Object instance operation method and system, electronic equipment and storage medium
By extracting the feature code of the object instance and determining the target object instance based on it, the problem that targeted operations on specific object instances in the prior art are solved, and accurate identification and operation of object instances in the same data type is realized.
Patent Information
- Application Number
- CN202510223899.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-27
AI Technical Summary
In the prior art, multiple object instances of the same structure or class are referenced, and the memory address offset of the target variables of multiple object instances is the same, resulting in that when the value of the target variable is modified through the object pointer, it will act on all object instances at the same time, and targeted operations on specific object instances cannot be performed.
By obtaining multiple candidate object instances of the target data type, extracting the feature code of each candidate object instance from memory, determining the target object instance based on the feature code, and performing preset operations on it, targeted operations on specific object instances in the same data type are realized.
Improve the accuracy of identifying target object instances, realize accurate operations on specific object instances in the same data type, and avoid simultaneous modification of all object instances.
Smart Images

Figure CN120215952A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and particularly relates to an object instance operation method, system, electronic device and storage medium. Background Art
[0002] In programming, a structure and a class are user-defined data types that allow multiple data items of different types to be encapsulated into a single data structure. Each data item in a structure or class is called a member, including member functions and member variables. An object instance is a specific data object created in memory according to a defined structure or class. In related technologies, for multiple object instances that reference the same structure or class (where a target variable is defined in the class), and the memory address offsets of the target variables of the multiple object instances are the same, when it is necessary to modify the value of the target variable by means of an object pointer, this operation will act on all object instances simultaneously, so that it is impossible to perform targeted operations on a certain target object instance. Summary of the Invention
[0003] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention provides an object instance operation method, system, electronic device and storage medium, aiming to improve the accuracy of identifying a target object instance, perform targeted operations on specific object instances in the same data type, and improve the accuracy of object instance operations.
[0004] On the one hand, an embodiment of the present invention provides an object instance operation method, including the following steps:
[0005] Obtain multiple candidate object instances of a target data type;
[0006] Extract the feature code of each of the candidate object instances located in the memory from the memory;
[0007] Determine a target object instance according to the feature codes of the candidate object instances;
[0008] Perform a preset operation on the target object instance.
[0009] According to some embodiments of the present invention, the extracting the feature code of each of the candidate object instances located in the memory from the memory includes the following steps:
[0010] Determine the first memory address where the feature code of each of the candidate object instances is located;
[0011] Extract the memory value of the first memory address to obtain the feature code of the candidate object instance.
[0012] According to some embodiments of the present invention, determining the first memory address where the signature of each candidate object instance is located includes the following steps:
[0013] Obtain the base memory address of the candidate object instance;
[0014] Add a preset first address offset to the base memory address to obtain the first memory address where the signature of the candidate object instance is located.
[0015] According to some embodiments of the present invention, the first address offset is determined through the following steps:
[0016] Obtain the machine code of multiple sample instances in memory, where the multiple sample instances include object instances of different types of objects created based on the target data type;
[0017] Compare the differences between the machine codes of different sample instances to determine the code fields representing different types of objects;
[0018] Determine the first address offset according to the relative position of the code field in the machine code.
[0019] According to some embodiments of the present invention, determining the target object instance according to the signatures of each candidate object instance includes the following steps:
[0020] Determine whether the signature of the candidate object instance is the expected signature;
[0021] In the case where the signature of the candidate object instance is the expected signature, determine the corresponding candidate object instance as the target object instance.
[0022] According to some embodiments of the present invention, the expected signature is determined through the following steps:
[0023] Obtain the machine code of multiple sample instances in memory, where the multiple sample instances include object instances of different types of objects created based on the target data type;
[0024] Compare the differences between the machine codes of different sample instances to determine the code fields representing different types of objects;
[0025] Determine the code field of the object instance belonging to the object of the target type as the expected signature.
[0026] According to some embodiments of the present invention, performing a preset operation on the target object instance includes the following steps:
[0027] Obtain the second address offset of the target variable;
[0028] Determine the second memory address where the target variable is located according to the second address offset and the memory block base address of the target object instance;
[0029] Perform a modification operation on the memory value of the second memory address.
[0030] According to some embodiments of the present invention, the operation of modifying the memory value of the memory address includes the following steps:
[0031] Obtain the machine code corresponding to the target modification state;
[0032] Replace the memory value of the second memory address with the machine code.
[0033] According to some embodiments of the present invention, before the step of obtaining multiple candidate object instances of the target data type, the object instance operation method further includes the following steps:
[0034] Obtain program code, wherein a function jump code is inserted at the target position of the program code, and the function jump code indicates the address of the hook function;
[0035] Execute the program code, and when the function jump code is executed, execute the hook function according to the function jump code to jump to execute the step of obtaining multiple candidate object instances of the target data type.
[0036] On the other hand, an object instance operating system provided by an embodiment of the present invention includes:
[0037] A first module configured to obtain multiple candidate object instances of a target data type;
[0038] A second module configured to extract the signature codes of each of the candidate object instances located in the memory from the memory;
[0039] A third module configured to determine a target object instance according to the signature codes of the respective candidate object instances;
[0040] A fourth module configured to perform a preset operation on the target object instance.
[0041] On the other hand, an embodiment of the present invention provides an electronic device, including at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor so that the at least one control processor can execute the object instance operation method as described in the first aspect above.
[0042] On the other hand, an embodiment of the present invention provides a computer-readable storage medium storing computer-executable instructions for executing the object instance operation method as described above.
[0043] One of the above technical solutions has the following advantages or beneficial effects: The present application provides an object instance operation method, system, electronic device, and storage medium. This solution obtains multiple candidate object instances of a target data type, extracts the feature codes of each candidate object instance in memory, determines the target object instance based on the feature codes of each candidate object instance, and performs a preset operation on the target object instance. According to the technical solution of this embodiment, candidate object instances that reference the same target data type are obtained for analysis. By retrieving memory and extracting the feature codes of each candidate object instance in memory, the target object instance is correctly identified based on the feature codes, thereby realizing targeted operations on specific object instances in the same data type and improving the accuracy of object instance operations. Description of the Drawings
[0044] Figure 1 is a flowchart of an object instance operation method provided by an embodiment of the present invention;
[0045] Figure 2 is Figure 1 a flowchart of step S102 in
[0046] Figure 3 is a schematic diagram of the object instance creation and reading process provided by an embodiment of the present invention;
[0047] Figure 4 is Figure 2 a flowchart of step S201 in
[0048] Figure 5 is Figure 1 a flowchart of step S103 in
[0049] Figure 6 is Figure 1 a flowchart of step S104 in
[0050] Figure 7 is a schematic diagram of directly creating an object instance based on a class provided by an embodiment of the present invention;
[0051] Figure 8 is a schematic diagram of indirectly creating an object instance based on a class provided by an embodiment of the present invention;
[0052] Figure 9 is Figure 6 a flowchart of step S703 in
[0053] Figure 10 It is a flowchart of an object instance operation method provided by another embodiment of the present invention;
[0054] Figure 11 It is a schematic structural diagram of an object instance operation system provided by an embodiment of the present invention;
[0055] Figure 12 It is a structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0056] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.
[0057] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as up, down, front, back, left, right, etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the present invention.
[0058] In the description of the present invention, the meaning of several is one or more, the meaning of multiple is two or more, greater than, less than, exceeding, etc. are understood as not including the present number, and above, below, within, etc. are understood as including the present number. If the first and the second are described only for the purpose of distinguishing technical features, they should not be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or the sequence relationship of the indicated technical features.
[0059] In the description of the present invention, unless otherwise clearly defined, terms such as setting, installing, connecting, etc. should be understood in a broad sense, and those skilled in the art can reasonably determine the specific meanings of the above terms in the present invention in combination with the specific content of the technical solution.
[0060] Before the embodiments of the present invention are described in detail, some nouns and terms involved in the embodiments of the present invention are first explained. The nouns and terms involved in the embodiments of the present invention are applicable to the following explanations.
[0061] 1) A Dynamic Link Library (DLL), also known as a dynamic link library file, is a library that contains code and data that can be used by multiple programs simultaneously. For example, in the Windows operating system, the Comdlg32 DLL executes common functions related to dialog boxes. Each program can use the functions contained in this DLL to implement an "Open" dialog box, which helps to promote code reuse and efficient use of memory.
[0062] 2) GameAssembly.dll is a dynamic link library file commonly found in games compiled with IL2CPP, especially those developed based on the Unity engine. IL2CPP is a technology that converts high-level language code (such as C#) into standard C++ code, and GameAssembly.dll is the library file containing runtime and script code generated during this conversion process. GameAssembly.dll contains important logic and runtime libraries required for the game to run, and it is one of the key components for the game program to execute properly. It is responsible for providing necessary code and resources during the game runtime to ensure the game runs smoothly. GameAssembly.dll contains the core logic and function implementations of the game, such as character behaviors, item systems, combat mechanisms, etc. These functions are called and executed by the game main program in the form of DLL files, providing players with a rich gaming experience.
[0063] 3) Programming reverse engineering, that is, reverse engineering of programs, is a technical process that involves decomposing existing program code into its most basic components in order to analyze, understand how it works, identify its components and functions. This process is usually carried out in situations where there is no access to the source code, for debugging, software security analysis, or just for learning purposes. The basic principle of reverse engineering is to convert the compiled program code back to a form close to the original source code through various technical means. This process involves multiple steps, and each step requires specific tools and skills. Usually, reverse engineering starts from the binary form of program execution, and then parses and converts it in order to restore human-readable program code or logic. Reverse engineering involves a variety of tools and techniques. Disassemblers and debuggers are two main tools commonly used by reverse engineers. A disassembler can convert binary code into assembly language, which is a language slightly more advanced than machine code. A debugger allows reverse engineers to monitor the running state of the program, including the values of variables, the control flow of the program, and the call stack during program execution.
[0064] 4) Inline Hook is a technique that modifies the execution flow of a function during program runtime. By modifying the original code, the execution path of the target function is redirected to a custom code segment, thereby achieving the interception and modification of the target function. Inline Hook is commonly used in scenarios such as dynamic function modification, tracking, and performance analysis, and can be used for operations such as monitoring, modifying parameters, and modifying return values.
[0065] In programming, structs and classes are user-defined data types that allow multiple data items of different types to be encapsulated into a single data structure. Each data item in a struct or class is called a member, including member functions and member variables. An object instance is a specific data object created in memory according to the defined struct or class. In related technologies, for multiple object instances that reference the same class or struct (where the target variable is defined), and the memory address offsets of the target variables of the multiple object instances are the same, when it is necessary to modify the value of the target variable through an object pointer, this operation will act on all object instances simultaneously, making it impossible to perform targeted operations on a certain target object instance.
[0066] Exemplarily, in a certain game program, there is a character object class defined. The members in this character object class include character name, health value, attack power, defense power, blood volume status, movement method, attack method, etc. Based on the character object class, multiple different character objects can be created, such as a character object and an enemy object. The character object and the enemy object define their respective attribute values, behavior methods, or skill methods on the basis of the character object class (parent class). For example, the enemy may have higher attack power, while the character may have more health value. When the game program is running, character object instances and enemy object instances will be created in memory based on the character object class and object creation instructions. In the case where the original code cannot be obtained or modifying the original code is allowed, when it is necessary to modify the blood volume status of the character object, for example, changing the blood volume status to a blood volume holding status, in this case, generally, the blood volume status in the character object class in the static storage area of memory is modified through a pointer. However, since both the character object instance and the enemy object instance reference the character object class, and the blood volume status is defined in the character object class, therefore, the memory address offsets of the blood volume statuses of the character object instance and the enemy object instance mapped to memory are the same. Therefore, this modification operation will act on both the character object instance and the enemy object instance simultaneously, and both the character object and the enemy object will be modified to the blood volume holding status, making it impossible to specifically modify the blood volume status of the character object to the blood volume holding status.
[0067] Therefore, the embodiments of the present invention provide a method, a system, an electronic device, and a storage medium for operating object instances. This solution obtains multiple candidate object instances of a target data type, extracts the feature codes of each candidate object instance located in the memory from the memory, determines the target object instance according to the feature codes of each candidate object instance, and performs a preset operation on the target object instance. According to the technical solution of this embodiment, candidate object instances that reference the same target data type are obtained for analysis. By retrieving the memory and extracting the feature codes of each candidate object instance located in the memory, the target object instance among them is accurately identified based on the feature codes, so as to achieve targeted operations on one object instance in the same data type.
[0068] In the present invention, a method, a system, an electronic device, and a storage medium for operating object instances are provided, and will be described in detail one by one in the following embodiments.
[0069] The processing process of the method for operating object instances provided by the embodiments of the present invention can cover most program debugging scenarios without modifying the original code, enabling program debuggers to operate on a specific object instance targetedly, so as to debug the object in the program to the required functional state. Specifically, before program debugging, the debugger can find different object instances of the same target data type in the memory during program operation. By analyzing the differences between different object instances, the feature codes of the object instances that can represent a specific object are determined. During program debugging, when an operation needs to be performed on a certain object instance, the debugger can run a program that can implement the method for operating object instances of the embodiments of the present application, so that the processor obtains multiple candidate object instances of the target data type, then extracts the feature codes of each candidate object instance located in the memory from the memory, determines the object instance to be modified according to the feature codes of each candidate object instance, and then performs a preset operation on this object instance, so as to achieve targeted operations on a specific object instance in the same data type.
[0070] The method for operating object instances provided by the embodiments of the present invention can be applied to a terminal, can also be applied to a server side, or can also be software running on a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a set-top box, etc.; the server side can be configured as an independent physical server, can also be configured as a server cluster or a distributed system composed of multiple physical servers, or can also be configured as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the method for operating object instances, etc., but is not limited to the above forms.
[0071] The present invention can be used in numerous general-purpose or special-purpose computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0072] Referring to Figure 1 , Figure 1 FIG. is a flowchart of an object instance operation method provided by an embodiment of the present invention. The object instance operation method includes but is not limited to steps S101 to S104:
[0073] Step S101, obtaining a plurality of candidate object instances of a target data type.
[0074] Specifically, a data type is a set of rules in a programming language for specifying the storage format and the range of storable values of variables, constants, or function return values. Different data types determine the storage method, operation method, and value range of data in computer memory. Data types are usually divided into basic data types, composite data types, and abstract data types. The data type in this embodiment refers to a description that can define a set of attribute characteristics and behavior rules. For example, classes, abstract classes, and structures, etc. The target data type refers to the data type referenced by the object to be operated. A candidate object instance refers to the mapping in memory of an object created based on the target data type, and the candidate object instance is represented in the form of binary machine code in memory.
[0075] Exemplarily, a game program includes multiple classes, such as a class for defining a character object, a class for defining a skill object, and a class for defining a terrain object. Based on the character object class, enemy objects and character objects are created. In the case where it is necessary to modify a character object instance, the target data type refers to the character object class.
[0076] In one embodiment, the class definition, as part of the program, is usually stored in the global area or the static storage area. This area stores the structure information of the class, including method definitions and static variables. Regardless of how many objects are created, there is only one copy of the class definition in memory. The storage of objects is different from the static storage method of classes. Each instance of an object is separately allocated space in the heap memory. The heap memory is dynamically allocated and can create and destroy objects as needed during runtime. Each object instance stores its own state information, such as instance variables. The class provides a blueprint for creating objects, and the object is the specific implementation of this blueprint. Although the class definition is static in memory, the dynamic creation of objects through the heap memory enables each object to independently store its own data. After the source program is compiled into an executable program, all classes are organized and stored in the executable program in a certain order and structure. When the executable program runs, the classes are stored in a certain position in memory in a certain format and order. At the same time, during program execution, one or more object instances of the class are generated by calling the constructor of the class. The constructor of the class can complete the space allocation and initial settings of the object. When an object instance is created, the instance variables of the object are stored in memory in the order in which they appear in the class definition. In addition to instance variables, an object also has a hidden member: a reference to its enclosing class. This reference enables the object to access the methods and fields of its class and is usually stored in the header information of the object to establish the association between the object and the class.
[0077] Based on this, when the program under debugging is executed, the type information of each object (i.e., the reference in the header information) at the time of object instantiation can be obtained. This obtaining method can be implemented using the getClass() method of the object; then the type information of the target data type can be obtained through the bytecode object of the target data type; compare the type information of the object with the type information of the target data type. Specifically, it can be implemented by checking whether the type information of the object is the same as or a subclass of the type information of the target data type. If the type of the object is the same as or a subclass of the type of the specified class, then the object is determined to be a candidate object instance of the target data type.
[0078] In practical applications, when it is necessary to modify a certain object instance of a target program, the debugger executes the object instance operation method of the embodiment of the present application after running the target program. During the running of the target program, each time an object instance of a data type is created, its belonging type information is stored in the header information. Therefore, the debugger can specify the type information of the target data type. The object instance operation method of the embodiment of the present application reads the type information of all object instances created during the running of the target program, and then compares the type information of each object instance with the specified type information to determine all object instances with the same specified type information, so as to obtain multiple candidate object instances of the target data type. Then, the signature codes of each candidate object instance located in the memory are extracted from the memory, and the object instance to be modified is determined according to the signature codes of each candidate object instance, and then a preset operation is performed on the object instance, so as to realize targeted operations on specific object instances in the same data type.
[0079] Step S102: Extract the signature code of each of the candidate object instances located in the memory.
[0080] Specifically, the signature code represents the identity identifier of the object instance in the memory to distinguish the object identity corresponding to the instance. The signature code is part of the object instance, which is located in a specific area of the object instance memory block and is stored in binary machine code. For the convenience of reading, it can be represented in hexadecimal or decimal form when read. Exemplarily, the signature code of a character object instance may be "0", while the signature code of an enemy object instance may be "1"; the signature code of a character object instance may be "01", while the signature code of an enemy object instance may be "11". The number of digits of the signature code is not fixed, and the embodiment of the present application does not specifically limit the number of digits and content of the signature code, as long as different types of object instances can be distinguished.
[0081] Exemplarily, after an object is created, it is stored in a specific location in the memory. The internal attribute variables of the object are represented as specific areas in the specific memory block occupied by the object in the memory. Since multiple candidates reference the same target data type, the structure information of the candidate object instances in the memory is basically the same. After determining each candidate object instance in the memory, the signature code of the candidate object instance can be extracted based on the signature code in a specific area of the memory block of the candidate object instance.
[0082] Step S103: Determine the target object instance according to the signature codes of each of the candidate object instances.
[0083] Specifically, the signature code of the object instance can characterize different types of objects. Based on this, the target object instance among them can be determined by sequentially judging whether the signature code of each candidate object instance is the expected signature code.
[0084] In practical applications, when it is necessary to modify a certain object instance of a target program, the debugger can specify the target data type and the expected signature. After the target program runs, the object instance operation method of the embodiment of the present application is executed. During the running of the target program, the object instance operation method of the embodiment of the present application determines the target object instance among them by obtaining multiple candidate object instances of the specified target data type, then extracting the signature of each candidate object instance located in the memory from the memory, and judging whether the signature of each candidate object instance is the specified expected signature, and then performs a preset operation on the target object instance, so as to realize targeted operations on specific object instances of the same data type.
[0085] Step S104, perform a preset operation on the target object instance.
[0086] Specifically, the preset operation refers to a method that can perform a certain specified operation on the object instance. The implementation method of the preset operation is part of the object instance operation method of the embodiment of the present application. The implementation method of the preset operation can be directly written into the main program of the object instance operation method, or can be called as a subroutine by the main program of the object instance operation method to implement the preset operation. The preset operation includes an operation target and an operation type. The operation target refers to the variable or attribute that needs to be operated in the object instance, and the operation type refers to addition, deletion, modification, etc. The specific content of the preset operation can be set by the program debugger according to requirements.
[0087] Exemplarily, in a game program, by obtaining multiple candidate object instances under the character object class defined by the game, including enemy object instances and character object instances. By extracting the signature of each candidate object instance from the memory, and then determining whether the candidate object instance is the character object instance that needs to be operated based on the extracted signature. After determining the character object instance, find the specific area in the memory block where the health status attribute of the character object instance is located, and then modify the value of the specific area, so as to change the health status of the character object instance.
[0088] In another example, in a game program, by obtaining multiple candidate object instances under the character object class defined by the game, including enemy object instances and character object instances. By extracting the signature of each candidate object instance from the memory, and then determining whether the candidate object instance is the enemy object instance that needs to be operated based on the extracted signature. After determining the enemy object instance, find the specific area in the memory block where the attack power attribute of the enemy object instance is located, and then the access permission of the specific area can be set to read-only, so as to lock the attack power of the enemy object instance during the subsequent game process.
[0089] One of the above technical solutions has the following advantages or beneficial effects: In the embodiment of the present invention, multiple candidate object instances of a target data type are obtained, the signature codes of each candidate object instance located in the memory are extracted from the memory, the target object instance is determined according to the signature codes of each candidate object instance, and a preset operation is performed on the target object instance. According to the technical solution of this embodiment, candidate object instances that reference the same target data type are obtained for analysis. By retrieving the memory and extracting the signature codes of each candidate object instance located in the memory, the target object instance is accurately identified based on the signature codes, so as to realize targeted operations on one object instance in the same data type.
[0090] Referring to Figure 2 , in an implementation manner of the embodiment of the present invention, the extracting the signature codes of each candidate object instance located in the memory includes the following steps:
[0091] Step S201, determining the first memory address where the signature code of each candidate object instance is located;
[0092] Step S202, extracting the memory value of the first memory address to obtain the signature code of the candidate object instance.
[0093] Specifically, the signature code in the embodiment of the present invention represents the identity identifier of the object instance in the memory to distinguish the object identity corresponding to the instance. The signature code is part of the object instance, which is located in a specific area of the object instance memory block and is stored in binary machine code. For the convenience of reading, it can be represented in hexadecimal or decimal form when read. Based on this, in the embodiment of the present invention, the memory block address range of the candidate object instance can be determined first, and then the first memory address can be determined based on the specific area where the signature code is located. The memory value stored in the first memory address is the signature code. By extracting the memory value of the first memory address, the signature code of the candidate object instance can be obtained.
[0094] In practical applications, please refer to Figure 3 , Figure 3 is a schematic diagram of the object instance creation and reading process provided by an embodiment of the present invention. When the target program runs, the object creation process of the target program is as follows:
[0095] First, an object of a class is created. Generally, the new keyword is used to create an object of a class and assign it to a variable.
[0096] After the object is created, memory space will be allocated for the object. As Figure 3 shown, the address range of the allocated memory space (i.e., the memory block) is 03068960 - 03D689F0.
[0097] After allocating memory space, initialize the member variables of the object. Member variables include the attributes and methods of the class. Generally, for attributes, default values are assigned to them. For example, the default value of an int-type attribute is 0, and the default value of a String-type attribute is null. If a constructor is defined in the class, the constructor is called to initialize the member variables. If no constructor is defined, the default no-argument constructor is used to initialize the member variables.
[0098] In the constructor, assignment operations can be performed on the member variables. For example, for an attribute named name, this.name = name can be used in the constructor to assign a value to the name attribute.
[0099] After initializing the member variables, execute the constructor. The constructor is a special method used for some initialization operations when creating an object. The name of the constructor is the same as the name of the class and has no return type. Some initialization operations can be performed in the constructor, such as assigning values to attributes, calling other methods, etc. If no constructor is defined, the program automatically adds a no-argument constructor.
[0100] After executing the constructor, a memory block storing variables or attributes can be obtained, which is the object instance. The constructor returns a reference to the object. The target program can assign this reference to a variable for subsequent use.
[0101] Please continue to refer to Figure 3 , after the target program creates an object instance, the process of extracting the object instance feature code of the embodiment of the present application is as follows:
[0102] First, determine multiple object instances created by the target program, and determine candidate object instances belonging to the target data type based on the type information of the object instances. Then, access the candidate object instances according to the memory block addresses where the candidate object instances are located. Determine the first memory address based on the fact that the feature code is located in a specific area of the candidate object instance. For example, the first memory address is 03068970. Then extract the memory value of the first memory address to obtain the feature code of the candidate object instance. For example, if the memory value at the memory address 03068970 is "10 1.55008e-02 20", all or part of the digits on the memory value can be used as the feature code of the candidate object instance. For example, the feature code can be "10".
[0103] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: During the running of the target program in the embodiment of the present invention, by determining the memory address where the signature is located, each candidate object instance of the target data type created by the target program can be quickly and accurately extracted from the memory, and then the target object instance can be accurately identified based on the signature, so as to realize targeted operations on an object instance in the same data type.
[0104] Referring to Figure 4 , in an implementation manner of the embodiment of the present invention, the determining the first memory address where the signature of each candidate object instance is located includes the following steps:
[0105] Step S301, obtaining the base address of the memory block of the candidate object instance;
[0106] Step S302, adding a preset first address offset to the base address of the memory block to obtain the first memory address where the signature of the candidate object instance is located.
[0107] Specifically, the base address of the memory block of an object instance refers to the address of the first byte of the object instance in the memory, which is used to identify the position of the object, so as to facilitate the access and management of object data. The memory of an object instance usually includes an object header (such as a type pointer and synchronization information) and instance data (field values). In this embodiment, the base address of the candidate object instance can be determined by means of a static base address, a register base address, a reference chain base address, and a dynamic base address, as follows:
[0108] Static base address method, by analyzing the source code or disassembly result of the target program through reverse engineering technology, searching for pointers of global variables or functions used in the program, so as to find the base address of the object instance.
[0109] Register base address, if the target program stores the memory address in the register of the CPU during the running process, the base address of the object instance can be found by tracking the running process of the program and observing and analyzing the values in the register.
[0110] Reference chain base address, some data objects in the target program may be organized in a linked list structure. If the target data type of the target program adopts a linked list structure when creating an object, the base address of the object instance can be found by tracking the pointers of the linked list and tracing back to the head node of the linked list.
[0111] Dynamic base address, the target program will generate code or modify the memory layout during the running process, so that the position of the base address will often change. Through dynamic analysis and debugging tools, the change of the base address of the object instance can be captured and tracked in real time, so as to find the base address of the object instance.
[0112] In addition, by scanning the memory space of the program, an address storing a specific value (such as the initial value of a global variable) can be found, and this address can be used as the base address of the candidate object instance.
[0113] Specifically, the first address offset refers to the distance from the base address of the memory block of the object instance to the address of the specific location where the signature is located, usually in bytes. The first address offset is used to locate the signature in the memory block of the candidate object instance. For object instances referring to the same data type, their data storage structures in memory are the same. Therefore, the distances from the base address of the memory block of different candidate object instances to the address of the specific location where their signatures are located are the same, that is, through the same first address offset, the signatures in the memory blocks of different candidate object instances can be correspondingly found.
[0114] Exemplarily, a linked list structure generated when creating an object instance of the target data type in the target program can be obtained. By tracing the pointers of the linked list, the base addresses of each candidate object instance of the target data type in memory can be determined, and then the base address of the memory block of each candidate object instance is added with a preset first address offset to obtain the first memory address where the signature of the candidate object instance is located. For example, obtain the linked list structure generated when creating role object instances and enemy object instances of the character object class in a game program. By tracing the pointers of the linked list, determine the base addresses of the role object instance and the enemy object instance in memory respectively. Add the first address offset to the base address of the memory block of the role object instance to obtain the first memory address where the signature of the role object instance is located, and add the first address offset to the base address of the memory block of the enemy object instance to obtain the first memory address where the signature of the enemy object instance is located.
[0115] In practical applications, when it is necessary to modify a certain object instance of the target program, the debugger executes the object instance operation method of the embodiment of the present application after running the target program. The object instance operation method of the embodiment of the present application is based on a specified target data type, reads the linked list structure generated when creating an object instance of the target data class in the target program, determines the base addresses of each candidate object instance of the target data class in memory by tracing the pointers of the linked list, adds the specified first address offset to the base address of the memory block of each candidate object instance to obtain the first memory address where the signature of the candidate object instance is located. Read the memory value of the first memory address of the candidate object instance to obtain the signature of the candidate object instance, and then determine the object instance to be modified according to the signatures of each candidate object instance, and then perform a preset operation on the object instance, so as to achieve targeted operations on specific object instances of the same data type.
[0116] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: During the running of the target program, in the embodiments of the present invention, by adding a preset address offset to the base address of the object instance, the memory address where the signature is located can be located, and the signature of each candidate object instance of the target data type located in the memory can be quickly and accurately extracted from the memory. Then, based on the signature, the target object instance can be accurately identified, so as to implement targeted operations on one object instance in the same data type.
[0117] In an implementation manner of the embodiments of the present invention, the first address offset is determined through the following steps:
[0118] Step S401, obtain the machine codes of multiple sample instances in the memory, where the multiple sample instances include object instances of different types of objects created based on the target data type;
[0119] Step S402, compare the differences between the machine codes of different sample instances, and determine the code fields representing different types of objects;
[0120] Step S403, determine the first address offset according to the relative positions of the code fields in the machine codes.
[0121] Specifically, the target program may create different types of objects based on the same target data type. For example, a game program may create two different types of objects, namely enemy objects and character (i.e., player) objects, based on the character object class. However, since these two types of objects are both created based on the same target data type and have the same data structure in the memory, the embodiments of the present application need to analyze the differences between the machine codes of different object instances created based on the same data type in the memory, so as to determine the code fields that can represent different types of objects, and further determine the first address offset based on the code fields. The multiple sample instances refer to the respective object instances created based on the target data type by the target program in each process. The object instances are in the form of machine codes in the memory, and the machine codes of each sample instance in the memory can be obtained by respectively reading each object instance to a specified register position. Each sample instance is classified into different types of objects, such as character objects or enemy objects.
[0122] Exemplarily, after an object is created, it is stored at a specific location. The internal attribute variables of the object are represented as specific regions in the specific memory block occupied by the object in memory. In the embodiments of the present application, multiple sample instances of objects of the same type can be compared first to determine the parts where the machine codes are the same among the multiple sample instances, and then the differences in this part of the machine code between the sample instances of different types of objects are compared to determine the code fields characterizing different types of objects. Then, the first address offset is determined according to the relative position of the code field in the entire machine code of the sample instance. For example, if the base address of a certain sample instance is 03068970 and the address of the code field that can characterize the type of its object analyzed is 03068988, then the first address offset is 03068988 - 03068970 = 0x18.
[0123] In practical applications, debuggers can use reverse engineering techniques to decompile the executable file of the target program into assembly code. Then, by modifying the states of different types of objects in the assembly code and observing the changes in the memory values of object instances simultaneously, if the memory value of a certain object instance read changes synchronously after modifying the state of a certain type of object, it is determined that the object instance corresponds to the currently modified object type. For example, by modifying the assembly code to fix the attack power of the enemy object to 0 and the defense power to 100, and then observing the changes in the memory values of each object instance, the object instance whose memory value in the corresponding attribute area changes synchronously is determined as a sample instance of the enemy type; similarly, by modifying the assembly code to fix the attack power of the character object to 100 and the defense power to 0, and then observing the changes in the memory values of each object instance, the object instance whose memory value in the corresponding attribute area changes synchronously is determined as a sample instance of the character type, so as to obtain multiple sample instances containing different types of objects. After obtaining multiple sample instances, by comparing the differences between the machine codes of different sample instances, the code fields representing different types of objects are determined. For example, the state of the character instance is affected by user input, while the state of the enemy instance is controlled by the game logic. The character instance may contain control information different from that of the enemy instance. By comparing the sample instances, the code fields corresponding to this part of the control information are determined, so as to determine the first address offset where the signature is located. The debugger can write the analyzed first address offset in advance to a specific position of the register to facilitate the invocation of the object instance operation method. In the case where a certain object instance of the target program needs to be modified, the debugger executes the object instance operation method of the embodiment of the present application after running the target program. The object instance operation method of the embodiment of the present application obtains the base addresses of each candidate object instance of the target data type in the memory, adds the specified first address offset to the memory block base address of each candidate object instance to obtain the first memory address where the signature of the candidate object instance is located, thereby determining the signature of the candidate object instance, and then determines the object instance to be modified according to the signatures of each candidate object instance, and then performs a preset operation on the object instance, so as to achieve targeted operations on specific object instances in the same data type.
[0124] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: In this embodiment, object instances of different types of objects of the target data type are obtained to form multiple sample instances. By comparing the differences between the machine codes of different sample instances, the code fields representing different types of objects are determined, and the first address offset is determined according to the relative position of the code fields in the machine code, so that the object instance operation method can accurately find the signature of the candidate object instance based on the first address offset during execution.
[0125] Refer to Figure 5, in an implementation manner of the embodiment of the present invention, determining the target object instance according to the feature codes of each of the candidate object instances includes the following steps:
[0126] Step S501, determining whether the feature code of the candidate object instance is the expected feature code;
[0127] Step S502, when the feature code of the candidate object instance is the expected feature code, determining the corresponding candidate object instance as the target object instance.
[0128] Specifically, the expected feature code refers to the feature code of the object instance that can be the object of the target type. The feature code may be one or more. For example, the debugger needs to find the object instance of the role type, and its feature code is "0". Therefore, the debugger can specify the expected feature code "0" at a specific position in the register. During the execution of this method, it is judged whether the feature code of each candidate object instance is "0". If so, it is determined that the candidate object instance is the role object instance.
[0129] In another example, the feature code of the object instance of the enemy type is "0", and the feature code of the object instance of the role type is other feature codes except "0". The debugger needs to find the object instance of the role type. Therefore, the debugger can specify the expected feature code "0" at a specific position in the register. During the execution of this method, it is judged whether the feature code of each candidate object instance is "0". If so, it is determined that the candidate object instance is the enemy object instance, otherwise it is the role object instance.
[0130] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: In the embodiment of the present application, by judging whether the feature code of the candidate object instance is the expected feature code, the target object instance among all candidate object instances is quickly screened out, so as to realize targeted operations on the instances of specific types of objects under the same data structure.
[0131] In an implementation manner of the embodiment of the present invention, the expected feature code is determined through the following steps:
[0132] Step S601, obtaining the machine code of multiple sample instances in memory, where the multiple sample instances include object instances of different types of objects created based on the target data type;
[0133] Step S602, comparing the differences between the machine codes of different sample instances to determine the code fields representing different types of objects;
[0134] Step S603, determining the code field of the object instance belonging to the target type of object as the expected feature code.
[0135] Specifically, a target program may create different types of objects based on the same target data type. For example, a game program may create two different types of objects, namely enemy objects and character (i.e., player) objects, based on the character object class. However, since both types of objects are created based on the same target data type and have the same data structure in memory, the embodiments of the present application need to analyze the differences in the machine code of different object instances created from the same data type in memory, so as to determine the code fields that can represent different types of objects, and then select the code fields corresponding to the target type of object as the expected signature code, so as to facilitate the accurate screening of the target object instance during the execution of the object instance operation method of the present solution.
[0136] Exemplarily, the embodiments of the present application may first compare multiple sample instances belonging to the same type of object to determine the parts of the machine code that are the same among the multiple sample instances, and then compare the differences in this part of the machine code between the sample instances of different types of objects, so as to determine the code fields that represent different types of objects, and then use the code fields in the sample instances belonging to the target type of object as the expected signature code.
[0137] In practical applications, a debugger can use reverse engineering techniques to decompile the executable file of the target program into assembly code, and then modify the states of different types of objects in the assembly code and simultaneously observe the changes in the memory values of the object instances. If the memory value of a certain object instance is synchronously changed after modifying the state of a certain type of object, it is determined that the object instance corresponds to the currently modified object type. Through this method, multiple sample instances for classifying different types of objects can be obtained. By comparing the differences between the machine codes of different sample instances, the code fields that represent different types of objects can be determined. For example, the state of a character instance is affected by user input, while the state of an enemy instance is controlled by game logic. The character instance may contain control information different from that of the enemy instance. By comparing the sample instances, the code fields corresponding to this part of the control information can be determined, and then the code fields in the sample instances belonging to the target type of object are used as the expected signature code. The debugger can write the analyzed expected signature code in advance to a specific location in the register to facilitate the invocation of the object instance operation method. In the case where a certain object instance of the target program needs to be modified, the debugger executes the object instance operation method of the embodiments of the present application after running the target program. The object instance operation method of the embodiments of the present application obtains each candidate object instance of the target data type, extracts the signature code of the candidate object instance from the memory, and then determines the target object instance to be modified by judging whether the signature code of the candidate object instance is the expected signature code, and performs a preset operation on the target object instance, so as to achieve targeted operations on specific object instances in the same data type.
[0138] One of the above technical solutions has the following advantages or beneficial effects: In this embodiment, object instances of different types of the target data type are obtained to form multiple sample instances. By comparing the differences between the machine codes of different sample instances, the code fields representing different types of objects are determined, and then the code fields corresponding to the target type of object are selected as the expected feature codes, so as to facilitate the accurate screening of target object instances during the execution of the object instance operation method of this solution.
[0139] Please refer to Figure 6 , in an implementation manner of the embodiment of the present invention, the performing a preset operation on the target object instance includes the following steps:
[0140] Step S701, obtaining a second address offset of the target variable;
[0141] Step S702, determining a second memory address where the target variable is located according to the second address offset and the memory block base address of the target object instance;
[0142] Step S703, performing a modification operation on the memory value at the second memory address.
[0143] Specifically, the target variable refers to a certain variable or attribute that needs to be operated on in the object instance. For example, the attack power attribute or the defense power attribute, etc. The second address offset refers to the distance from the memory block base address of the object instance to the address of the specific position where the target variable is located, usually in bytes. The second address offset is used to locate the target variable in the memory block of the target object instance. Generally, for object instances that reference the same data type, their data storage structures in memory are the same, that is, the distribution of each attribute variable in the memory block of the object instance is the same.
[0144] In an example of an object instance, when a certain target data type is defined in the target program, multiple objects of the target data type can be created by using the new method. For example, the target data type (class) is defined as follows:
[0145] class Character:
[0146] def _init_(self, name, health, attack):
[0147] self.name = name # Character name
[0148] self.health = health # Character health
[0149] self.attack = attack # Character attack power
[0150] Create objects as follows:
[0151] player = Character("Hero", 100, 20) # Create a player character
[0152] enemy = Character("Monster", 80, 15) # Create an enemy character
[0153] In the above example, objects can be created directly based on the target data type. Please refer to Figure 7 , this way of creating will map out an object instance in memory that has the same structure as the Character class.
[0154] In another example, objects can also be created by a subclass inheriting from a base class. For example, define the target data type (base class) and its subclasses as follows:
[0155] class Character{
[0156] def _init_(self, name, health, attack):
[0157] self.name = name # Character name
[0158] self.health = health # Character health
[0159] self.attack = attack # Character attack power
[0160] };
[0161] class Player: public Character{
[0162] ……
[0163] }; # Define the Player subclass
[0164] class Enemy: public Character{
[0165] ……
[0166] }; # Define the Enemy subclass
[0167] Create objects as follows:
[0168] player = Player() # Create a player character
[0169] enemy = Enemy() # Create an enemy character
[0170] In the above example, the Character class is the base class, which contains the attributes and methods common to both characters and enemies. The Player and Enemy classes inherit from the Character class respectively, and can add their own specific behaviors or override the methods in the base class as needed. Please refer to Figure 8 , this creation method will first map the data with the same structure as the Character parent class in the allocated memory block, and then continue to map the data with the same structure as the Player subclass in the same memory block, thus forming an instance of the player character object. The creation process of the enemy character object instance is the same.
[0171] It can be understood that whether it is an object instance directly created based on the target data type or an object instance created by a subclass inheriting from the base class (target data type), each object instance has part of the data with the same structure as the target data type, that is, the distribution of each attribute variable defined in the target data type in the memory blocks of each candidate object instance is the same.
[0172] Exemplarily, the base address of the memory block when obtaining candidate object instances created based on the target data type in the target program can be obtained, and then the target object instance can be determined according to the signature of each candidate object instance. Then, the base address of the memory block of the target object instance is added with a preset second address offset to obtain the second memory address where the target variable of the target object instance is located, and the memory value of the second memory address is modified, so as to realize the modification of the value of the target variable. For example, obtain the base addresses of the memory blocks of the character object instance and the enemy object instance created based on the character object class in the game program, and determine whether the signature of each object instance is the signature of the character object instance, so as to identify the character object instance from each object instance. Then, the base address of the memory block of the character object instance is added with the second address offset to obtain the address where the blood volume status attribute to be modified is located, and the memory value of this address is modified to realize the targeted modification of the blood volume status attribute of the character object instance.
[0173] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: In the embodiment of the present invention, during the running of the target program, after determining the target object instance through the signature, by adding a preset address offset to the base address of the target object instance, the memory address of the variable to be modified in the target object instance can be quickly and accurately located, so as to realize the modification operation of the target variable.
[0174] Please refer to Figure 9 , in an implementation manner of the embodiment of the present invention, the operation of modifying the memory value of the memory address includes the following steps:
[0175] Step S801, obtaining the machine code corresponding to the target modification state;
[0176] Step S802, replace the memory value of the second memory address with the machine code.
[0177] Specifically, the states of the various variables in the object instance constitute the object state. The state of a variable refers to the attribute value of the variable. For example, the attribute value of the attack power variable is 100, and the attribute value of the health status variable is the health maintenance state. The target modification state refers to the attribute value after the target variable is modified. When it is necessary to modify the attribute value of the target variable, first, the target modification state input by the debugger can be obtained through the front-end interaction interface. For example, the input target modification state is attack power 90. Then, the binary machine code corresponding to the target modification state can be determined by querying, and then the memory value of the second memory address of the target variable can be replaced with the queried machine code, so as to achieve the modification of the value of the target variable.
[0178] Exemplarily, the base memory address when creating candidate object instances based on the target data type in the target program can be obtained, and then the target object instance can be determined according to the signature codes of the various candidate object instances. Then, the base memory address of the target object instance is added with a preset second address offset to obtain the second memory address where the target variable of the target object instance is located. The target modification state of the target variable input by the user is obtained, the machine code corresponding to the target modification state is queried in the solid-state memory, and then the memory value of the second memory address of the target variable is replaced with the queried machine code, so as to achieve the modification of the value of the target variable. For example, the base memory addresses of the character object instance and the enemy object instance created based on the character object class in the game program are obtained, and it is determined whether the signature code of each object instance is the signature code of the character object instance, so as to identify the character object instance from each object instance. Then, the base memory address of the character object instance is added with the second address offset to obtain the address where the health status attribute to be modified is located, and the value of the health status variable is modified to the machine code corresponding to the health maintenance state, so as to achieve the modification of the health status attribute of the character object instance to the health maintenance state.
[0179] One of the technical solutions in the above technical solutions has the following advantages or beneficial effects: After determining at least one target variable in the embodiment of the present invention, the machine code corresponding to the target modification state input by the user is obtained, and the memory value of the second memory address where the target variable is located is replaced with the machine code, so that the target variable in the target object instance can be modified to the target state required by the user.
[0180] Please refer to Figure 10 , in an implementation manner of the embodiment of the present invention, before the step of obtaining multiple candidate object instances of the target data type, the object instance operation method further includes the following steps:
[0181] Step S901: Obtain program code, where a function jump code is inserted at the target position of the program code, and the function jump code indicates the address of a hook function.
[0182] Step S902: Execute the program code. When the function jump code is executed, execute the hook function according to the function jump code to jump to and execute the step of obtaining multiple candidate object instances of the target data type.
[0183] Specifically, program code refers to the code with a jump instruction inserted in the target program for creating a target object instance. The jump instruction in the program code is called a function jump code. The target position of the program code refers to the instruction position in the target program that needs to be hooked (i.e., jumped to and executed). A hook function refers to the program method that needs to be executed after the jump. In the embodiments of the present invention, the hook function is used to implement the object instance operation method of the embodiments of the present invention.
[0184] Exemplarily, the program code can be constructed based on the Inline Hook technology as follows:
[0185] Under normal circumstances, a debugger cannot obtain the source code of the target program. What the debugger downloads is the executable program code of the compiled target program. Therefore, the debugger can decompile the executable program code into high-level language code (e.g., assembly language code) through reverse engineering technology to obtain the target program code. At the same time, analyze the memory address of the target position in the running target program through a debugging tool to facilitate the construction of jump instructions.
[0186] Then, write a hook function (i.e., the hook function), and the hook function contains the logic of the object instance operation method of the embodiments of the present invention.
[0187] To jump the execution flow of the target program to the constructed hook function, it is necessary to analyze the address offset of the jump. This address offset is calculated based on the difference between the address of the hook function and the hooked address (i.e., the target position), and at the same time, the number of bytes occupied by the jmp instruction (adjustment instruction) itself (usually 5 bytes) also needs to be considered. That is, the address offset to be jumped = hook address - hooked address - 5 (jmp instruction length).
[0188] After determining the address offset to be jumped, construct a function jump code (i.e., the jmp instruction) based on the address offset of the jump, and then replace the code at the target position in the target program with the function jump code to obtain the program code. The address offset in the function jump code can indicate the position where the program jumps to the hook function.
[0189] In addition, after the method process of executing the hook function is completed, it may be necessary to resume the execution of the original instructions of the target program (i.e., the instructions at the target position). Therefore, before modifying the instructions of the target program, the machine code at the target position can be saved first, and then after the end hook function is executed, the machine code of the jmp instruction can be replaced back with the machine code at the target position.
[0190] In practical applications, when a debugger needs to modify a certain object instance at an appropriate time during the running of the target program, a hook function can be constructed based on the logic of the object instance operation method of the embodiments of the present application. By analyzing the memory address at the target position in the running target program through a debugging tool, the address offset for jumping is determined based on the memory address of the hook function and the memory address at the target position. Then, a function jump code is constructed based on this address offset, and the code at the target position in the target program is replaced with the function jump code, thereby obtaining the program code. When the function jump code in the program code is executed, the object instance operation method of the embodiments of the present invention can be jumped to and executed, so as to achieve the modification of the state of the target object instance. After the execution of the hook function is completed, since the function jump code is replaced back with the original code at the target position, the process of the target program continues to be executed.
[0191] In some embodiments, taking the scenario of modifying a character instance in a game program as an example, the operation process is specifically described as follows:
[0192] A debugger can obtain the GameAssembly.dll file of the game program. When the game program is executed, it will be linked to the GameAssembly.dll file and mapped to the machine code in memory. Generally, GameAssembly.dll is an encrypted file and the source code in the file cannot be obtained. Therefore, the debugger can capture the machine code in memory during the game running, map it to assembly language through reverse engineering technology, and thus find the object instances created by the game program in memory. Further, the mapped assembly language and the machine code of the object instance can be displayed on the front-end interface, so as to facilitate the debugger to analyze the signature of the object instance.
[0193] Compare the machine code in memory of the character object instance and the enemy object instance of the game, determine the features (i.e., code fields) that can distinguish the character object instance from other object instances, and determine the address offset of the feature relative to the base address of the character object instance as the first address offset, and use this feature as the expected signature. For example, at the position of offset 0x18, this memory area can be used as the signature to identify whether it is a character or an enemy. If the memory value at this position is 0, it is an enemy, and if it is non-0, it is a character.
[0194] Construct a hook function based on the first address offset and the expected signature to implement the object instance operation method of the embodiments of the present invention.
[0195] Replace several bytes of instructions at an appropriate position in the game program, and the replaced instructions are used to jump to the hook function.
[0196] After the game program jumps to the hook function, implement the following functional logic in the hook function:
[0197] Query each object instance created based on the character object class during the operation of the game program. These object instances may be character object instances or enemy object instances.
[0198] Determine the memory address where the object instance signature is located based on the base address of the object instance and the first address offset. Use assembly to address and access this memory address in the object instance, fetch the corresponding memory value into a register, and determine whether the register value is 0. If it is 0, it indicates an enemy object instance, and no modification is made to this object instance. If it is non-0, it indicates a character object instance, and the memory value of the target variable of this object instance can be modified. Specifically: Obtain the target variable to be modified specified by the debugger (such as the blood volume status variable), and determine the second address offset based on the relative position of the target variable in the target data type. Then, add the second address offset to the base address of the character object instance to determine the memory address where the target variable is located. Obtain the target modification status specified by the debugger (such as the blood volume holding status), and query to determine the machine code corresponding to this target modification status. Then, replace the memory value at the memory address where the target variable is located with the above machine code.
[0199] After modifying the character object instance, jump out of the hook function and return to the jump position of the game program to continue executing the subsequent steps of the game program.
[0200] Corresponding to the above method embodiments, the present invention also provides an embodiment of an object instance operation system. Figure 11 The structural schematic diagram of the object instance operation system according to an embodiment of the present invention is shown. As Figure 11 shown, the object instance operation system 1101 includes:
[0201] A first module 1102, configured to obtain a plurality of candidate object instances of a target data type;
[0202] A second module 1103, configured to extract the signature of each of the candidate object instances located in the memory from the memory;
[0203] A third module 1104, configured to determine a target object instance according to the signatures of the respective candidate object instances;
[0204] The fourth module 1105 is configured to perform a preset operation on the target object instance.
[0205] The above is a schematic solution of an object instance operating system according to this embodiment. It should be noted that the technical solution of this object instance operating system and the technical solution of the above object instance operation method applied to the object instance operating system belong to the same concept. For the details not described in the technical solution of the object instance operating system, reference can be made to the description of the technical solution of the above object instance operation method.
[0206] As Figure 12 shown, Figure 12 FIG. shows a structural block diagram of an electronic device 1200 according to an embodiment of the present invention. The components of the electronic device 1200 include but are not limited to a memory 1210 and a processor 1220. The processor 1220 is connected to the memory 1210 through a bus 1230, and a database 1250 is used to store data.
[0207] The electronic device 1200 further includes an access device 1240, and the access device 1240 enables the electronic device 1200 to communicate via one or more networks 1260. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 1240 may include one or more of any type of wired or wireless network interfaces (for example, a network interface card (NIC)), such as an IEEE802.11 wireless local area network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.
[0208] In an embodiment of the present invention, the above components of the electronic device 1200 and Figure 12 other components not shown in Figure 12 may also be connected to each other, for example, through a bus. It should be understood that the structural block diagram of the electronic device shown in
[0209] is only for illustrative purposes and is not a limitation on the scope of the present invention. Those skilled in the art can add or replace other components as needed. The electronic device 1200 can be any type of stationary or mobile electronic device, including a mobile computer or mobile electronic device (for example, a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (for example, a smart phone), a wearable electronic device (for example, a smart watch, smart glasses, etc.) or other types of mobile devices, or a stationary electronic device such as a desktop computer or a PC. The electronic device 1200 can also be a mobile or stationary server.
[0210] Among them, the processor 1220 is used to execute the computer-executable instructions of the object instance operation method.
[0211] The above is a schematic solution of an electronic device according to this embodiment. It should be noted that the technical solution of this electronic device and the technical solution of the above object instance operation method belong to the same concept. For the details not described in the technical solution of the electronic device, reference can be made to the description of the technical solution of the above object instance operation method.
[0212] The embodiment of the present invention also provides a storage medium, which is a computer-readable storage medium. This storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above object instance operation method.
[0213] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and may be located in one place, or may also be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0214] Those of ordinary skill in the art will understand that all or some of the steps and systems disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, communication media typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery media.
[0215] The above is a specific description of the preferred embodiments of the present invention, but the present invention is not limited to the above embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of the present invention.
Claims
1. A method for operating an object instance, characterized in that: The following steps are involved: Get multiple candidate object instances of the target data type; Extracting from the memory a feature code of each candidate object instance located in the memory; Determine the target object instance according to the feature code of each candidate object instance; Perform a preset operation on the target object instance.
2. The object instance operation method according to claim 1, characterized in that: The step of extracting the feature code of each candidate object instance located in the memory from the memory comprises the following steps: Determine a first memory address where a feature code of each candidate object instance is located; A memory value of the first memory address is extracted to obtain a feature code of the candidate object instance.
3. The object instance operation method according to claim 2, characterized in that: The step of determining the first memory address where the feature code of each candidate object instance is located comprises the following steps: Obtaining the memory block base address of the candidate object instance; The memory block base address is added with a preset first address offset to obtain a first memory address where the feature code of the candidate object instance is located.
4. The object instance operation method according to claim 3, characterized in that: The first address offset is determined by the following steps: Obtaining machine codes of multiple sample instances in memory, wherein the multiple sample instances include object instances of different types of objects created based on a target data type; Compare the differences between machine codes of different sample instances and determine the code fields that represent different types of objects; A first address offset is determined according to a relative position of the code field in the machine code.
5. The object instance operation method according to claim 1, characterized in that: The step of determining the target object instance according to the feature code of each candidate object instance comprises the following steps: Determining whether the feature code of the candidate object instance is an expected feature code; When the feature code of the candidate object instance is the expected feature code, the corresponding candidate object instance is determined as the target object instance.
6. The object instance operation method according to claim 5, characterized in that: The expected feature code is determined by the following steps: Obtaining machine codes of multiple sample instances in memory, wherein the multiple sample instances include object instances of different types of objects created based on a target data type; Compare the differences between machine codes of different sample instances and identify code fields that represent different types of objects; The code field of the object instance belonging to the target type object is determined as the expected feature code.
7. The object instance operation method according to claim 1, characterized in that: The performing of a preset operation on the target object instance comprises the following steps: Get the second address offset of the target variable; Determine a second memory address where the target variable is located according to the second address offset and the memory block base address of the target object instance; A modification operation is performed on the memory value of the second memory address.
8. The object instance operation method according to claim 7, characterized in that: The modifying operation on the memory value of the memory address comprises the following steps: Get the machine code corresponding to the target modification status; The memory value of the second memory address is replaced with the machine code.
9. The object instance operation method according to any one of claims 1 to 8, characterized in that: Before the step of obtaining multiple candidate object instances of the target data type, the object instance operation method further includes the following steps: Acquire program code, wherein a function jump code is inserted into a target position of the program code, and the function jump code indicates an address of a hook function; The program code is executed, and when the function jump code is executed, the hook function is executed according to the function jump code to jump to the step of obtaining multiple candidate object instances of the target data type.
10. An object instance operating system, characterized in that: include: A first module is configured to obtain multiple candidate object instances of a target data type; The second module is configured to extract from the memory a feature code of each candidate object instance located in the memory; A third module is configured to determine a target object instance according to a feature code of each candidate object instance; The fourth module is configured to perform a preset operation on the target object instance.
11. An electronic device, characterized in that: It includes at least one control processor and a memory for communicating with the at least one control processor; the memory stores instructions that can be executed by the at least one control processor, and the instructions are executed by the at least one control processor to enable the at least one control processor to execute the object instance operation method as described in any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute the object instance operating method according to any one of claims 1 to 9.