Skip to content
TrackPodcasts
technologySep 2, 202641:33pending

#600: This Free Tool Decodes Game Boy ROM From a Photograph

David Bombal

About this episode

Can you recover working software from a photograph of a microchip?


Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.


The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.


Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.


The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.


The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.


// Sponsored SEGMENT //

Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal


// Link to No Starch Website for Travis’ Book //

Order Microcontroller Exploits and get the eBook free.

https://nostarch.com/microcontroller-...


Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com


// Travis Goodspeed SOCIAL //

GitHub: https://github.com/travisgoodspeed


// GitHub link to GameBoy ROM Tutorial //

https://github.com/travisgoodspeed/gb...


// David's SOCIAL //

Discord: discord.com/invite/usKSyzb

Twitter: www.twitter.com/davidbombal

Instagram: www.instagram.com/davidbombal

LinkedIn: www.linkedin.com/in/davidbombal

Facebook: www.facebook.com/davidbombal.co

TikTok: tiktok.com/@davidbombal

YouTube: / @davidbombal

Spotify: open.spotify.com/show/3f6k6gE...

SoundCloud: / davidbombal

Apple Podcast: podcasts.apple.com/us/podcast...


// MY STUFF //

https://www.amazon.com/shop/davidbombal


// SPONSORS //

Interested in sponsoring my videos? Reach out to my team here: [email protected]


// MENU//

0:00 - Coming Up

0:40 - Intro

03:28 - Book Overview

05:27 - Proton Pass Ad

07:29 - Demonstration Context

09:56 - Demo Begins

12:48 - Marking the Chip Rows

18:27 - How Travis Wrote his Book

19:55 - Design Rule Check

23:11 - How to Decode the Binary

28:36 - Can the Binary Numbers Change?

30:30 - Why is this Method Useful?

34:24 - More book Overviews

40:48 - Conclusion


Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!


Disclaimer: This video is for educational purposes only.

#gameboy #reverseengineering #rom

Get every episode summarized

Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

#600: This Free Tool Decodes Game Boy ROM From a Photograph

David Bombal

0:00
41:33

More episodes

More from David Bombal

View all episodes →