3 ms·
At least a few models of Linksys/Cisco home routers I own had their firmware "encrypted" using GnuPG. They had the extension .gpg.img but could simply be decryp
by notaplumber 6y ago
At least a few models of Linksys/Cisco home routers I own had their firmware "encrypted" using GnuPG. They had the extension .gpg.img but could simply be decrypted with:
$ gpg --output decrypted.img --decrypt <model><ver>.gpg.img
binwalk can handle the rest.
It looks like they mainly did this for verification, as there is an RSA public key embedded on the device. It unfortunately does make it nearly impossible to flash any modified firmware such as OpenWRT, which is very frustrating. I say nearly as I haven't fully investigated the models that I own. Some routers have a emergency recovery flash method that may bypass the PGP check, I recall older D-Link models having a web flasher integrated into u-boot.
- xfer 6y agoEmbedded where? If it is on a writable flash then you can probably rewrite with your own public key?
- 0xricksanchez 6y agoThey make use of /etc_ro/public.pem to verify the integrity of a firmware update. So flashing a custom firmware (e.g.: OpenWRT) will fail all checks they put in place. I did not investigate how one could circumvent the update mechanism yet but if you're interested in doing so for these particular models my GitHub repo (https://github.com/0xricksanchez/dlink-decrypt https://github.com/0xricksanchez/dlink-decrypt) has a decryption script for these firmware images so you can snoop around the file system for further clues.
- notaplumber 6y agoI think they were replying to me about the Linksys/Cisco routers, but it is similar in that the public key is contained on the filesystem and prevents flashing any firmware not signed with it. What's worse is they added this after the fact to several models in later firmware versions, making it impossible to downgrade to older unsigned versions. Unlike with yours, no decryption script is required, gnupg can decrypt them as-is.
- notaplumber 6y agoSorry, poor choice of words I guess. I mean it's embedded within the filesystem. If you had root or serial access to the device, then you could probably very easily replace it, but at that point you could also just write the firmware anyway. The checks are only important for flashing via the Web UI.