Skip to content

Firmware analysis

Firmware is the software that makes an embedded device work. Analyzing it reveals embedded credentials, cryptographic keys, hidden services, vulnerabilities, and the device’s logic. It’s a central piece of IoT pentesting (IoT pentest).

- download from the manufacturer's site / update portal
- capture the OTA update (intercept the traffic, see web-api)
- direct dump of the memory chip (SPI flash) via hardware (see ot-hardware)
- extraction from the app itself or the device's filesystem
binwalk firmware.bin # identify and extract filesystems and components
binwalk -e firmware.bin # extract (squashfs, jffs2, cpio, kernel...)
# after extracting the rootfs:
- look for credentials: grep for passwords, /etc/shadow, keys in /etc, certificates
- private keys, API tokens, backend URLs (hardcoded)
- binaries with known vulns (versions of busybox, dropbear, openssl...)
- boot scripts, services, default accounts
Extraction binwalk, firmware-mod-kit, unblob, sasquatch (squashfs)
Automated EMBA (full Linux firmware analysis), FACT
Analysis strings, grep, Ghidra (ARM/MIPS binaries, see pwn-reversing)
Emulation QEMU + firmadyne/FirmAE to run the firmware and attack its web/services
- emulate the firmware (QEMU + FirmAE/firmadyne) -> bring up its web interface/services
- attack the emulated web/API like a normal app (see web-*) without risking the device
- useful for fuzzing and dynamic analysis without depending on physical hardware
- HARDCODED credentials/keys (access to all devices of the model)
- signing private keys -> allow signing malicious firmware if reused
- backdoors/hidden accounts, active debug services
- weak crypto (see crypto-*), predictable RNG, secrets reused across devices
  • Don’t embed credentials/keys; per-device secrets in secure storage.
  • Sign the firmware and verify it at boot (secure boot); encrypt where appropriate.
  • Keep components updated (busybox/openssl/dropbear) and manage end of life.
  • Disable debug services and factory accounts in production.
  • Routers/cameras with shared private keys across all devices (one leak compromises the whole fleet).
  • Backdoors in firmware (hidden accounts) found by extraction and grep.
  • Campaigns exploiting unsigned firmware for persistence that’s hard to eradicate.
  • Obtain the firmware (web/OTA/chip/app)
  • Extract with binwalk/unblob and mount the rootfs
  • Look for hardcoded credentials/keys/tokens
  • Review component versions (known vulns)
  • Detect backdoors/hidden accounts/debug services
  • Emulate (FirmAE/QEMU) to attack web/services
  • Analyze key binaries in Ghidra if needed (pwn-reversing)