Jump to content

Map script arbitrary code execution: Difference between revisions

Now THIS is an awesome find! Let me know if there's any problem with this kind of proofreading.
>Torchickens
(Created page with "'''Map script arbitrary code execution''' is an arbitrary code execution method in {{RBY}}, usually requiring the expanded item pack. ==Summary== Item 42 and item 42'...")
 
>Sherkel
(Now THIS is an awesome find! Let me know if there's any problem with this kind of proofreading.)
Line 1:
'''Map script arbitrary code execution''' is an [[arbitrary code execution]] method in {{RBY}}, usually requiring the [[expanded item pack]].
 
==Summary==
Item 42 and item 42's quantity control wMapScriptPtr (D36E-F in {{RB}} and D36D-E in {{Yellow}}), with the index number of item 42 being the first byte to a little-endian pointer. TheseThis addressesaddress contain the current map script (not to be confused with [[glitch meta-map script activation|the meta-map script]] which is not controlled by wMapScriptPtr).
 
This script is run continuously after the menu is closed. The address can be changed to viableone itemscorresponding to a different item slot, such as Water Stone x 211x211 (Thunderstone x 211x211 in Yellow) to make the script point to item 3 (D322/D321).
 
This is an efficient way of arbitrary code execution, but the items in slot 42 will be wiped after leaving the map, so it may be a good idea to swap the original map script back in before moving to a new map.
 
==See also==
#[[Expanded bag item documentation (Generation I)]]
 
[[Category:Generation I glitches]]
Anonymous user
Cookies help us deliver our services. By using our services, you agree to our use of cookies.