11 Finding Software Bugs in Embedded Devices
189
Table 11.1 Comparison of the unpacking performance of Binwalk, BAT, FRAK and
Firmware.RE on a few example firmware packages (according to [155])
Device
Vendor
OS
Binwalk
BAT
FRAK
Firmware.RE
PC
Intel
BIOS
✗
✗
✗
✗
Camera
STL
Linux
✗
✓
✗
✓
Router
Bintec
–
✗
✗
✗
✗
ADSL gateway
Zyxel
ZynOS
✓
✓
✗
✓
PLC
Siemens
–
✓
✓
✗
✓
DSLAM
–
–
✓
✓
✗
✓
PC
Intel
BIOS
✓
✓
✗
✓
ISDN server
Planet
–
✓
✓
✗
✓
Voip
Asotel
Vxworks
✓
✓
✗
✓
Modem
–
–
✗
✗
✗
✓
Home automation
Belkin
Linux
✗
✗
✗
✓
55%
64%
0%
82%
• Firmware.RE [155] extends BAT with additional unpacking methods and specific
analyses to perform automated large-scale analyses. When released, it achieved
a lower false positive rate when unpacking firmware compared to binwalk.
11.2.5 Modifying and Repacking Firmware
Modifying and repacking a firmware could be one optional step during the analysis
of the firmware and device security. The modifications could be performed either
at the level of the entire firmware package, or at the level of individually unpacked
files (that are finally repacked back into a firmware package). Such a step could be
useful in testing several things. First, it can check whether a particular firmware has
error, modification and authenticity checks for new versions of firmware. If such
checks are missing or improperly implemented, the firmware update mechanism
can then be used as an attack vector, or as a way to perform further analysis
of the system [57, 162]. Second, it can be used to augment the firmware with
additional security-related functionality, such as exploits, benign malware and more
advanced analysis tools. For example, this could be useful when there are no
other ways to deliver an exploit (e.g., non-network local exploits such as kernel
privilege escalation), or provide some (partial) form of introspection into the running
device/firmware [163].
The firmware-mod-kit tool [262] is perhaps the most well-known (and possibly among the very few) firmware modification tools. Unfortunately, it supports a
limited number of firmware formats, and while it can be extended to support more
formats, to do so requires substantial manual effort. Further, for some formats it
relies on external tools to perform some of the repacking. These tools are developed
189
Table 11.1 Comparison of the unpacking performance of Binwalk, BAT, FRAK and
Firmware.RE on a few example firmware packages (according to [155])
Device
Vendor
OS
Binwalk
BAT
FRAK
Firmware.RE
PC
Intel
BIOS
✗
✗
✗
✗
Camera
STL
Linux
✗
✓
✗
✓
Router
Bintec
–
✗
✗
✗
✗
ADSL gateway
Zyxel
ZynOS
✓
✓
✗
✓
PLC
Siemens
–
✓
✓
✗
✓
DSLAM
–
–
✓
✓
✗
✓
PC
Intel
BIOS
✓
✓
✗
✓
ISDN server
Planet
–
✓
✓
✗
✓
Voip
Asotel
Vxworks
✓
✓
✗
✓
Modem
–
–
✗
✗
✗
✓
Home automation
Belkin
Linux
✗
✗
✗
✓
55%
64%
0%
82%
• Firmware.RE [155] extends BAT with additional unpacking methods and specific
analyses to perform automated large-scale analyses. When released, it achieved
a lower false positive rate when unpacking firmware compared to binwalk.
11.2.5 Modifying and Repacking Firmware
Modifying and repacking a firmware could be one optional step during the analysis
of the firmware and device security. The modifications could be performed either
at the level of the entire firmware package, or at the level of individually unpacked
files (that are finally repacked back into a firmware package). Such a step could be
useful in testing several things. First, it can check whether a particular firmware has
error, modification and authenticity checks for new versions of firmware. If such
checks are missing or improperly implemented, the firmware update mechanism
can then be used as an attack vector, or as a way to perform further analysis
of the system [57, 162]. Second, it can be used to augment the firmware with
additional security-related functionality, such as exploits, benign malware and more
advanced analysis tools. For example, this could be useful when there are no
other ways to deliver an exploit (e.g., non-network local exploits such as kernel
privilege escalation), or provide some (partial) form of introspection into the running
device/firmware [163].
The firmware-mod-kit tool [262] is perhaps the most well-known (and possibly among the very few) firmware modification tools. Unfortunately, it supports a
limited number of firmware formats, and while it can be extended to support more
formats, to do so requires substantial manual effort. Further, for some formats it
relies on external tools to perform some of the repacking. These tools are developed
