Skip to content

Hardcoded Credentials

Firmware often contains hardcoded credentials that can compromise IoT devices if left unaddressed. These credentials may appear in plaintext, encoded formats (e.g., base64), or obfuscated strings. Detecting them requires a combination of static and dynamic analysis techniques, along with pattern recognition and tooling. Below are methods to systematically search for hardcoded credentials in firmware binaries and extracted files.


Static Analysis of Binaries

Objective: Identify hardcoded credentials in compiled binaries (e.g., ELF files, binaries extracted from firmware images).

  1. String Extraction
    Use tools like strings or binwalk to extract human-readable strings from binaries.

    strings firmware.bin | grep -E 'admin|password|token|secret'
    
    This searches for common credential keywords. For base64-encoded credentials:
    grep -Eo '([A-Za-z0-9+/]{8,})' firmware.bin | base64 --decode | grep -E 'password|key'
    

  2. Reverse Engineering
    Use disassemblers like IDA Pro, Ghidra, or Binary Ninja to inspect memory regions for hardcoded strings. Look for:

  3. Strings in .rodata or .data sections.
  4. Network packets (e.g., HTTP headers, MQTT topics) containing credentials.
  5. Configuration files (e.g., config.json, credentials.txt) embedded in the binary.

  6. ELF File Inspection
    For Linux-based firmware, use objdump or readelf to inspect ELF binaries:

    readelf -s firmware.elf | grep -E 'config|cred|key'
    
    Check for symbols or sections that might store credentials.


Static Analysis of Extracted Files

Objective: Search for credentials in extracted firmware files (e.g., filesystem images, configuration files).

  1. Filesystem Extraction
    Use binwalk to extract files from firmware images:

    binwalk -e firmware.bin
    
    Inspect extracted directories for files like user.conf, secrets.txt, or default_passwords.

  2. Pattern Matching
    Use grep or find to search for credential patterns:

    find extracted_files -type f -exec grep -l 'admin:' {} \;
    
    Look for base64 strings or hex-encoded values:
    grep -Eo '([A-Za-z0-9+/]{8,})' extracted_files/* | base64 --decode | grep -E 'password|token'
    

  3. Yocto/Linux-Specific Checks
    For Yocto-based systems, check /etc/ or /usr/share/ directories for config files. Use find to locate suspicious files:

    find /path/to/rootfs -name "*.cfg" -o -name "*.conf" -exec grep -l 'password' {} \;
    


Dynamic Analysis

Objective: Monitor runtime behavior to detect credential usage.

  1. Network Traffic Capture
    Use Wireshark or tcpdump to capture network traffic and filter for credentials:

    tcpdump -i lo -s 0 -w capture.pcap
    
    Analyze HTTP Basic Auth headers or MQTT payloads in Wireshark.

  2. Runtime Memory Inspection
    Run firmware in a controlled environment (e.g., QEMU) and use gdb to inspect memory:

    gdb -ex "set pagination off" -ex "disassemble main" -ex "break main" -ex "run" firmware.elf
    
    Check for strings in memory or environment variables.


Advanced Techniques

  • Decryption/Obfuscation: If credentials are encrypted, use tools like Binary Ninja or Ghidra to reverse-engineer decryption routines.
  • Source Code Analysis: For open-source firmware, search source files for patterns:
    grep -r '^[A-Za-z0-9]{8,}$' /path/to/source
    
  • Automated Tools: Use Binwalk, Firmware Mod Kit (Firmware-MK), or Firmware Analysis Toolkit (FAT) for automated credential detection.

Key takeaways

  • Hardcoded credentials often appear in plaintext, base64, or obfuscated formats.
  • Combine static analysis (string extraction, disassembly) with dynamic monitoring (network captures, runtime inspection).
  • Use tools like binwalk, strings, and grep to automate pattern matching in firmware files.
  • Prioritize checking configuration files, network traffic, and memory regions for sensitive data.
  • For open-source firmware, source code audits are critical for identifying hardcoded secrets.