
#600: This Free Tool Decodes Game Boy ROM From a Photograph
About this episode
Can you recover working software from a photograph of a microchip?
Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.
The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.
Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.
The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.
The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.
// Sponsored SEGMENT //
Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal
// Link to No Starch Website for Travis’ Book //
Order Microcontroller Exploits and get the eBook free.
https://nostarch.com/microcontroller-...
Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com
// Travis Goodspeed SOCIAL //
GitHub: https://github.com/travisgoodspeed
// GitHub link to GameBoy ROM Tutorial //
https://github.com/travisgoodspeed/gb...
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
// MENU//
0:00 - Coming Up
0:40 - Intro
03:28 - Book Overview
05:27 - Proton Pass Ad
07:29 - Demonstration Context
09:56 - Demo Begins
12:48 - Marking the Chip Rows
18:27 - How Travis Wrote his Book
19:55 - Design Rule Check
23:11 - How to Decode the Binary
28:36 - Can the Binary Numbers Change?
30:30 - Why is this Method Useful?
34:24 - More book Overviews
40:48 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#gameboy #reverseengineering #rom
Get every episode summarized
Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from David Bombal

#599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds
David Bombal

#598: AI Can’t Understand Intent. That’s a Security Problem
David Bombal

#597: The Hacking Gadgets You Need to Know
David Bombal

#596: This is the Real Cybersecurity Problem
David Bombal