Reverse Engineering IoT Firmware: SPI Flash Extraction

In security audits of embedded systems, retrieving the firmware is usually the critical first step. When over-the-air updates are encrypted and the debug ports (UART, JTAG) are disabled in production silicon, dumping the physical SPI Flash memory chip becomes necessary.

In this write-up, we extract firmware directly from an 8-pin SOP SPI flash chip using a Bus Pirate. This hardware-level approach bypasses any bootloader lockdowns and extracts the raw partition table directly from the silicon.

extract_firmware.sh Bash
#!/bin/sh
# Query the SPI flash details using flashrom via Bus Pirate
flashrom -p buspirate_spi:dev=/dev/ttyUSB0,spispeed=1M -r firmware_dump.bin

# Verify the integrity of the binary dump by comparing hashes
if [ $? -eq 0 ]; then
  echo "Dump successful. Running md5sum..."
  md5sum firmware_dump.bin
else
  echo "Failed to read flash memory." >&2
  exit 1
fi

After standard verification, we can proceed to unpack the bin file using tools like binwalk. If the partition table contains standard filesystem formats (e.g. SquashFS, jffs2), binwalk extracts it automatically. Otherwise, manual offset carving is required.


Recent Writes & Archive

Dense, terminal-style index of prior posts. Press Tab to focus and navigate rows instantly.

Date Title Tags
Building a High-Availability Traefik Router with Docker Compose [#homelab]
POSIX sh vs. Bash: Portability in Modern Scripts [#shell]
CTF Write-up: Heap Exploitation in glibc 2.35 [#ctf]