Reverse Engineering & Binary Analysis Basics · درس

استخراج أنظمة الملفات من البرامج الثابتة وتحليلها

استخرج أنظمة الملفات المضمّنة المخفية داخل صور البرامج الثابتة وحدّدها وثبّتها، لاستعادة الملفات الثنائية والإعدادات والمفاتيح التي تحتوي عليها.

الدرس 4 من 413 خطوة

استخراج أنظمة الملفات من البرامج الثابتة وتحليلها درس مجاني في Reverse Engineering & Binary Analysis Basics على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في Reverse Engineering & Binary Analysis Basics، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.

Inside the Firmware Blob

You can analyze firmware images, emulate embedded binaries, and use hardware-assisted debugging. Most firmware is more than code: it embeds entire filesystems holding executables, web pages, and secrets.

Extracting them is often where the real findings live.

Firmware Layout

A typical image is a stack of regions:

  • Bootloader
  • Kernel
  • One or more root filesystems
  • Configuration / NVRAM areas

Each region may use a different format and compression.

Identifying Contents with binwalk

binwalk scans for known magic signatures and reports what is inside and where.

binwalk firmware.bin
# 0x40   uImage header
# 0x1A00 Squashfs filesystem, gzip

Carving Out Sections

Once you know offsets, you can extract a region. binwalk can do this automatically, or you can carve with dd.

binwalk -e firmware.bin
# or carve manually:
dd if=firmware.bin of=rootfs.sqsh bs=1 skip=6656

Common Embedded Filesystems

Embedded devices favor compact, sometimes read-only filesystems:

  • SquashFS (compressed, read-only)
  • JFFS2 / UBIFS (flash-aware)
  • CramFS (older, read-only)

Each needs the matching tool to unpack.

Unpacking SquashFS

SquashFS is the most common. Extract it with unsquashfs to get a normal directory tree.

unsquashfs rootfs.sqsh
# creates ./squashfs-root with /bin /etc /www ...

What to Look For

Inside the root filesystem, hunt for high-value files:

  • /etc/passwd and hardcoded credentials
  • Web admin scripts in /www
  • TLS keys and certificates
  • Startup scripts revealing services
grep -rIn 'password' squashfs-root/etc 2>/dev/null

Finding Hardcoded Secrets

Vendors frequently embed backdoor accounts or API keys. Scan strings across the whole tree and inspect config files.

These secrets are the most common firmware vulnerability you will report.

Connecting to Your Other Skills

Extracted binaries feed back into your earlier work: emulate a recovered service binary, or attach hardware-assisted debugging to a running device executing that same code.

Filesystem extraction unlocks the targets for those techniques.

When Extraction Fails

If binwalk finds nothing, the image may be encrypted or use a proprietary container.

  • Check entropy: uniformly high suggests encryption
  • Look for the bootloader's decryption routine
  • Try vendor update tools or known keys

Repacking After Modification

For dynamic testing you sometimes patch a filesystem and put it back. Repack with the matching tool and fix the firmware header checksum, or the device rejects the image.

Always work on copies and keep the pristine original for reference.

mksquashfs squashfs-root rootfs_new.sqsh -comp gzip

Quick Check

Which tool is commonly used to scan a firmware image for embedded filesystems and other known structures by their signatures?

Recap

You can now mine firmware for its real contents:

  • Map the layout, then identify regions with binwalk
  • Carve sections and unpack SquashFS/JFFS2/UBIFS
  • Hunt for credentials, keys, and admin scripts
  • Feed recovered binaries into emulation and debugging
البدء مجانًا

تعلم Assembly مع معلم ذكاء اصطناعي — مجانًا

اكتب وقم بتشغيل أكوادك الفعلية في المتصفح، واحصل على مساعدة فورية من معلم ذكاء اصطناعي متاح 24/7، واستمر من حيث توقفت على الويب أو في التطبيق.

الدورات
12
الدروس
48

الأسئلة الشائعة

هل درس «استخراج أنظمة الملفات من البرامج الثابتة وتحليلها» مجاني؟

نعم — نص درس «استخراج أنظمة الملفات من البرامج الثابتة وتحليلها» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة Reverse Engineering & Binary Analysis Basics، انتقل إلى CoddyKit PRO. تتضمن دورة Reverse Engineering & Binary Analysis Basics 4 دروس في المجموع.

ماذا ستتعلم في «استخراج أنظمة الملفات من البرامج الثابتة وتحليلها»؟

استخرج أنظمة الملفات المضمّنة المخفية داخل صور البرامج الثابتة وحدّدها وثبّتها، لاستعادة الملفات الثنائية والإعدادات والمفاتيح التي تحتوي عليها. تتمرن على Reverse Engineering & Binary Analysis Basics مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.

هل أحتاج إلى خبرة سابقة لأبدأ Reverse Engineering & Binary Analysis Basics؟

لا تُشترط خبرة سابقة. Reverse Engineering & Binary Analysis Basics على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.

كم من الوقت يستغرق درس «استخراج أنظمة الملفات من البرامج الثابتة وتحليلها»؟

معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.

هل يمكنني كتابة وتشغيل أكواد في درس Reverse Engineering & Binary Analysis Basics هذا؟

نعم. كل درس في Reverse Engineering & Binary Analysis Basics يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.

جميع الدروس في هذه الدورة

  1. تحليل صور البرامج الثابتة
  2. محاكاة الملفات الثنائية المضمّنة
  3. تصحيح الأخطاء بمساعدة العتاد
  4. استخراج أنظمة الملفات من البرامج الثابتة وتحليلها
← العودة إلى Reverse Engineering & Binary Analysis Basics