000 024FEC54 0000AEE4
04000000 024FEC58 0000A958
04000000 024FEC5C 00004E30
04000000 024FEC60 42C80000
works on super too, I put conditional key as it hacks the same location, maybe some refinement can make them coexist.
[auto asm super]
80000100
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142503CE
04000000 024FE828 A9376BF9
04000000 024FE82C 180003B9
04000000 024FE830 53103FDA
04000000 024FE834 6B1A033F
04000000 024FE838 540002E1
04000000 024FE83C 18000359
04000000 024FE840 794033FA
04000000 024FE844 6B1A033F
04000000 024FE848 54000261
04000000 024FE84C 180002F9
04000000 024FE850 794053FA
04000000 024FE854 6B1A033F
04000000 024FE858 540001E1
04000000 024FE85C 18000299
04000000 024FE860 7940B3FA
04000000 024FE864 6B1A033F
04000000 024FE868 54000161
04000000 024FE86C 18000239
04000000 024FE870 794193FA
04000000 024FE874 6B1A033F
04000000 024FE878 540000E1
04000000 024FE87C 180001D9
04000000 024FE880 7941B3FA
04000000 024FE884 6B1A033F
04000000 024FE888 54000061
04000000 024FE88C 1C000160
04000000 024FE890 BD003A60
04000000 024FE894 BD403A60
04000000 024FE898 A9776BF9
04000000 024FE89C 17DAFC16
04000000 024FE8A0 18C80000
04000000 024FE8A4 00005E1C
04000000 024FE8A8 0000DA90
04000000 024FE8AC 0000AEE4
04000000 024FE8B0 0000A958
04000000 024FE8B4 00004E30
04000000 024FE8B8 3F800000
20000000
[auto asm super]
80000100
04000000 01BBD8F0 BD403A60
04000000 01BBD8F0 142503CE
04000000 024FE828 A9376BF9
04000000 024FE82C 180003B9
04000000 024FE830 53103FDA
04000000 024FE834 6B1A033F
04000000 024FE838 540002E1
04000000 024FE83C 18000359
04000000 024FE840 794033FA
04000000 024FE844 6B1A033F
04000000 024FE848 54000261
04000000 024FE84C 180002F9
04000000 024FE850 794053FA
04000000 024FE854 6B1A033F
04000000 024FE858 540001E1
04000000 024FE85C 18000299
04000000 024FE860 7940B3FA
04000000 024FE864 6B1A033F
04000000 024FE868 54000161
04000000 024FE86C 18000239
04000000 024FE870 794193FA
04000000 024FE874 6B1A033F
04000000 024FE878 540000E1
04000000 024FE87C 180001D9
04000000 024FE880 7941B3FA
04000000 024FE884 6B1A033F
04000000 024FE888 54000061
04000000 024FE88C 1C000160
04000000 024FE890 BD003A60
04000000 024FE894 BD403A60
04000000 024FE898 A9776BF9
04000000 024FE89C 17DAFC16
04000000 024FE8A0 18C80000
04000000 024FE8A4 00005E1C
04000000 024FE8A8 0000DA90
04000000 024FE8AC 0000AEE4
04000000 024FE8B0 0000A958
04000000 024FE8B4 00004E30
04000000 024FE8B8 3F800000
20000000
@TomSwitch, not sure if you have noticed this on beta94c1 or not
when performing a new search, the % and bar goes over 100% before going back to 100% at the end of the search
like 102%>100%, 116%>100%
when performing a new search, the % and bar goes over 100% before going back to 100% at the end of the search
like 102%>100%, 116%>100%
I notice that going over thing but it can't be due to changes in c1.@TomSwitch, not sure if you have noticed this on beta94c1 or not
when performing a new search, the % and bar goes over 100% before going back to 100% at the end of the search
like 102%>100%, 116%>100%
This is c->c1

Post automatically merged:
OK this is the reason, 100% is for RW memory size and all segment with R is bigger

Last edited by TomSwitch,
On Breeze beta 94b when search pointer whith this setting:
search_depth=6
num_offset=20
search_range=0x08000
after next depth 5-1(R button)if continue crash.
search_depth=6
num_offset=20
search_range=0x08000
after next depth 5-1(R button)if continue crash.
There is no reason for your target to be in front. If you have a long list it is normal to crash when you just hack it.@TomSwitch, could you lower the inc1000 Revert1000 to 100 or 10?
1000 has tenfold the crash rate of 100, almost guarantee crash
If you so incline to start hacking you can do this:
Freeze game, Hack 1000, move down 100, Revert 1000
If anything looks like pointer better double check that they are not(try to follow it) before hacking it.
Post automatically merged:
Is there a version that don't crash? If there is one then I am very interested to know which one.On Breeze beta 94b when search pointer whith this setting:
search_depth=6
num_offset=20
search_range=0x08000
after next depth 5-1(R button)if continue crash.
Your setting is large so crash is not a surprise, the chance is good.
Last edited by TomSwitch,
good tips! didn't know it could do thatIf you so incline to start hacking you can do this:
Freeze game, Hack 1000, move down 100, Revert 1000
Post automatically merged:
you should stop next depth when target is 5 digits long, especially when using a large num offset 99.9% will crash, num offset 2 might be able to survive a 5 digits next depth searchOn Breeze beta 94b when search pointer whith this setting:
search_depth=6
num_offset=20
search_range=0x08000
after next depth 5- 1(R button)if continue crash.
exit breeze and try again using different settings
Last edited by dsrules,
@TomSwitch ,is this the way to respond to those who ask for help?There is no reason for your target to be in front. If you have a long list it is normal to crash when you just hack it.
If you so incline to start hacking you can do this:
Freeze game, Hack 1000, move down 100, Revert 1000
If anything looks like pointer better double check that they are not(try to follow it) before hacking it.
Post automatically merged:
Is there a version that don't crash? If there is one then I am very interested to know which one.
Your setting is large so crash is not a surprise, the chance is good.
I understand that you are the best at creating cheats,but you could be more polite
.
quote the part you think is rude?@TomSwitch ,is this the way to respond to those who ask for help?
I understand that you are the best at creating cheats,but you could be more polite.
![]()
@TomSwitch this:quote the part you think is rude?
All you had to do was tell me i was doing it wrong and suggest a better setting,simply right?
I don't see any part of that message being rude. You have to explain why you think it is rude.@TomSwitch this:
All you had to do was tell me i was doing it wrong and suggest a better setting,simply right?
In your message you did not ask for help. You reported that 94b crash. I need more information for a bug report. This is a very standard question, is it not there before? I think you are not new to using breeze for pointer search.
Your setting will crash for many games, but since you did not give details I can only say good chance to crash which I think is a fair statement. There is no point for me to try it on a random game. If it crash I get nothing as I already expect most game to crash, if it don't crash I also get nothing, there are games that won't crash which I also already know.
Similar threads
- Replies
- 2
- Views
- 255
- Replies
- 3
- Views
- 216
- Replies
- 0
- Views
- 78
-
- Sticky
- Replies
- 271
- Views
- 6K









