A 1980 BASIC game called The Wizard's Castle, written for the Exidy Sorcerer and published in a print magazine, hid executable Z80 machine language inside a REM comment on line 10. Beej's blog post reverse-engineers exactly how it works, and the mechanism is specific enough to be genuinely instructive.
The trick depends on three cooperating facts. First, BASIC on the Sorcerer always stores the first program line at memory address 469, making the content of any REM on line 10 predictably land at address 474. Second, the USR() function calls whatever address is stored at memory location 259 as a jump target. Third, line 40 executes POKE 260,218 and POKE 261,1, which writes the 16-bit little-endian address 256+218=474 into that jump vector. The result: USR(0) executes the raw bytes stuffed into the REM string as machine code, reads a hardware value for entropy, and seeds the random number generator on line 80.
The full post works through the actual byte content of that REM string and what the machine language routine does once called. If you write embedded systems, care about memory layout, or wonder how 1980s programmers squeezed real functionality out of a constrained interpreter, the original is worth reading in full.
[READ ORIGINAL →]