LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 28 February 2015 | | Platform | Quiet Systems | | Series | DKSR-M-2015-02 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF Same Maldrone line moves to Full Disclosure and Nullcon. Conference venue does not create a new defect ID. ### Key judgments 1. **[Assessment — High confidence]** Full Disclosure message dated 1 February 2015 (list 3 February 2015). Nullcon Goa 6 February 2015. 2. **[Assessment — High confidence]** Same Parrot AR.Drone ARM Linux case family as January. No CVE. 3. **[Inference — Moderate confidence]** This is venue, not a second vuln. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Sasi: Full Disclosure note and Nullcon talk *Event / publication dates: Full Disclosure 1 February 2015 (IST; list 3 February 2015). Nullcon Goa 6 February 2015, 16:00* | Field | Value | | --- | --- | | Component | software | | Product | Parrot AR.Drone ARM Linux | | CVE / advisory | no CVE | | Patch | none found | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — A1] Full Disclosure https://seclists.org/fulldisclosure/2015/Feb/14 · Openwall https://lists.openwall.net/full-disclosure/2015/02/03/1 · Nullcon schedule https://archive.nullcon.net/website/goa-15/schedule.php** **Exposure.** Same unauthenticated host access as January. Act plus persistence. **Intelligence assessment.** [Assessment — High confidence] February dates. Same case family as 2015-01-A. **Opportunity.** Do not invent a second CVE for the talk. Watch DEF CON 23 Parrot week. **LRRK relevance.** Control Fabric. **Confidence.** High. ## Forward indicators 1. Satterfield / Robinson DEF CON 23 (August 2015). > **Collection integrity.** Same research line as January. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>