Extracting SquashFS
Squashfs is a widely used compressed, read-only filesystem in IoT and embedded systems, often embedded within firmware images. Analyzing Squashfs is critical for uncovering hidden data, identifying vulnerabilities, and understanding the attack surface of embedded devices. Due to its compressed nature, extraction and inspection require specialized tools and techniques to reveal its contents and assess security risks.
Extraction Techniques¶
1. Extracting Standalone Squashfs Images¶
If the Squashfs image is standalone (e.g., a .squashfs file), use unsquashfs to extract its contents:
-d flag to specify an output directory:
2. Extracting from Firmware Binaries¶
Many IoT firmware images embed Squashfs within a larger binary. Use binwalk to locate and extract the Squashfs partition:
firmware.bin.extracted.squashfs).
3. Handling Encrypted Squashfs¶
If the filesystem is encrypted, tools like fsarchiver or custom scripts may be required. For example, use fsarchiver to extract encrypted Squashfs:
Analysis Techniques¶
1. Mounting and Inspecting Files¶
Mount the extracted Squashfs to inspect its structure:
Usefind or ls to explore files:
2. Searching for Hidden Data¶
Use strings to scan for embedded text or secrets:
find with specific patterns:
3. Identifying Vulnerabilities¶
- Binary Analysis: Use
readelforobjdumpto inspect binaries for vulnerabilities (e.g., stack canaries, NX bits): - Permissions Check: Verify insecure file permissions:
Advanced Analysis¶
1. Detecting Encrypted Data¶
Use binwalk to scan for encrypted data within the Squashfs:
2. Checking for Hidden Partitions¶
Some firmware images include multiple Squashfs partitions. Use binwalk to identify and extract all:
3. Reverse-Engineering Custom Compression¶
If the Squashfs uses a non-standard compression algorithm, use squashfs-tools to inspect metadata:
Key takeaways¶
- Extraction: Use
unsquashfsfor standalone images andbinwalkto locate embedded Squashfs in firmware. - Analysis: Combine file inspection, string scanning, and binary analysis to uncover hidden data and vulnerabilities.
- Advanced Techniques: Leverage
binwalkand custom scripts to detect encrypted data or hidden partitions.