Skip to content

Inspecting SquashFS

Squashfs is a compressed, read-only filesystem commonly used in embedded Linux systems due to its efficiency in size and performance. Mounting a Squashfs image allows analysts to inspect its directory structure, extract files, and analyze the contents of firmware or root filesystems. This section covers techniques for mounting Squashfs images and inspecting their contents using standard Linux tools.


Mounting Squashfs Images

To mount a Squashfs image, you need the squashfs-tools package, which provides the mount utility and kernel module. First, ensure the module is loaded:

sudo modprobe squashfs

If the module is not already loaded, check with lsmod and load it manually if necessary. Once the module is available, mount the image to a temporary directory:

sudo mount -t squashfs image.squashfs /mnt/squashfs

Replace image.squashfs with the path to your Squashfs file. The mount point (/mnt/squashfs) must exist; create it if needed:

sudo mkdir -p /mnt/squashfs

To verify the mount, use:

df -h

or check the mount point directly:

ls /mnt/squashfs

Inspecting Squashfs Contents

After mounting, use standard Linux tools to explore the filesystem:

ls /mnt/squashfs
find /mnt/squashfs -name "important_file"

For deeper analysis, extract individual files or directories using unsquashfs (part of squashfs-tools):

unsquashfs image.squashfs

This extracts the contents to a directory named squashfs-root. You can then analyze files directly without mounting.


Alternative: Analyzing Without Mounting

If mounting is not feasible (e.g., due to kernel restrictions), use unsquashfs to extract the entire filesystem:

unsquashfs image.squashfs -d /path/to/extract

This method is useful for static analysis of files without requiring a live mount.


Key takeaways

  • Use mount -t squashfs to mount Squashfs images, ensuring the kernel module is loaded.
  • unsquashfs provides an alternative for extracting and analyzing contents without mounting.
  • Inspect mounted filesystems with ls, find, and file-specific tools like file or strings.
  • Always verify mount points and permissions when working with firmware or embedded systems.