← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/years/2016.md
Imported-content SHA-256
9b0a71c02cdd45a6bd3f15c6943f58b6232801ca4d6561477a77b040cb929e94
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 7 August 2016 |
| Platform | Quiet Systems |
| Series | DC-Y-2016 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

2016 splits: named airframes are now victims (professional Wi-Fi / XBee command injection; DJI Phantom 3 multi-vector hijack of maneuver), while the collector-truck line continues (industrial-wireless delivery; a flying pentest laptop). No CVE or Exploit-DB ID attaches.

### Key judgments

1. **[Assessment — High confidence]** Luo at DEF CON 24 and Rodday at Black Hat Asia are victim-vehicle Move problems on named or professional stacks. Civil GPS, radio, Wi-Fi, FPV, app / SDK, and an unauthenticated professional datalink are the failure classes, not a single CVE.
2. **[Assessment — High confidence]** Melrose (Black Hat USA) and Bishop Fox Arsenal keep the UAV-as-attacker line: close-in RF / EMI toward industrial wireless, and a low-cost quadcopter as a persistent rooftop RF implant. Black Hat Europe 2016 is NIL.
3. **[Inference — Moderate confidence]** Speaker disclosure to an unnamed professional-UAV vendor (Rodday) without a public advisory identifier means Passport still has nothing to close against. Absence of catalogued exploits is not evidence the class is closed.

## 01. Luo: DJI Phantom 3 stack allows hijack of maneuver, including GNSS-spoofed geofence and RTH

*Event / publication dates: presented 7 August 2016 (Sunday 13:00 PT), DEF CON 24, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | software |
| Product | DJI Phantom 3 stack (radio / Wi-Fi / FPV / unauthenticated civil GPS / app / SDK) |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Aaron Luo (Trend Micro) presented “Drones Hijacking - multi-dimensional attack vectors and countermeasures” at DEF CON 24. The DC24 archive, media.defcon.org slides (updated), media.defcon.org video, InfoconDB, and the DEF CON 24 video-and-slides RSS are the primary record. The inventory names https://github.com/Aaron-Luo/DEFCON24 as the talk-named repo for the GPS-related research code. Failure class: the Phantom 3 stack allows hijack of maneuver, including GNSS-spoofed geofence and RTH behavior. No CVE or Exploit-DB ID was found.

**Exposure.** Move: unauthorized maneuver, including geofence and return-to-home driven by a false fix. Sense: unauthenticated civil GPS and FPV / radio / Wi-Fi as inputs. Act: app / SDK as a command path into the same airframe.

**Intelligence assessment.** [Assessment — High confidence] This is the most complete victim-vehicle signal in the leftover 2010–2016 set: one named consumer stack, several trust surfaces, physical consequence is hijack of maneuver. [Assessment — High confidence] Exploit status is public writeup, not catalogued and not reported in the wild in this inventory. [Inference — Moderate confidence] Countermeasures named in the title are speaker guidance, not a vendor patch identifier.

**Opportunity.** Passport Phantom 3 radio, Wi-Fi, FPV, GNSS, app, and SDK as separate trust fields. Kestrel against Unicorn Team 2015 and Robinson / Mitchell 2015. Lab geofence / RTH consequence under a false fix. Campaign the Phantom family from Hill 2013 (collector) to this victim record.

**LRRK relevance.** Control Fabric, Passport, Watch, Lab, Kestrel. Sense-Move-Act on a named DJI stack. KAT: radio / Wi-Fi / GNSS / app → maneuver.

**Confidence.** High on the talk, slides, video, and named repo. Moderate on patch — none published. High that no CVE ID exists in this record.

## 02. Rodday: professional UAV Wi-Fi and XBee telemetry accept unauthenticated command injection

*Event / publication dates: Black Hat Asia 2016 briefings, 31 March and 1 April 2016, Singapore.*

| Field | Value |
| --- | --- |
| Venue | Black Hat Asia |
| Component | firmware |
| Product | Unnamed professional UAV; Wi-Fi (WEP); XBee 868LP telemetry; GCS–airframe datalink |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Nils Rodday presented “Hacking a Professional Drone” at Black Hat Asia 2016. The briefing page and Black Hat slides are the official record. InfoconDB cross-checks the title. Forbes (2 March 2016) covered a surveillance-drone hack ahead of the briefing. A 2015 University of Twente thesis and a NOMS 2016 paper sit behind the talk. The speaker said findings were disclosed to an unnamed professional-UAV vendor; no CVE or public vendor advisory identifier was found. No Exploit-DB ID or GitHub research repo was found.

**Exposure.** Move: unauthenticated / MITM command injection on the GCS–airframe datalink. Sense / Act follow whatever those commands do with the professional airframe. Physical consequence is unauthorized command of a surveillance-class UAV.

**Intelligence assessment.** [Assessment — High confidence] WEP on the aircraft Wi-Fi plus XBee 868LP telemetry is the named fabric, not a consumer toy radio. [Assessment — High confidence] “Disclosed to vendor” without an identifier is not a Passport. [Uncertainty] The airframe vendor remains unnamed in the public record. [Inference — Moderate confidence] Professional SKUs that still ship WEP or unauthenticated XBee-class telemetry share the class even when the badge is different.

**Opportunity.** Passport professional datalinks for Wi-Fi cipher and XBee authentication — evidence, not a speaker claim. Kestrel against WASP 2011 (XBee as truck telemetry) and Luo 2016 (consumer stack). Watch for a CVE that this inventory does not contain.

**LRRK relevance.** Control Fabric, Passport, Watch, Lab. Sense-Move-Act on a professional UAV. KAT: Wi-Fi / XBee → GCS–airframe commands → maneuver.

**Confidence.** High on the briefing and slides. Moderate on vendor identity. High that no public advisory ID was found.

## 03. Melrose: consumer UAV as close-in RF delivery against industrial wireless

*Event / publication dates: presented 3 August 2016 (Wednesday 13:50 PT), Black Hat USA 2016, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | Black Hat USA |
| Component | hardware |
| Product | Consumer UAV used as a close-in RF / EMI delivery platform against industrial wireless; 2.4 GHz control-link coexistence (Yokogawa framing) |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Jeff Melrose (Yokogawa) presented “Drone Attacks on Industrial Wireless: A New Front in Cyber Security” at Black Hat USA 2016. The briefing page and Black Hat slides are the official record. ISSSource, PCMag, and Christian Science Monitor Passcode covered the briefing. InfoconDB cross-checks the title. Failure class: a consumer UAV as a close-in RF / EMI delivery platform against industrial wireless (C-UAS / plant-perimeter gap), including control-link coexistence on 2.4 GHz. No CVE, Exploit-DB ID, or GitHub research repo was found. This is not a dedicated C-UAS product briefing.

**Exposure.** Act from the air toward plant wireless. Sense: coexistence and EMI on industrial links. Move of the consumer UAV is the delivery. Physical consequence is disruption or manipulation of industrial wireless at the perimeter, not a named UAV hijack.

**Intelligence assessment.** [Assessment — High confidence] The object is plant wireless plus a UAV-as-truck, corroborated by A1 slides and B1 trade press. [Assessment — High confidence] No C-UAS product talk exists in this leftover window; do not file this as one. [Inference — Moderate confidence] 2.4 GHz coexistence is a shared-spectrum fact for both the UAV control link and plant radios.

**Opportunity.** Passport plant wireless and perimeter C-UAS as separate fields. Lab UAV-borne RF as a delivery class, not a recipe. Kestrel against Pack / Rowe 2014 (UAV RF survey) and WASP 2011 (RF truck). Campaign plant-perimeter UAV delivery separately from victim-vehicle hijack.

**LRRK relevance.** Watch, Lab, Campaign “UAV-as-RF-delivery.” Sense-Move-Act toward industrial wireless. Control Fabric on 2.4 GHz coexistence. Not a C-UAS product Passport.

**Confidence.** High on the briefing and slides. Moderate on which plant radios were shown. High that no CVE attaches.

## 04. Brown / Latimer / Petro: low-cost quadcopter as a flying pentest laptop / rooftop RF implant

*Event / publication dates: 3 August 2016 (Arsenal theater 11:00 PT; hands-on 14:00 PT), Black Hat USA 2016, Las Vegas.*

| Field | Value |
| --- | --- |
| Venue | Black Hat USA |
| Component | hardware |
| Product | Bishop Fox Danger Drone; low-cost Raspberry Pi quadcopter used as a flying pentest laptop / persistent rooftop RF implant |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Francis Brown, David Latimer, and Dan Petro (Bishop Fox) presented “Highway to the Danger Drone” as a Black Hat USA 2016 Arsenal theater demo and hands-on. The Arsenal theater and Arsenal listing pages, plus the presenter page, are the official record. Vice covered the build as a flying hacker laptop. Speakers said they would release an SD image / parts list / 3-D files via Bishop Fox; no 2016 repo URL was verified. The speaker-firm post dated 26 August 2016 is after this cutoff and is after-record only. No CVE or Exploit-DB ID was found.

**Exposure.** Sense and Act from a flying or perched pentest platform. Move is the quadcopter as delivery and as a rooftop implant. The UAS is the attacker platform, not a disclosed victim.

**Intelligence assessment.** [Assessment — High confidence] Arsenal pages establish the in-window demo. [Assessment — High confidence] Failure class is UAS-as-attacker, continuing WASP / Snoopy, not a Phantom-style hijack. [Uncertainty] No talk-specific GitHub URL is verified. [Inference — Moderate confidence] A Raspberry Pi on a quadcopter is enough to put a persistent RF implant on a roof without a new airframe vendor.

**Opportunity.** Campaign collector-truck airframes (2010–2014 plus this Arsenal). Passport “flying pentest laptop” as a Watch object, not a CVE. Lab rooftop persistence as a physical consequence. Do not treat a promised SD image as a catalogued exploit.

**LRRK relevance.** Watch, Lab, Campaign “UAV-as-attacker.” Sense-Move-Act from a cheap airframe. Kestrel against WASP 2011, Snoopy 2014, and Melrose 2016.

**Confidence.** High on the Arsenal listing and in-window demo. Moderate on the after-cutoff firm post. High that no CVE or verified 2016 repo URL exists in the inventory.

## Forward indicators

1. A public vendor advisory or CVE on the unnamed professional UAV, Phantom 3, or XBee-class telemetry.
2. Catalogued Exploit-DB or in-wild claims tied to these talks — none in this inventory; Iran RQ-170 claims stay outside.
3. MAVLink / ArduPilot / Pixhawk or dedicated C-UAS product talks on these stages (still NIL).
4. Black Hat Europe kinematic briefings (2016 is NIL). DEF CON villages remain NIL for UAV / GCS / GNSS-spoof / MAVLink / DJI / Parrot / C-UAS. DroneWarz Village does not appear until later DEF CONs.

> **Collection integrity.** Searched media.defcon.org DEF CON 24 presentations, video-and-slides, and villages; defcon.org DC24 archive; Black Hat Asia 2016 briefings; Black Hat USA 2016 briefings and Arsenal; Black Hat Europe 2016 briefing lists; InfoconDB; Forbes, ISSSource, PCMag, CS Monitor Passcode, Vice. Four counted talks. Black Hat Europe 2016 is NIL. DEF CON 24 villages (Wireless, Car Hacking, IoT, and the rest of the media.defcon.org village tree) have no UAV / GCS / GNSS-spoof / MAVLink / DJI / Parrot / C-UAS village talk. SkyJack, Humphreys / UT Austin, Shamir Scangate, HOPE 2012, Nullcon, THOTCON / GrrCON / CODE BLUE, ADS-B / ATC, and car CAN talks stayed out. No invented talks. No exploit steps. CVE / Exploit-DB: none found. Luo repo and Rodday thesis / NOMS paper copied from the inventory. Bishop Fox promised SD image has no verified 2016 repo URL.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>