1. Acquiring Raw SPI Flash Dumps
Physical security assessments often begin by desoldering or clipping an 8-pin SOIC SPI Flash chip using a Pomona clip connected to a CH341A programmer or Raspberry Pi.
Using flashrom, we read the chip memory twice to verify MD5 checksum integrity, ensuring the binary dump is 100% clean and non-corrupted.
# Read SPI flash memory
flashrom -p ch341a_spi -r firmware_dump_1.bin
flashrom -p ch341a_spi -r firmware_dump_2.bin
# Verify image match
md5sum firmware_dump_1.bin firmware_dump_2.bin2. Filesystem Carving with Binwalk
With raw firmware in hand, we run binwalk to identify bootloader headers (U-Boot), Linux kernel footprints, and compressed filesystem offsets (SquashFS, cramfs, or JFFS2).
# Recursively extract compressed filesystems
binwalk -Me firmware_dump_1.bin
# Inspect extracted rootfs
cd _firmware_dump_1.bin.extracted/squashfs-root
ls -la etc/ usr/ sbin/3. Hunting /etc/shadow and Hardcoded Credentials
Surprisingly, many commercial connected devices still ship with shared root passwords across every unit in the field. Once the filesystem is unpacked, we inspect etc/shadow and etc/passwd.
4. Decompiling Embedded Daemon Binaries
We import custom web management binaries (such as mini_httpd or custom IoT daemons) into Ghidra to hunt for buffer overflows, command injection in system() calls, and hidden debug endpoints.
- Implement cryptographic hardware root-of-trust with verified Secure Boot.
- Encrypt root filesystems and store decryption keys inside a hardware crypto module.
- Disable all production UART shells and debug interfaces before fabrication.
- Enforce per-device unique factory passwords generated from hardware serials.
