Uploaded May 2020 | Updated September 2026, 2 weeks ago
We use the SameBoy emulator to research what triggers MissingNo and reconstruct a plausible story of how someone could have discovered the glitch. By tracing Game Boy memory reads and writes, we find the stale land-encounter table, the Old Man tutorial's player-name overwrite, and the buggy Cinnabar Island shore tile.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-gameboy-pokemon/pokemon-glitches
Join the Hextree Discord: discord.gg/xgQpCQCpvy
GameBoy Hacking Playlist: youtube.com/watch?v=ix5yZm4fwFQ&list=PLniOzp3l9V82onKsktyyKlIenAAUj45Mk
Checkout Stacksmashing's video about modifying GameBoy games: youtube.com/watch?v=dQLp5i8oS3Y&list=PLniOzp3l9V82onKsktyyKlIenAAUj45Mk&index=3
Coincidentally somebody else also just made a video about MissingNo, going into the details of the Sprite: youtube.com/watch?v=ZI50XUeN6QE
CHAPTERS
00:00 - The MissingNo ritual and item glitch
01:32 - Reconstructing how the glitch could be discovered
02:57 - The coastline reuses previous encounter data
04:48 - The Old Man tutorial as the MissingNo trigger
05:25 - Forming a memory read and write hypothesis
06:06 - Adding trace commands to the SameBoy emulator
07:15 - Capturing Old Man writes and shoreline reads
08:50 - Intersecting traces and filtering background activity
10:36 - Watching the final candidate addresses
12:00 - Zone updates and decoding the player name ASH
13:45 - Stale land encounters on the buggy shore tile
15:14 - Identifying Pokémon ID and level pairs
16:10 - Separate land and water encounter tables
17:11 - The item multiplication mystery remains
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pokemon #MissingNo #GameBoy #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
We use the SameBoy emulator to research what triggers MissingNo and reconstruct a plausible story of how someone could have discovered the glitch. By tracing Game Boy memory reads and writes, we find the stale land-encounter table, the Old Man tutorial's player-name overwrite, and the buggy Cinnabar Island shore tile.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-gameboy-pokemon/pokemon-glitches
Join the Hextree Discord: discord.gg/xgQpCQCpvy
GameBoy Hacking Playlist: youtube.com/watch?v=ix5yZm4fwFQ&list=PLniOzp3l9V82onKsktyyKlIenAAUj45Mk
Checkout Stacksmashing's video about modifying GameBoy games: youtube.com/watch?v=dQLp5i8oS3Y&list=PLniOzp3l9V82onKsktyyKlIenAAUj45Mk&index=3
Coincidentally somebody else also just made a video about MissingNo, going into the details of the Sprite: youtube.com/watch?v=ZI50XUeN6QE
CHAPTERS
00:00 - The MissingNo ritual and item glitch
01:32 - Reconstructing how the glitch could be discovered
02:57 - The coastline reuses previous encounter data
04:48 - The Old Man tutorial as the MissingNo trigger
05:25 - Forming a memory read and write hypothesis
06:06 - Adding trace commands to the SameBoy emulator
07:15 - Capturing Old Man writes and shoreline reads
08:50 - Intersecting traces and filtering background activity
10:36 - Watching the final candidate addresses
12:00 - Zone updates and decoding the player name ASH
13:45 - Stale land encounters on the buggy shore tile
15:14 - Identifying Pokémon ID and level pairs
16:10 - Separate land and water encounter tables
17:11 - The item multiplication mystery remains
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#Pokemon #MissingNo #GameBoy #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.





![Kernel Root Exploit via a ptrace() and execve() Race Condition
Lets have a look at a recent kernel local privilege escalation exploit!
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-system-hacking/serenity-os-kernel-exploits
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
Exploit Source: https://hxp.io/blog/79/hxp-CTF-2020-wisdom2/
Kernel Developer Walkthrough: https://www.youtube.com/watch?v=LORxdO1XUjY
Syscalls, Kernel vs. User Mode and Linux Kernel Source Code: https://www.youtube.com/watch?v=fLS99zJDHOc
How Do Linux Kernel Drivers Work? https://www.youtube.com/watch?v=juGNPLdjLH4
👕 T-Shirt Series: https://www.youtube.com/playlist?list=PLhixgUqwRTjwy6HCzLfwNzdrSrcrLOM4d
CHAPTERS
00:00 - Introduction
00:15 - Exploit PoC
00:39 - main()
00:52 - prepare_shellcode()
02:39 - mmap() shared memory to signal ready state
03:07 - fork() into [child] and [parent]
03:44 - [parent] wait for the child
04:00 - [child] unveil() loop
05:03 - [parent] ptrace ATTACH and POKE child
05:58 - [child] execve(passwd)
06:38 - [parent] PEEK entrypoint of child in loop
07:34 - [parent] child entrypoint changes!
07:49 - Exploit Walkthrough
09:20 - Root Shell via Shellcode
10:10 - Vulnerability Summary
10:37 - Which UNIX-like Kernel is this?
12:44 - The importance for Security Research
13:59 - Next Video and Resources
14:22 - Patreon and YT Members
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BinaryExploitation #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Kernel Root Exploit via a ptrace() and execve() Race Condition](https://i.ytimg.com/vi/qUh507Na9nk/mqdefault.jpg)



![Solving Nintendo HireMe!!! with Basic Math
We are going to solve the Nintendo HireMe.cpp challenge with some basic math. I call it basic because linear algebra is taught pretty early in school. But I know it is not so easy to figure out that it can be used here. Also, the trick with GF(2) is math that you would only learn at university. But if you watched my videos, you would have known it from the software_update video writeup ;)
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-cryptography/cracking-with-z3-theorem-prover
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
Watch part 1 - Introduction: https://www.youtube.com/watch?v=6sHSDoJ5a1s
software_update challenge writeup: https://www.youtube.com/watch?v=EOlddNofKxo
HireMe.c: https://www.nerd.nintendo.com/files/HireMe
My Solution Notebook: https://gist.github.com/LiveOverflow/683181b72b4123fdb325956d6f038e72
SageMath and Jupyter Notebook: https://www.sagemath.org/
z3: https://github.com/Z3Prover/z3
CHAPTERS
00:00 - Introduction
00:26 - What Made It Click?!
01:13 - Alternative Mathematical Representation
02:04 - Recognizing Linear Algebra
03:00 - Matrices Math
04:15 - Using SageMath
04:40 - Galois Field GF(2)
06:06 - Creating and Solving the System of Equations
08:23 - Tackling the XOR Bruteforce Part
09:40 - Start of Walkthrough: Inverting s-box
10:17 - inp_to_out() and Recursive solve_round()
11:10 - Generate Internal Input[] Candidates with z3
12:45 - Kicking off the Solving Algorithm
13:41 - Cliffhanger: SageMath + Jupyter Notebook
14:02 - Finding a Solution!!!!!
14:22 - Conclusion
15:22 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#CTF #Cryptography #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Solving Nintendo HireMe!!! with Basic Math](https://i.ytimg.com/vi/thbZwi6WwIE/mqdefault.jpg)
