188
A. Francillon et al.
mechanisms, which are often arbitrary and microcontroller specific. Such protection
mechanisms can sometimes be bypassed due to vulnerabilities in the implementation of the protections themselves [447, 556]. However, such attacks may not always
succeed, and one may be left with using more costly invasive hardware attacks
such as Linear Code Extraction (LCE) [549] or direct memory readout using a
microscope [158] as the only option available.
11.2.3 Unpacking Firmware
The next step towards the analysis of a firmware package is to unpack and extract
the files or resources it contains. The output of this phase largely depends on the
type of firmware, as well as the unpacking and extraction tools employed. In some
examples, executable code and resources (such as graphics files or HTML code)
might be embedded directly into a binary blob that is designed to be directly copied
into memory by a bootloader and then executed. Some other firmware packages
are distributed in a compressed and obfuscated package which contains a blockby-block image copy of the Flash memory. Such an image may consist of several
partitions containing a bootloader, a kernel, a file system, or any combination of
these.
11.2.4 Firmware Unpacking Frameworks
The main tools to unpack arbitrary firmware packages are: binwalk [263],
FRAK [161], Binary Analysis Toolkit (BAT) [558] and Firmware.RE [155]
(Table 11.1 compares the performance of each framework):
• Binwalk is perhaps the best known and most used firmware unpacking tool
developed by Craig Heffner [263]. It uses pattern matching to locate and carve
files from a binary blob. Additionally, it also extracts some meta-data such as
license strings.
• FRAK is an unpacking toolkit first presented by Cui et al. [162]. It reportedly 1
supports a limited number of device vendors and models, such as HP printers
and Multi-Function Peripherals (MFP).
• The Binary Analysis Toolkit (BAT), formerly known as GPLtool, was originally
designed by Armijn Hemel and Tjaldur software in order to detect GPL license
violations [269, 558]. To do so, it recursively extracts files from a binary blob
and matches strings with a database of known strings from GPL projects and
licenses. BAT also supports file carving similar to binwalk, as well as a very
flexible plugin-oriented extension interface.
1 Even though the authors mention that the tool would be made publicly available, it has yet to be
released.
Précédent

- 195/268

Suivant