Uploaded September 2019 | Updated September 2026, 2 weeks ago
We continue with Cheat Engine to find the player and camera position in Pwn Adventure 3. These stable pointer paths and camera-update instructions prepare a proper fly hack for the next episode.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-pwn-adventure/windows-game-hacking
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Blog post: liveoverflow.com/player-and-camera-position-for-fly-hack-pwn-adventure-3-2
Playlist: youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw9DnQtssdAwgG
CHAPTERS
00:00 - Why the first fly hack was not good enough
00:35 - Scanning for the player's height
02:34 - Fixing a failed scan with freeze tests
04:24 - Finding XYZ coordinates and teleporting
05:48 - Building a stable position pointer path
07:48 - Discovering camera position and direction
08:39 - Designing a fly hack around the camera
10:01 - Freezing the camera position update
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#PwnAdventure3 #Pwnadventure #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
We continue with Cheat Engine to find the player and camera position in Pwn Adventure 3. These stable pointer paths and camera-update instructions prepare a proper fly hack for the next episode.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-pwn-adventure/windows-game-hacking
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Blog post: liveoverflow.com/player-and-camera-position-for-fly-hack-pwn-adventure-3-2
Playlist: youtube.com/playlist?list=PLhixgUqwRTjzzBeFSHXrw9DnQtssdAwgG
CHAPTERS
00:00 - Why the first fly hack was not good enough
00:35 - Scanning for the player's height
02:34 - Fixing a failed scan with freeze tests
04:24 - Finding XYZ coordinates and teleporting
05:48 - Building a stable position pointer path
07:48 - Discovering camera position and direction
08:39 - Designing a fly hack around the camera
10:01 - Freezing the camera position update
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#PwnAdventure3 #Pwnadventure #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.




![Understanding C Pointer Magic Arithmetic | Ep. 07
We debug the line that causes the heap overflow. And its a great opportunity to understand pointers in C.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/understanding-the-vulnerability
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
The full playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
Grab the files: https://github.com/LiveOverflow/pwnedit
The original disclosure: https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit
Episode 07:
CHAPTERS
00:00 - Intro & Motivation
00:46 - Create Debug Build
01:02 - The Crashing Location
01:43 - Scary Pointer Magic
02:10 - *to++ = *from
02:56 - Explaining: from++
04:03 - Explaining: *from
04:56 - Explaining: to++
05:23 - Explaining: *to = *from
05:54 - The Copy While Loop
06:26 - Explaining: from[0] vs *from
07:14 - The Bug!
08:35 - Wrong Allocation Size Calculated
09:30 - Unescape Logic
10:15 - Why though?
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BufferOverflow #BinaryExploitation #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Understanding C Pointer Magic Arithmetic | Ep. 07](https://i.ytimg.com/vi/zdzcTh9kUrc/mqdefault.jpg)