Skip to content
All modules
AdvancedModule 23 of 27120 minutes

Firmware, hardware and signals

Find the filesystem inside a firmware blob, read a debug interface off a board, and decode a captured signal back into bytes.

Assumes21. Reverse engineering

By the end you can

  • Locate and extract an embedded filesystem from a firmware image by signature and entropy
  • Identify the architecture and endianness of an embedded binary before disassembling it
  • Read a UART, SPI or I2C capture from a logic analyser back into framed bytes
  • Recognise what a JTAG or SWD interface offers, and why a challenge hands you one
  • Decode a captured RF or infrared transmission into its underlying symbols
  • Find hardcoded credentials and keys in an image, and explain why they cannot simply be rotated

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 16 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Extracting a firmware image and stopping at the first filesystem. Images routinely carry several, plus a bootloader and a kernel, and the interesting one is rarely first.
  • Disassembling embedded code as x86 because the tool defaulted to it. ARM, MIPS and RISC-V all appear, and the entropy plot will not tell you which.
  • Reading a logic capture as data before setting the framing. Baud rate, bit order and idle level decide what the bytes are, and all three are guesses until confirmed.
  • Accepting whatever the unpacker extracted. It reports what it recognised, and the gap between the image size and the extracted bytes is an encrypted or unknown partition that nothing warned you about.
  • Writing up a hardcoded key as 'rotate the credential'. It is present in every device already shipped, so the honest remediation is a firmware update and a key that is not the same everywhere.

Checkpoint

From a firmware image, extract the root filesystem, find the credential or key it ships with, and state the offset and format of the container it came from.

Teaching note

Hardware challenges look inaccessible without hardware, which is untrue and worth saying in the first minute: the capture, the blob and the dump are the challenge, and they are all files. Start from a supplied capture, not from a board.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.