LC-2 · Software Danger Reports
LrrK Def Cuts
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Def Cuts **LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems. | Field | Value | | --- | --- | | Collection cutoff | 7 August 2016 | | Platform | Quiet Systems | | Series | DC-S-03 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Image rights require separate verification before publication. | ## Executive read ### BLUF Aaron Luo’s DEF CON 24 briefing is the 2016 main-stage record that a DJI Phantom 3 stack — radio, Wi-Fi, FPV, unauthenticated civil GPS, app, and SDK — can lose maneuver, including GNSS-spoofed geofence and return-to-home behavior. ### Key judgments 1. **[Assessment — High confidence]** *Drones Hijacking - multi-dimensional attack vectors and countermeasures* was presented by Aaron Luo (Trend Micro) at DEF CON 24 on 7 August 2016; slides and video are on media.defcon.org. 2. **[Assessment — High confidence]** Inventory records no CVE, no Exploit-DB ID, and exploit-status public writeup. A talk-named GitHub repo exists: https://github.com/Aaron-Luo/DEFCON24 (cited as a named record only). 3. **[Inference — Moderate confidence]** The physical consequence is hijacked maneuver of a consumer airframe (false fence / RTH, lost operator control), not a catalogued OEM advisory. ## 01. Phantom 3 stack: GNSS and command-path failures hijack maneuver *Event / publication dates: DEF CON 24, 7 August 2016 (Sun 13:00 PT). Talk date and conference last day coincide; cutoff is 7 August 2016.* | Field | Value | | --- | --- | | Venue | DEF CON | | Component | software | | Product | DJI Phantom 3 | | CVE / advisory | none found | | Patch | none | | Exploit status | public writeup | **Verified record — [Fact — A1]** Talk title *Drones Hijacking - multi-dimensional attack vectors and countermeasures*; speaker Aaron Luo (Trend Micro); DEF CON 24 official archive https://defcon.org/html/links/dc-archives/dc-24-archive.html. After-record: media.defcon.org updated slides (`DEF CON 24 - Aaron-Luo-Drones-Hijacking-Multi-Dimensional-Attack-Vectors-And-Countermeasures-UPDATED.pdf`) and video (`DEF CON 24 - Aaron Luo - Drones Hijacking - multi-dimensional attack vectors - countermeasures.mp4`); DEF CON 24 video-and-slides RSS. InfoconDB is a cross-check only. **[Fact — A1]** CVE / advisory: none found. Exploit-DB ID: none found. GitHub research repo: https://github.com/Aaron-Luo/DEFCON24 (talk-named repo for the GPS-related research code; named as a record, not reproduced). Exploit-status: public writeup. **Exposure.** Move and Act: hijack of maneuver on the Phantom 3. Sense: unauthenticated civil GPS feeding geofence and RTH. Control path: radio / Wi-Fi / FPV / app / SDK named as the other dimensions of the same stack. Update path is not a disclosed item in the inventory. **Intelligence assessment.** **[Assessment — High confidence]** This is DEF CON 24’s only inventoried kinematic main-stage talk. **[Assessment — High confidence]** Failure class is the Phantom 3 stack as a whole (command-path surfaces plus unauthenticated civil GPS), so geofence and RTH can be made to serve a false position and the operator can lose maneuver. **[Uncertainty]** No vendor advisory or CVE was assigned in the talk window; whether a later DJI firmware closed any named surface is outside this cutoff. **[Inference — Moderate confidence]** Combined with 2015 Unicorn Team civil-GNSS work, RTH / geofence is a Sense-to-Move coupling, not a separate radio exploit. **Opportunity.** Passport Phantom 3 (and later DJI stacks) for command-path authentication and for whether geofence / RTH consume unauthenticated civil GNSS. Do not treat the GitHub URL as a patch or as a PoC to run. Watch for a CVE this talk never received. **LRRK relevance.** Move / Act on a named consumer airframe. Sense via civil GNSS into geofence and RTH. Control Fabric (radio / Wi-Fi / app / SDK). Lab and Passport the stack, not a single packet. KAT: GNSS fix to flight-mode logic. **Confidence.** High on the official DC24 record, media archive, and the inventory GitHub URL as a named record. Moderate on later firmware state (not in window). Nil on CVE and EDB. ## Forward indicators 1. A DJI advisory or CVE is retroactively tied to this 2016 Phantom 3 showing (inventory: none). 2. A later BH/DC talk separates command-path takeover from GNSS-fed geofence / RTH as distinct Passport questions. 3. The talk-named GitHub record is archived, moved, or cited by a vendor response; still a named record only. > **Collection integrity.** Built from leftover inventory 2016-04 only. Official sources: defcon.org DC24 archive; media.defcon.org DC24 presentations and video-and-slides; DEF CON 24 RSS; GitHub URL copied from the inventory as a named record. InfoconDB cross-check only. Black Hat Europe 2016 and DEF CON 24 villages remain NIL for kinematic titles. Slides, video, and repo contents treated as metadata; hijack procedures, GNSS recipes, and payloads excluded. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none found / none found / https://github.com/Aaron-Luo/DEFCON24 / public writeup. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>