Help with making a TTYD save exploit?

Discussion / Support for Softmods (SDML, AR, Game Hacks)
Post Reply
User avatar
Posts: 23
Joined: Sat Jun 27, 2015 8:39 pm

Help with making a TTYD save exploit?

Post by Zephiles » Sun Jan 03, 2021 7:49 pm

Most people aren't aware of this, but TTYD (Paper Mario: The Thousand-Year Door, just to clarify if that's not obvious) has a save exploit that can be used to load a dol from a memory card like any of the other game exploits listed in this Softmods section. The save exploit was found by me, and I fully understand how it works, but the problem is that I don't know how FIX94's loader code and whatnot works, and I don't really want to spend a lot of time trying to figure it out. So the point of this thread is to see if there's anyone around that knows how that code works, so it can be applied to TTYD.

If anyone wants to see TTYD's save exploit in action, it has already been used for a different project: To load a REL file from the memory card, stored inside of a save file. To be more specific, this mod is designed to modify one of the game's save files, so that loading it modifies the game's reset code, reboots the game, and then loads a REL file at boot. Unlike FIX94's code, the main code in this one was written purely in assembly, and is applied via Python (although we also have a web patcher that applies the changes via JavaScript).

This project can be found here, premade saves for it can be found here, and an example of a REL mod that can be loaded with it can be found here.
TTYD Speedrunner
Post Reply