Closed WereCatf closed 6 years ago
Sasquatch works on other big endian squashfs file systems, so it would seem unlikely that it is treating some/all of the fields incorrectly. I think it's more likely that this file system has had some custom modifications made to it.
What leads me to this conclusion is that the squashfs header claims that it is big endian and v4.0. These do not exist, as SquashFS v4.0 moved to a fixed little-endian format (even for big-endian systems). So either the header is wrong, or someone has made some customizations to the SquashFS 4.0 standard.
Well, I don't dispute any of that, I know nothing about Squashfs's internals. I only know the image contains a working filesystem because it comes from a live system.
Binwalk says the following:
Alas, sasquatch fails at extracting the files:
I know the filesystem is not corrupt, so I can only hazard a guess that sasquatch gets the endianness wrong on one or another value.