BSWJ: binwalk

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

4 minutes
Video Transcription
Hello. Welcome back to breaking stuff, Joe. Here on Cyberia, on demand. Today we're gonna be talking about the tool been Walk the walk is a great forensic utility for examining firmware images and extracting executed bols images, file types, different file types, just anything you might be able to pull from a firmware image
this is capable of doing.
It's a really simple tool to use very, very effective. And it's a great way to do that. Sort of first past scan of any target of forensic activity if you have a firm where image. So we're gonna see how easy it is to you. We're gonna see how useful it is, and we're gonna actually show in use here on breaking stuff with Joe.
As usual, here we are back in our Callie BM. Now you may note that this text on the screen is a little bit smaller than usual, little bit tougher to read. There's a good reason for that you'll see in just a second. So, as I said before in the intro, we're looking at the tool called Been Walk today,
and it's a quick look because it's a pretty easy tool to use at its most basic level. All been walk is really doing is searching through
a given binary image. Generally speaking firm where images or what you're looking for, Andi, it's just
100 for any file signatures, any images, any files that it confined.
Insight of that firm where?
So we're gonna go ahead. We're going to just do a quick example
to see how you could use this tool. Now, I downloaded a firm or file off of the Intel website pretty much at random,
and we're gonna go ahead. We're just gonna run against that.
So first, just to get a look at all the different options you have within walk because it is a pretty hefty tool, you can see that it will attempt to extract known file types. If you give it that opportunity, it will attempt to calculate file entropy. You can find all sorts of different signatures, which is what we're going to be looking for in this case. So we're gonna be using this tack. Be option here in just a second.
To find common file signatures,
you have to have disassembly scan options, binary differential options. This is a very robust tool that can perform very in depth forensic analysis on this binary that we have access to. In this case, we're really just want to take a quick look and see what we can pull out at an initial scan and see what information we can gather with. Basically no work.
We're gonna go ahead and Ben walk
Capital Beak, and then we'll just auto complete with this file that again. This is just a firmware image that I pulled down from in tow,
and you can see this is why we didn't zoom in. So if you zoom in the the, uh, yeah, it becomes very, very difficult to read.
So here you can see we've got a few different pieces of information. We have
the decimal location, the hex decimal, and we have a description of what was found there. So this is again just looking for common final signatures, and as soon as it finds one, it reports the location both and desolate Hexi decimal. And then it gives you a description. So it's got an A R G archive data. So these air archives
you could see most of the files I found were archives, with some exceptions,
we have to copyright strings here. Get both saying copyright from Intel
on. Do you concede that we've got sort of an initial look at all the different
pieces of file information already in here. You can see over here we've got the original names of these different files that have been turned into archives. You can see that the OS is for M ISS tosses for a window system, the compressed file size versions. You can do some depth, some digging into these air J's
And of course, because we know where they are. And we know that Ben Walk is able to identify them very easily. We could extract those actual archives and start digging through them
Now. I would be the subject of a much more focused and, of course, much longer course. But that's a sort of work that you could start doing and start playing around with this tool on your own time. And then, you know, in some of the labs that we have available here on Cyber Eri, so that's all there is for this tool. Been walk again. It is a tool for forensic examination
of firmware images or really any binary but most specifically in most generally
firmware images. Thank you all for watching. This has been breaking stuff with Joe on Cyber Eri on.