Party Pokémon 82 and 81 swap for text command 0x7A arbitrary code execution (Red/Green JP)  @ChickasaurusGL
Party Pokémon 82 and 81 swap for text command 0x7A arbitrary code execution (Red/Green JP)  @ChickasaurusGL
Evie (ChickasaurusGL) 🌺 | Party Pokémon 82 and 81 swap for text command 0x7A arbitrary code execution (Red/Green JP) @ChickasaurusGL | Uploaded March 2022 | Updated October 2024, 37 minutes ago.
Notes: In Pokémon Red and Green, as documented by ice_ice, swapping party Pokémon 82 with 81 runs arbitrary code execution at D106. This is apparently due to the invalid 0x7A text command. twitter.com/i_c_e_i_c_e_/status/1474353856452898821

Using LWA, you can set up both the expanded inventory (and a custom name), and the data at D106 in one glitch Poké Mart. Afterwards, swapping Pokémon 82 with 81 immediately runs your code at D106 (Hall of Fame script in this video).

The setup is based on the LWA exploit here, with a current PC box already set up. youtube.com/watch?v=yhEPteRdH3g

I may come back to the description another time though, to add more information.

Save file where repeating the steps in this video should work (swap item 1 and item 2 into the text pointer table items just below the ????? and talk to the lady):
drive.google.com/file/d/17uzYMIQMjzphv13_ytB1a5HvXTbGG-xp/view?usp=sharing
Party Pokémon 82 and 81 swap for text command 0x7A arbitrary code execution (Red/Green JP)Decamark 0x4A7As corruption of Trainer name/card/gender (Pokémon FireRed and LeafGreen)Unlock Mobile System GB +get (unredeemable) Egg Ticket, Battle Tower w/ACE (Crystal JP) (request)Game Boy Printer bad serial/opcode arbitrary/remote code proof of concept (Pokémon Yellow)Attempting to exchange the Bike Voucher with a full bag of 20 items (Generation I)Game Boy (DMG) boot ROM Rev 1 as opposed to Rev 0 cart handling comparisonsBuffer overflow caused by extremely long Rival name in battle (Pokémon Gold and Silver)Locating the warping (parallel universe) NPC caused by playing sound 00 (Generation I)Glitches when modifying memory address D09B before viewing a text box (Red/Blue)Trading (8F) arbitrary code execution programs w/friends with up to 6 party Pokémon (Generation I)Giovanni door soft-locking (similar to Cinnabar Island Blaine Door) Dokokashira door glitch (RG JP)Clearing the mailbox (EN Gold/Silver)

Party Pokémon 82 and 81 swap for text command 0x7A arbitrary code execution (Red/Green JP) @ChickasaurusGL

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER