All Research/IoT Security
IoT SecurityAug 20, 20267 min read

Extracting IoT Firmware with Binwalk & Auditing Hardcoded Shadow Hashes

From raw Flash binary dumps to root filesystem exploitation.

“Learn how hardware hackers dump SPI Flash chips, unpack SquashFS and JFFS2 filesystems with Binwalk, and crack legacy DES/MD5 shadow hashes found on commercial smart devices.”

1. Acquiring Raw SPI Flash Dumps

Physical security assessments often begin by desoldering or clipping an 8-pin SOIC SPI Flash chip using a Pomona clip connected to a CH341A programmer or Raspberry Pi.

Using flashrom, we read the chip memory twice to verify MD5 checksum integrity, ensuring the binary dump is 100% clean and non-corrupted.

terminal
bash
# Read SPI flash memory
flashrom -p ch341a_spi -r firmware_dump_1.bin
flashrom -p ch341a_spi -r firmware_dump_2.bin

# Verify image match
md5sum firmware_dump_1.bin firmware_dump_2.bin

2. Filesystem Carving with Binwalk

With raw firmware in hand, we run binwalk to identify bootloader headers (U-Boot), Linux kernel footprints, and compressed filesystem offsets (SquashFS, cramfs, or JFFS2).

terminal
bash
# Recursively extract compressed filesystems
binwalk -Me firmware_dump_1.bin

# Inspect extracted rootfs
cd _firmware_dump_1.bin.extracted/squashfs-root
ls -la etc/ usr/ sbin/

3. Hunting /etc/shadow and Hardcoded Credentials

Surprisingly, many commercial connected devices still ship with shared root passwords across every unit in the field. Once the filesystem is unpacked, we inspect etc/shadow and etc/passwd.

If a shadow hash starts with $1$, it is legacy MD5-based crypt, which can be cracked at billions of hashes per second using Hashcat on a modern GPU.

4. Decompiling Embedded Daemon Binaries

We import custom web management binaries (such as mini_httpd or custom IoT daemons) into Ghidra to hunt for buffer overflows, command injection in system() calls, and hidden debug endpoints.

Key Remediation Checklist:
  • Implement cryptographic hardware root-of-trust with verified Secure Boot.
  • Encrypt root filesystems and store decryption keys inside a hardware crypto module.
  • Disable all production UART shells and debug interfaces before fabrication.
  • Enforce per-device unique factory passwords generated from hardware serials.
KT
Written by
Kshitija & Research Team
OffSec Lead // VAPT & IoT Researcher
// RELATED_INTELLIGENCE

Continue Reading

Android Security8 min read

Deep Dive: Reversing Android Keystore Implementations with Frida

A hands-on walkthrough showing how modern Android applications store sensitive tokens in the Keystore, how hardware-backed TEEs protect them, and how researchers hook Cipher.doFinal() using Frida runtime instrumentation.

By KshitijaRead Analysis
API Security6 min read

Hunting BOLA/IDOR in GraphQL Microservices: A Methodology

Broken Object Level Authorization (BOLA) remains the #1 vulnerability on modern APIs. Here is our step-by-step methodology for mapping authorization graphs and discovering cross-tenant data leaks in GraphQL.

By TechnicalRead Analysis