NES Game Genie Technical Notes (2001)
tuxnes.sourceforge.net
tuxnes.sourceforge.net
My favourite code is ANTOSA. This is a code for Super Mario Bros. which turns all pipes you can't enter upside-down. SMB1 has been disassembled with commentary, so it's now possible to see how the code works. It turns out there is a table of blocks for the top two layers of both non-warp and warp pipes, that looks like this:
VerticalPipeData
98dd: 11 10 .bulk $11,$10 ;used by pipes that lead somewhere
98df: 15 14 .bulk $15,$14
98e1: 13 12 .bulk $13,$12 ;used by decoration pipes
98e3: 15 14 .bulk $15,$14
The code to draw the pipes gets this address of this table and stores it in the Y register. Then, if the pipe isn't a warp pipe, it executes 4 INY (increment Y) instructions in a row to adjust the offset.The ANTOSA code just replaces two of the INY instructions with a two-byte BVS (Branch on Overflow Set) instruction. However, the Overflow flag is never set at this point, so effectively this instruction is a two-byte no-op.
The practical upshot is that Y is only incremented by 2, which means it points two bytes inside the "pipes that lead somewhere" data rather than directly at the "used by decoration pipes" data. It turns out that the first two bytes determine the top of the pipe, and the second two bytes determine the second layer, so decoration pipes are effectively drawn (second layer, top layer). And voila -- "upside down" non-warp pipes.
If it was intentional, it was very clever. But I suspect it wasn't -- BVS is an odd choice for a two-byte NOP! An alternative would be change one of the INYs to a DEY (decrement Y), producing the functionally-equivalent codes EETOKX, EETOSX, EETOVX or EETONX, depending on which INY you change. I admit ANTOSA sounds cooler.
The full SMB disassembly (not mine) is here if you're interested: https://6502disassembly.com/nes-smb/SuperMarioBros.html
* Typically. NES cartridges could also contain RAM.
https://youtu.be/yjBsHyJlkRE?t=16
---
There is a guy on Youtube called "Displaced Gamers" that explains how NES games work. There is an interesting episode where he breaks down how a certain item in the game Faxanadu behaves.
It's a pendant that is supposed to increase your attack power, but when you get it does the opposite. In the video he explains exactly what is going on in the code: the game was shipped with a bug.
He then goes about crafting a Game Genie code to fix the bug. It's a fascinating video:
https://www.youtube.com/watch?v=FeemO9yW-hs
---
If you are curious as to how the Game Genies works, watch this:
https://www.youtube.com/watch?v=C86OsYRACTM
---
If you are curious about the origins of the Game Genie, watch this:
I'm definitely going to go through his past videos - looks like so much interesting stuff in there.
https://gamefaqs.gamespot.com/boards/522595-final-fantasy/45...
> The code is GOSSIP (amazing coincidence that it happens to also be an English word). This works in Capcom's Ghosts 'n Goblins to start your player with a really funky weapon.
Oh, the potential for easter eggs if you anticipated the use of a Game Genie by players, this was meta-gaming at its earliest in strictly offline mode. You could even hide codes in-story for later replays and whatnot. What's not to love about such a hacky mode of expression, a hacking-friendly barebones paradigm.
Most modern emulators have similar but much more fleshed out features. They're nice not only for finding cheat codes but for reverse engineering games for the purposes of making romhacks or tool assisted speedruns and things like that.
Incidentally, Game genie and Gameshark were the first time I realized I was committing piracy (or any crime), when I was asked to leave a store for writing down a code that was in one of those 10,000 Game Codes books. It's been a long sordid tale of hidden algebra notecards and microscopic formula sheets ever since.
This life of crime chose me.
It can do more than that of course, but it's cool to see that the gameshark I had as a little kid worked in a similar fashion.
Even though I had an interest in programming from a young age, before learning how to use those plug-ins, it hadn't really dawned on me that everything in the game, like your health, location, stats, and even your characters current action, were all states stored in memory somehow.
Using those plugins (or similar), you can narrow down and manipulate all sorts of values. Infinite ammo? Just lock the value to something greater than 0. Even just locking the height value of your position opened up interesting avenues because you could circumvent gravity in a way that was relatively easy to find.
Tangentially, if this sort of thing entertains you as it does me, the magic system in the Magic 2.0 book series by Scott Meyer effectively works like a cheat engine.
> The process of searching for working codes would have been slow and tedious, though as Menzies explains, the team came up with little tricks to speed things up. "I wired up a Commodore 64 to control a prototype Game Genie using a pop-up utility on the Commodore, so we could type codes directly in hex, which was a big improvement over using the NES controller. Also we managed to daisy-chain two Game Genies so we could enter up to six codes at once, which sped things up a bit. [...]
> "It wasn't very glamorous," adds Rigby. "And it took about three days to go through a game, sometimes longer for some of the popular RPGs. The thing I remember most was the very first dev kit; it was a few rows of switches soldered onto the top of a black 5.25-inch floppy disk box. They were binary switches and you had to flick the position to 0 or 1 to represent the address and the value you wanted to change to." [...]
[1] - https://www.nintendolife.com/features/the-story-of-the-game-...
Game Shark on later systems did "freeze" ram and the Pro models on psx/n64 had really nice code searching features like you're describing.
https://en.wikipedia.org/wiki/Lewis_Galoob_Toys,_Inc._v._Nin....
Also patching isn't really the right word either. They were more like conditional freezes, because of bank switching. The game genie had no idea what bank was loaded at any given time so the codes say "if this address is this right now, make it that instead" so it would (ideally) only be active when the right bank was set. But that's why some gg codes had weird side effects, because they were affecting other banks than the important one.
Super cool.
The answer these days is emulation & memory search. Memory search gets used for hacking native PC games these days too although it's a lot harder when anti-cheat is involved.
You give it a query like "show me values that decreased since we started observing" and you repeat the process to winnow it down to a memory location or set of locations. You then try fixing the memory location to a value and see what the game does.
Incidentally, in Link to the Past, the heart containers are denominated in units of 4, which can throw you off. Going from 4 hearts to 3 means the value goes from 16 to 12. If you went down to 3.5 hearts it'd be 14.
The device really was cool as shit, it was my first introduction into doing anything with computers really, I spent hours creating my own codes as a kid.
IIRC cheat codes were often published in popular gaming magazines as well, which is how you found most of them in the world before widespread Internet & PC access. I'd assume that either manufacturers or some other party found common codes manually via similar methods to this.
I hit my apex a few years later in the n64 era when a few games started to leave in cut content or beta stuff. Gamesharking cut content back into Goldeneye and Banjo Kazooie blew the other kids’ minds back then.
Funnily enough, a few years ago I found myself using Cheat Engine to skip a grindy part of a game - and it turned out that the code hunting skills from my childhood transferred perfectly. The exact same techniques from that old VHS tape applied, all wrapped up in a modern GUI.
There was a guide with it that more or less said to try random things and that maybe F would have more effect than 0 but it gave no indication that I can recall of how the device worked or why F might do more than 0.
Of course now I know that it's just modifying bits of memory (and how that can screw things up...) and that if you're doing a life counter or something, F is a bigger number, but yeah, it was never remotely clear to me as a kid what it was doing.
Still couldn't get anywhere in Battletoads even with infinite lives!
Also, the form factor seemed like it hastened the demise of our NES, making the cartridge connection even more flakey than normal wear and tear.
This is pure speculation on my part and is, it seems, incorrect.
IIRC it was mostly how the wedge on top pushed things down so the bundle would correctly be detected as completely inserted, eventually the Game Genie was pretty much required.
I fail to see why that was an outcome they wanted to avoid.
I would have felt pretty ripped off if I had spent what little money I could get on the newest Super Mario Bros. 3 codes only to discover it was six extra lives when I already had a code for three.
Then there is an example of a code: "ZEXPYGLA". I'd think it was designed to be easier to memorize.