Here's a quick explanation on how the cheat was created (posted this on another forum before here after some people asked how I 'found' the AoB's)
Well basically if you're familiar with java bytecode, this should come fairly simple to you.. All the hex values that you are searching for/replacing represent AVM2 bytecode. The only difference between editing java bytecode and flash bytecode is the fact that you inject the bytecode into class files with java, and in flash, you inject the code into memory.
Here's an example of the godmode hack:
//62 05
_as3_getlocal <5>
//60 1a
_as3_getlex _-LB
//66 4c
_as3_getproperty player_
//14 03 00 00
_as3_ifne offset: 3
//62 05
_as3_getlocal <5>
//48
_as3_returnvalue
What this code translates to is:
if (_loc_5 == _-LB.player_)
{
return _loc_5;
}
in other words, if loc_5 is equal to your player, then it returns your player (this is in the function -0A in the projectile class which handles the collision detection, and returns any object the that the current projectile is in range of (in order to damage it))
what I did was I changed the code to look like this:
if (_loc_5 == _-LB.player_) {
continue;
}
and what we end up with is this
//14 03 00 00
_as3_ifne offset: 3
//62 05
_as3_getlocal <5>
//48
changed to
//13 39 00 00
_as3_ifeq offset: 57
//02
_as3_nop
//02
_as3_nop
//02
_as3_nop
Basically what this modification does is it skips your players object when searching for objects to collide with, and registers the hit on the next object that the projectile is in range to collide with. Unfortunately, due to recent updates, this alone isn't enough to create a no-damage hack.. Through some form of magic, the server is capable of knowing if the projectile has collided with your player even if your player doesn't send a playerHit packet. I'm fairly sure it has to do with the SHOOTACK packet, but i'm not entirely sure.. Anyway, the simple hack around for this is to make sure every enemy shot fired collides with an object around you (which generates an otherHit packet), which is exactally what happens when you take the range checks out.. if you take the range detection out, the projectile collides with the nearest object, regardless of range (except for your own player, if you use the cheat above (broken image removed))
//62 06
_as3_getlocal <6>
//62 05
_as3_getlocal <5>
//66 b2 06
_as3_getproperty radius_
//62 0c
_as3_getlocal <12>
//11 30 00 00
_as3_iftrue offset: 48
//af
_as3_greaterthan
//2a
_as3_dup
//62 0c
_as3_getlocal <12>
//11 51 00 00
_as3_iftrue offset: 81
//11 33 00 00
_as3_iftrue offset: 51
//29
_as3_pop
//62 0b
_as3_getlocal <11>
//2a
_as3_dup
//11 03 00 00
_as3_iftrue offset: 3
//29
_as3_pop
//d0
_as3_getlocal <0>
//76
_as3_convert_b
//12 49 00 00
_as3_iffalse offset: 73
//62 07
_as3_getlocal <7>
//62 05
_as3_getlocal <5>
//66 b2 06
_as3_getproperty radius_
Basically what this does is it compares the distance between the projectile and the current object in the iteration (both x and y seperately), and if they're not in range, then the function continues. What we could do to make this simple is modify the values that the distances get compared to, put them to 0, so that way it looks like:
if (_loc_5.radius_ < _loc_6) {
continue;
}
if (_loc_5.radius_ < _loc_7) {
continue;
}
into
if (_loc_5.radius_ < 0) {
continue;
}
if (_loc_5.radius_ < 0) {
continue;
}
and you end up with this bytecode
//24 00
_as3_pushbyte 0
//62 05
_as3_getlocal <5>
//66 b2 06
_as3_getproperty radius_
//62 0c
_as3_getlocal <12>
//11 30 00 00
_as3_iftrue offset: 48
//af
_as3_greaterthan
//2a
_as3_dup
//62 0c
_as3_getlocal <12>
//11 51 00 00
_as3_iftrue offset: 81
//11 33 00 00
_as3_iftrue offset: 51
//29
_as3_pop
//62 0b
_as3_getlocal <11>
//2a
_as3_dup
//11 03 00 00
_as3_iftrue offset: 3
//29
_as3_pop
//d0
_as3_getlocal <0>
//76
_as3_convert_b
//12 49 00 00
_as3_iffalse offset: 73
//24 00
_as3_pusbyte 0
//62 05
_as3_getlocal <5>
//66 b2 06
_as3_getproperty radius_
Hopefully this helps you understand how to find/create AoB's for flash games (AS3 in specific since AS1-2 operate on the AVM1 bytecode engine which uses a completely different format)
If you have any questions, just post them here, and sorry for the overuse of the term 'basically'
NOTE: In case you were wondering, this method completely differs from any other methods i've used in the past (all of which have been patched thanks to these forums (broken image removed))
This one in particular isn't easy to patch due to the fact that some compromises have to be made (server-side projectile deletion based on when a player tells the server that THEY've been hit, or the simpler more direct route, server-side range-checked collision detection) which is why I've chosen to post it.