Pokemon Yellow hack recodes the game from within
tasvideos.org
tasvideos.org
Anyway, there is a rising field ("language-theoretic security") that studies this phenomenon. If this Pokemon example interests you, then you should give it a look.
1. In-game, he can write non-arbitrary but sufficiently powerful machine code to be executed directly. He uses this to write layer two.
2. He can write arbitrary machine code using A, B, start, select. He uses this to write layer three.
3. He can write arbitrary machine code using all the buttons (including d-pad combinations that I assume are physically impossible). He uses this to write the balloons.
All the code that actually gets run is precompiled machine code being executed by the processor. (There's nothing to stop him writing a shell, he just didn't.) He's not exploiting a system which happens to be turing-complete, he's gaining access to a system which was designed to be turing-complete but locked down.
Given the complexity and freedom of access that a videogame has, I'm not surprised that this hack is technically possible, but it is very impressive that someone's managed to do it!
A particularly interesting one for programmers might be the M6502 CPU.
All opcodes on the M6502 are 8 bits. Due to the way it was implemented in order to keep transistor count low, various patterns will trigger specific functionality at specific stages of execution (you can find a javascript emulation of it that displays the execution in excruciating detail as the result of creating a transistor exact clone of the design by decapping an actual 6502 CPU and scanning it...).
These were arranged so that the documented instructions present a suitably useful instruction set. But all of the remaining opcodes still does something that was simply deemed pointless by the designers.
Some have been found useful by demo writers in particular as a way of saving cycles. Some are just totally bizarre and/or unstable. Some does fun stuff like putting more than one value on the memory bus at the same time. Some even locks the CPU up so solid it needs to be power cycled to recover...
Here's an overview of the nitty gritty details from someone who actually knows what they're talking about: http://www.pagetable.com/?p=39
I've noticed similar behavior before in the Fire Emblem series. http://m.ign.com/walkthroughs/520430
The number was actually stored in the save file, so you could just count steps until you entered a random battle, reload the system, and take n-1 before healing to completely avoid encounters. I expect this was purposeful because the battle system was so tedious and the encounter rate was obnoxiously high.
Some games have naturally exploitable RNGs too. The GBA RPG Golden Sun and its sequel, for example, had a RNG that was completely reverse-engineered for players to get the top items that normally only randomly drop extremely rarely.
> 10) We think we've figured out how to hack into the computer our universe is running on.
It seems Software Engineering still has a long ways to go as a discipline: games like this fall to exploits by a small community after only a few years, while somehow the universe we live in has survived our civilization (and maybe others) banging on it for billions without any noticeable hiccups. ;)
So, no thanks. Go fuck up your own universe, I'm still using this one!
Then, within the game, the invalid-length-list is used to overwrite other arbitrary locations, including a function pointer to an update procedure. Once that's overwritten he can jump to his own code and it's "game over" as in, he completely controls the hardware.
But from what I can see, it wouldn't be possible without the initial hardware resetting during a write. Not that it diminishes the awesomeness, it'd just be a bit purer if it was a software-only hack.
The guys that do these tool-assisted speed runs are incredible. One fellow plays 4 Mega Mans all at once with a single controller doing input for all 4 games at the same time.
This Pokemon hack is insane, but was inspired by a guy who uses it to beat the game in around 2 minutes. That particular speed run abuses the fact that everything in the game has a simple identifier. So, what he does is inserts a warp point into his inventory, drops it in front of himself, and walks through it to the end of the game.
I built a layer of clojure code on top of the JNI bindings to get
an entirely functional interface to vba-rerecording. This
interface treats state of the emulator as an immutable object, and
allows me to do everything I could do with the lower level C
interface in a functional manner. Using this functional code, I
wrote search programs that take a particular game-state and try
out different combinations of button presses to get any desired
effect. By combining different styles of search with different
initial conditionsAnyway, an example list: http://www.entropyzero.org/Glitches.html.
https://github.com/kanzure/pokecrystal
https://bitbucket.org/iimarckus/pokered
(Red is fairly close to being the same as Yellow. But there are definitely differences.)
The Cortex project they having going is stellar and there are some great examples of Clojure-java interop.
For those that are wondering if something like this is possible outside of computers/video games, I would recommend a study of Lucid Dreaming. If brain hacking is possible, this has to be the best method of entry into the system.
Wow!