Skip to content
Advertisement

Unable to read value from memory using offsets

I’m trying to extract the value from a memory address using the base address of a .dll + offsets.

I used Cheat Engine to find the base address, and pymem to get the base address as hex.

enter image description here

Here’s the code I used to find the base address:

JavaScript

For reading the value I’m using ReadWriteMemory.

JavaScript

I used the output from the first code as the base address and added +0036e654 to it, but the output is always 0.

If I replace “jvm.dll” with 51250000 in Cheat Engine the addresses are still calculated correctly.

enter image description here

Advertisement

Answer

I was getting it all wrong from the start. The pointer offsets showed in Cheat Engine are hex values, so the offsets should be offsets=[0x40, 0x464, 0x38, 0x58, 0x18].

User contributions licensed under: CC BY-SA
7 People found this is helpful
Advertisement