Using Dex dump glitch to simulate the expanded party and almost filling our Pokédex (Generation I)

Subscribers:
17,700
Published on ● Video Link: https://www.youtube.com/watch?v=eYbtwSCY0Bw



Duration: 11:42
674 views
24


This glitch exploits a buffer overflow from a very long Pokédex entry. For this video, we choose glitch Pokémon 0xDC in Red/Blue https://glitchcity.wiki/GlitchDex/RB:220 (Pokédex sourced from SRAM AA00).

This glitch Pokémon is a hybrid of Pidgeotto, so to exploit this glitch we must not have Pidgeotto owned in the Pokédex.

Typically, its Pokédex entry will freeze the game, but in this video (following the preparations and steps in the Pastebin below), we use the glitch to have the party cursor be at No. 256 (even if you don't have the expanded party), allowing us to swap Pokémon 144 with Pokémon 10 to give us a lot of Pokédex entries.

(See https://pastebin.com/ZTdrvhPt )

How we avoid the freeze:

1. We'll want to be on SRAM bank 00 and it must be opened. To do that, we'll view a Pokémon's summary from the party before catching the 0xDC outside of battle with Rival LG. So we'll need a six letter long Rival's name, 9F, glitch item 0x9E and Master Balls to do Rival LG. See https://glitchcity.wiki/Rival_LOL_glitch
2. SRAM from 0:AA00 must be 'good'; the best way is to have it all up to where we want to corrupt as FF by starting over with a new save file. We must also never view glitch Pokémon sprites in case they corrupt the data, because control characters or multiple length characters could mess up our plans. Although it takes a while, you can duplicate items and get the expanded inventory and expanded PC items with dry underflow glitch without seeing MissingNo. by getting Ditto from Brock Through Walls, and doing the move 0x00 corruption glitch in Diglett's Cave to catch MissingNo. twice. To get it the second time, make sure to correct the flipped sprites by viewing a normal Pokémon's summary. Have yourself in Fuchsia City.

https://glitchcity.wiki/Brock_through...
https://glitchcity.wiki/Move_0x00_cor...)
https://glitchcity.wiki/Dry_underflow...
https://glitchcity.wiki/Expanded_item...
https://glitchcity.wiki/Expanded_PC_i...)

3. We'll want to enter a specific Hall of Fame induction with data containing a 0x50 terminator to terminate our data (this is where the expanded PC items comes into play, which we can acquire by depositing a x255 stack into the PC and doing the normal dry underflow glitch steps). Although this glitch has potential to be more powerful, with single-length characters and no terminating control characters B372 touches CD6B (wJoyIgnore) and chances are due to the complexity of the characters/chances of a 0x50 terminator, 0x00 byte etc. working out desired SRAM corruption(s)/Hall of Fame induction(s) that doesn't lock up the controls and corrupts the needed data would make preparing it harder. For now, we place the 0x50 byte a little before B372 to give us a glitch cursor position for setting up the equivalent of expanded party/'Select glitch' corruptions later without actually needing the expanded party.

4. To do that, have your only party member as a Level 80 (80 is 0x50 in hexadecimal) non-glitch Pokémon. Make sure you've never entered the Hall of Fame (retaining FF bytes), but at the same time trick the game into thinking it's your 37th induction by changing expanded PC item 52 (D5A2) to x36, and entering the Hall of Fame by changing item 36's quantity to x118 in the expanded bag (if you're swapping the above Ultra Ball x0 into item 36 to toss from map 256-, beware tint 0x07 will make the screen black in Super Game Boy mode, so it's good to change item 36 quantity from 7 to another value such as 6 first). This will register the 37th Hall of Fame entry causing a long corruption up to the 0x50 in your Pokémon's Level, but without touching B372 (would corrupt CD6B).

Effects:

The graphics will be corrupted (I think it's because the glitch Pokémon's sprite wrote to VRAM) and some data before ~CD6B has been corrupted. We use the corrupted cursor position to almost fill the Pokédex by swapping Pokémon 144 with Pokémon 10 (from position 256 this is up 112 times; choose switch, up 102 times, A) , and save and reset the game to avoid a game freeze.




Other Videos By Evie (ChickasaurusGL) 🌺


2023-09-08Experimental Pokédex nest buffer overflows (Generation I)
2023-09-08Cloning over/deleting a corrupted box contents w/arbitrary code execution (Gold/Silver EN request)
2023-09-08Clearing the mailbox (Japanese Crystal) (request)
2023-06-20Get any Pokémon w/any move+set of internal types (AncientPower Bulbasaur in video) (No ACE) (Yellow)
2023-06-01The uppercut invulnerability exploit (Game Freak's 1994 Pulseman) (warning: flashing lights)
2023-05-27Exploiting Game Boy Camera's SRAM storage to run minigames via cart swap (w/shoddy "Snek Fly" game)
2023-04-18NamingScreenType (D07D/C) arbitrary code execution (Generation I)
2023-04-18Agatha's badge describer glitch and arbitrary code execution from Antidote badge (Pokémon Red/Blue)
2023-04-18Special text box IDs during Trainer-Fly that work independent of maps (Generation I)
2023-04-18Use DHNhIT4 89 ゥ N (0x74) to obtain the 0xFF PP value without PP underflow glitch (Pokémon Yellow)
2023-03-21Using Dex dump glitch to simulate the expanded party and almost filling our Pokédex (Generation I)
2023-02-27Level 0 Pokémon cannot evolve by stone/obtain Level 0 Clefairy w/Brock Through Walls (Generation I)
2023-02-27Obtain MissingNo. (0xAF) with GoldBadge item (addendum to the GoldBadge glitch) (Red/Green v1.0)
2023-02-27Select glitch 35 Pokémon swap for instant Safari Zone exit glitch (Glitch City) (Red/Green/Blue JP)
2023-02-19Manipulating the unused Silph Co. 11F wLastMap warp 10 (Another Glitch City glitch) (Generation I)
2023-02-18Locating the warping ('parallel universe') NPC caused by playing sound 00 (Generation I)
2023-02-18Character misalignment glitches (Generation I)
2023-02-18Select glitch species corruption with party swap 178 for battling ィ゙ゃゾA (00) (Red/Green/Blue JP)
2022-12-28Oak Through Walls concept (Pallet Town Professor Oak guide abuse) (Generation I)
2022-12-28Attempting to exchange the Bike Voucher with a full bag of 20 items (Generation I)
2022-12-28Placeholder and unused Professor Oak text (Generation I)