Skip to content

Extracting SquashFS

Squashfs is a widely used compressed, read-only filesystem in IoT and embedded systems, often embedded within firmware images. Analyzing Squashfs is critical for uncovering hidden data, identifying vulnerabilities, and understanding the attack surface of embedded devices. Due to its compressed nature, extraction and inspection require specialized tools and techniques to reveal its contents and assess security risks.


Extraction Techniques

1. Extracting Standalone Squashfs Images

If the Squashfs image is standalone (e.g., a .squashfs file), use unsquashfs to extract its contents:

unsquashfs image.squashfs
This will create a directory containing the filesystem's files. For larger images, use the -d flag to specify an output directory:
unsquashfs -d extracted_root image.squashfs

2. Extracting from Firmware Binaries

Many IoT firmware images embed Squashfs within a larger binary. Use binwalk to locate and extract the Squashfs partition:

binwalk -e firmware.bin
This will identify the Squashfs offset and extract it as a separate file (e.g., firmware.bin.extracted.squashfs).

3. Handling Encrypted Squashfs

If the filesystem is encrypted, tools like fsarchiver or custom scripts may be required. For example, use fsarchiver to extract encrypted Squashfs:

fsarchiver extract archive.fsar extracted_dir
If encryption details are unknown, brute-force or dictionary attacks may be necessary, depending on the key derivation function used.


Analysis Techniques

1. Mounting and Inspecting Files

Mount the extracted Squashfs to inspect its structure:

sudo mount -t squashfs extracted_root.squashfs /mnt
Use find or ls to explore files:
find /mnt -name "suspicious_file"

2. Searching for Hidden Data

Use strings to scan for embedded text or secrets:

strings /mnt/bin/some_binary | grep -i "secret|key|token"
Look for hidden directories or files using find with specific patterns:
find /mnt -type d -name ".hidden"

3. Identifying Vulnerabilities

  • Binary Analysis: Use readelf or objdump to inspect binaries for vulnerabilities (e.g., stack canaries, NX bits):
    readelf -h /mnt/bin/some_binary
    
  • Permissions Check: Verify insecure file permissions:
    find /mnt -perm -2 -type f -exec ls -l {} \;
    

Advanced Analysis

1. Detecting Encrypted Data

Use binwalk to scan for encrypted data within the Squashfs:

binwalk -e image.squashfs
Look for patterns indicative of encryption (e.g., repeated byte sequences).

2. Checking for Hidden Partitions

Some firmware images include multiple Squashfs partitions. Use binwalk to identify and extract all:

binwalk -e firmware.bin --show-all

3. Reverse-Engineering Custom Compression

If the Squashfs uses a non-standard compression algorithm, use squashfs-tools to inspect metadata:

squashfs-tools -i image.squashfs


Key takeaways

  • Extraction: Use unsquashfs for standalone images and binwalk to locate embedded Squashfs in firmware.
  • Analysis: Combine file inspection, string scanning, and binary analysis to uncover hidden data and vulnerabilities.
  • Advanced Techniques: Leverage binwalk and custom scripts to detect encrypted data or hidden partitions.