Firmware analysis
Firmware is the software that makes an embedded device work. Analyzing it reveals embedded credentials, cryptographic keys, hidden services, vulnerabilities, and the device’s logic. It’s a central piece of IoT pentesting (IoT pentest).
Obtaining the firmware
Section titled “Obtaining the firmware”- download from the manufacturer's site / update portal- capture the OTA update (intercept the traffic, see web-api)- direct dump of the memory chip (SPI flash) via hardware (see ot-hardware)- extraction from the app itself or the device's filesystemStatic analysis of the firmware binary
Section titled “Static analysis of the firmware binary”binwalk firmware.bin # identify and extract filesystems and componentsbinwalk -e firmware.bin # extract (squashfs, jffs2, cpio, kernel...)# after extracting the rootfs:- look for credentials: grep for passwords, /etc/shadow, keys in /etc, certificates- private keys, API tokens, backend URLs (hardcoded)- binaries with known vulns (versions of busybox, dropbear, openssl...)- boot scripts, services, default accountsExtraction binwalk, firmware-mod-kit, unblob, sasquatch (squashfs)Automated EMBA (full Linux firmware analysis), FACTAnalysis strings, grep, Ghidra (ARM/MIPS binaries, see pwn-reversing)Emulation QEMU + firmadyne/FirmAE to run the firmware and attack its web/servicesEmulation (run without the hardware)
Section titled “Emulation (run without the hardware)”- emulate the firmware (QEMU + FirmAE/firmadyne) -> bring up its web interface/services- attack the emulated web/API like a normal app (see web-*) without risking the device- useful for fuzzing and dynamic analysis without depending on physical hardwareWhat to look for (high-value findings)
Section titled “What to look for (high-value findings)”- HARDCODED credentials/keys (access to all devices of the model)- signing private keys -> allow signing malicious firmware if reused- backdoors/hidden accounts, active debug services- weak crypto (see crypto-*), predictable RNG, secrets reused across devicesBlue Team / manufacturer
Section titled “Blue Team / manufacturer”- Don’t embed credentials/keys; per-device secrets in secure storage.
- Sign the firmware and verify it at boot (secure boot); encrypt where appropriate.
- Keep components updated (busybox/openssl/dropbear) and manage end of life.
- Disable debug services and factory accounts in production.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Routers/cameras with shared private keys across all devices (one leak compromises the whole fleet).
- Backdoors in firmware (hidden accounts) found by extraction and grep.
- Campaigns exploiting unsigned firmware for persistence that’s hard to eradicate.
Testing checklist
Section titled “Testing checklist”- Obtain the firmware (web/OTA/chip/app)
- Extract with binwalk/unblob and mount the rootfs
- Look for hardcoded credentials/keys/tokens
- Review component versions (known vulns)
- Detect backdoors/hidden accounts/debug services
- Emulate (FirmAE/QEMU) to attack web/services
- Analyze key binaries in Ghidra if needed (pwn-reversing)