Originally Posted by
Dead_Man
...
By the way, where did you get 0x3C40 pointer?
Have a look at the memory editing section, it's quite simple.
1) 3.0.9 Offsets thread, theres a LUA dump -> 0x006333E0 - UnitTracking
2) Open WoW in IDA/OllyDbg and take a look
3) Follow the function flow, you'll then find a call to this function at 0x0062E160.
Code:
0062E160 /$ 53 PUSH EBX
0062E161 |. 56 PUSH ESI
0062E162 |. 8BF1 MOV ESI,ECX ; ECX = ESI = basepointer
0062E164 |. 8B46 08 MOV EAX,DWORD PTR DS:[ESI+8]
0062E167 |. 8B58 04 MOV EBX,DWORD PTR DS:[EAX+4]
0062E16A |. 57 PUSH EDI
0062E16B |. 8B38 MOV EDI,DWORD PTR DS:[EAX]
0062E16D |. E8 BEE0E3FF CALL Wow.0046C230
0062E172 |. 3BF8 CMP EDI,EAX
0062E174 |. 75 04 JNZ SHORT Wow.0062E17A
0062E176 |. 3BDA CMP EBX,EDX
0062E178 |. 74 06 JE SHORT Wow.0062E180
0062E17A |> 5F POP EDI
0062E17B |. 5E POP ESI
0062E17C |. 33C0 XOR EAX,EAX
0062E17E |. 5B POP EBX
0062E17F |. C3 RETN
0062E180 |> 8B86 38100000 MOV EAX,DWORD PTR DS:[ESI+1038] ; [basepointer + 0x1038]
0062E186 |. 8B80 88130000 MOV EAX,DWORD PTR DS:[EAX+1388] ; [[basepointer + 0x1038] + 0x1388] = tracking stuff
0062E18C |. 5F POP EDI
0062E18D |. 5E POP ESI
0062E18E |. 5B POP EBX
0062E18F \. C3 RETN
[[basepointer + 0x1038] + 0x1388] = tracking stuff
4) Have another look at the 3.0.9 Offsets thread, Arigity posted the local playerbase pointer
[[[[[0x127F13C]+0x30]+0x28]+0x1038]+0x1388] = tracking stuff
Greetings