pokemon-red-cable-club-hack icon indicating copy to clipboard operation
pokemon-red-cable-club-hack copied to clipboard

Game hangs after trade menu is opened

Open mwpenny opened this issue 3 years ago • 2 comments

Hi there. Very interesting project!

I'm able to get this mostly working (the game brings me to the trade room and I'm able to open the menu). However, once the transfer completes and the menu opens, the game hangs. On real hardware (DMG-APAE-USA Pokemon Red cartridge; tried on a GBA and GBC), I can see the second trainer is named "2" and has a full party of Mews. When using BGB, I see the same thing briefly but then the graphics get corrupted and the game gets stuck in a rst 38 loop (crash):

image image

I tried using older commits but had the same problem. Is there something I'm missing? Let me know if I can provide more information.

Thanks!

mwpenny avatar May 29 '21 18:05 mwpenny

image

Same issue, if I understand correctly the exploit leverage the pkm id 0xce "name" to push 0xD7A3 as ret address in PlaceString: subroutine, so that the execution jumps 228 bytes before the Player2 name (0xD887) where it would jump to the shellcode. But so far so good, The execution crashes right because rst 38 is found. @vaguilar if you could please explain us what's missing, this stuff is totally new to me. Thanks

wh00hw avatar Apr 01 '24 00:04 wh00hw

https://archives.glitchcity.info/forums/board-115/thread-7576/page-0.html

well, the explaination is that if we are near endgame, those nops are actually set as event flags ex. D7B3 - Fought Sabrina Yet?

The exploit works correctly with new saves (tested before Gym 1)

wh00hw avatar Apr 01 '24 13:04 wh00hw