TimoVM

433 posts

TimoVM

TimoVM

@Timo_VM

Specialist when it comes to arbitrary code execution setups in the 2nd gen of pokémon games. Made a set of ACE setups for all language releases of gen 2.

Belgium เข้าร่วม Haziran 2023
24 กำลังติดตาม65 ผู้ติดตาม
TimoVM
TimoVM@Timo_VM·
@flag3833753 I recall that LuckyTyphlosion referred to them as “friendly clones”which you could consider using as a term? I think the term originates from the fact that “friendly clones” won’t cause any issues whatsoever on Gold/Silver.
English
1
0
0
89
flag3
flag3@flag3833753·
クリスタルで0x1500制御コード任意コード実行をするのに必要なニックネームのバグったポケモンに呼称をつけたいのだけどどういう名前にすると良いのか
日本語
1
0
2
774
TimoVM รีทวีตแล้ว
The Gears of Progress
The Gears of Progress@GearsProgress·
Poké Transporter GB v1.1.1 has been released! This release fixes a handful of bugs and re-enables Pokémon Yellow (thanks to a new entry point found by @Timo_VM !). With the 0xFE bug fixed and Yellow re-enabled, my focus has fully become adding in language compatibility
English
2
15
129
3.2K
TimoVM รีทวีตแล้ว
The Gears of Progress
The Gears of Progress@GearsProgress·
@mco_ogdenm Hopefully in the coming weeks. The RCE payload has to be rewritten based on an exploit that @Timo_VM discovered- their documentation is great though, so it should hopefully not be too painless
English
1
1
2
241
TimoVM
TimoVM@Timo_VM·
Setup for unnamed clone on 3DS Virtual Console: Box 1 must never have been full. - Put pokémon with item in box 1, save. Deposit one other pokémon and exit, don’t save. - Use PokéTransporter. When done, box 1 still has a pokémon in it, but a box count of 0. - Repeat the video:
English
0
0
5
469
TimoVM
TimoVM@Timo_VM·
@im_a_blisy In a way, yes! If box 1 is active, Transporter takes pokémon from the active box 1 (updated through normal gameplay) instead of the actual saved version of box 1. If the active box 1 happens to have more pokémon than the saved box 1, the saved box count underflows.
English
0
0
1
62
TimoVM
TimoVM@Timo_VM·
Experimenting a bit with Poké Transporter. There’s a pretty huge issue for the Virtual Console releases of gen 2 where Poké Transporter can be used to get a box 1 with a box count of 255 in it. Looks like this could be used to set up ACE without needing a frame perfect trick.
TimoVM tweet media
English
0
0
8
414
TimoVM รีทวีตแล้ว
ア▶︎イス
ア▶︎イス@i_c_e_i_c_e_·
というわけで取得わざを表示するツールを作りました 習得するレベルと技名を順番に表示できます 突貫工事ですが多分ちゃんと動いてます
日本語
4
43
142
11K
TimoVM รีทวีตแล้ว
RETIRE
RETIRE@RETIREglitch·
A nice upgrade to ACE: a simple payload that lets you connect to your PC with a custom GTS server, and send any code to instantly execute it. You no longer have to enter any code manually on the DS. Here I used it to give myself all items.
English
6
46
237
15.3K
TimoVM รีทวีตแล้ว
The Gears of Progress
The Gears of Progress@GearsProgress·
Here’s a video showcasing the entire transfer process for Poké Transporter GB v1.0.0!
English
67
1.1K
5K
549.5K
TimoVM รีทวีตแล้ว
The Gears of Progress
The Gears of Progress@GearsProgress·
I'm extremely excited to announce that Poke Transporter GB v1.0.0 has just released! A lot went into this, but the largest part is a complete visual overhaul by the amazing @LJSTAR_! You can also check out my new video detailing the project here! youtu.be/9mSkGhEYBkg
YouTube video
YouTube
English
1
28
63
3.8K
TimoVM
TimoVM@Timo_VM·
My newest video is now online! It focuses on an improved setup for the Celebi Egg Glitch. It allows you to obtain any pokémon in Gold/Silver/Crystal without using ACE. This improved setup preserves the egg’s DVs, allowing shiny hatches! Link below: youtu.be/QZXRYAsQhbg
YouTube video
YouTube
English
0
0
4
226
TimoVM
TimoVM@Timo_VM·
Working on a new video! This time I’m straying from ACE topics and instead focusing on a Celebi Egg Glitch setup. The first draft of the video is currently undergoing a round of feedback, should be done either tomorrow or somewhere next week depending!
English
0
0
3
172
TimoVM
TimoVM@Timo_VM·
@lan_de_gu_sha You might be interested in pfero’s code: 4F 15 08 05 C9 00 [code] 37 C9 4F changes the write location to the start of the second text line, while 08 05 C9 sets up the sequence E6 F5 05 C9, returning to main text. Too long for JP names, though Source: #Self-contained_setup_and_bootstrap" target="_blank" rel="nofollow noopener">glitchcity.wiki/wiki/0x1500_co…
English
1
0
1
57
wf@天然醤
wf@天然醤@lan_de_gu_sha·
メールで15 0A C0を表示するとCD46~が2E C5 00 C0になるから00で本文に戻れるのか… 2Eは文字の位置で変わるから15 0Aを先頭に置かないとうまくいかないと。 15 0A C9 でも見てみたけれど、2E C5 09 C9になるからこれだとhlレジスタがずれてダメになるな。 #ポケモンクリスタル #任意コード実行
日本語
1
0
1
230
TimoVM
TimoVM@Timo_VM·
@flag3833753 Finally, the various “slots” for the special call ACE setup are essentially abstractions. You can freely place code within the entire area. I’m working on an update for this setup, the Crystal setup crashes during some move animations. Should be done by the weekend!
English
1
0
0
164
TimoVM
TimoVM@Timo_VM·
@flag3833753 There’s been a recent effort by other members of the community to develop a framework for Red/Blue in which a RAM writer can be activated just by pressing select. Still pretty bulky, but might provide a good starting point!
English
1
0
0
123
flag3
flag3@flag3833753·
FF80を用いた任意コード実行で効果のオンオフを気軽にできるようにしたいとは思うのだけどどうするのが良いのかとなっている。専用のツールをゲーム内で作成するのが良いのかな
日本語
1
0
2
747
TimoVM
TimoVM@Timo_VM·
Experimented a bit over the last week and I’ve adopted RGBDS for writing my ACE code. Having a working assembler does wonders for how fast it is to code stuff, and while RGBDS isn’t perfectly suited (since it’s intended for writing actual GB ROMs) it’s adaptable enough for use.
English
0
0
2
163
TimoVM
TimoVM@Timo_VM·
@lan_de_gu_sha Most of the mobile adapter related code is still intact in the English version, but with slightly different RAM pointers compared to the JP version: #L3539" target="_blank" rel="nofollow noopener">github.com/pret/pokecryst… This code isn’t properly documented on our side, likely because it’s both complex and goes unused here.
English
0
0
0
47
TimoVM
TimoVM@Timo_VM·
@lan_de_gu_sha Command $0B does something very similar, buffering values in a similar way, but its function seems to be related to printing numbers of some kind instead. I assume that this means that the address pointer ends up being different compared to $0A, which ends up leading to a crash.
English
1
0
0
46
wf@天然醤
wf@天然醤@lan_de_gu_sha·
15 0A C0(モバイルスクリプト0Aの何か?)が日本語版でどういう挙動なのかがいまいちわからん。15 0B C0は日本語版のメール内で表示しようとしたらフリーズした。 (15 0A C0 00 ~のコード実行はできるんだが…) #ポケモンクリスタル #任意コード実行
日本語
1
0
0
146