← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/specials/dc-03-drones-hijacking.md
Imported-content SHA-256
8303009406a2910eadbf4932df547d63779d626f24e5cdb34eddb3b6516d4b76
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 7 August 2016 |
| Platform | Quiet Systems |
| Series | DC-S-03 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

Aaron Luo’s DEF CON 24 briefing is the 2016 main-stage record that a DJI Phantom 3 stack — radio, Wi-Fi, FPV, unauthenticated civil GPS, app, and SDK — can lose maneuver, including GNSS-spoofed geofence and return-to-home behavior.

### Key judgments

1. **[Assessment — High confidence]** *Drones Hijacking - multi-dimensional attack vectors and countermeasures* was presented by Aaron Luo (Trend Micro) at DEF CON 24 on 7 August 2016; slides and video are on media.defcon.org.
2. **[Assessment — High confidence]** Inventory records no CVE, no Exploit-DB ID, and exploit-status public writeup. A talk-named GitHub repo exists: https://github.com/Aaron-Luo/DEFCON24 (cited as a named record only).
3. **[Inference — Moderate confidence]** The physical consequence is hijacked maneuver of a consumer airframe (false fence / RTH, lost operator control), not a catalogued OEM advisory.

## 01. Phantom 3 stack: GNSS and command-path failures hijack maneuver

*Event / publication dates: DEF CON 24, 7 August 2016 (Sun 13:00 PT). Talk date and conference last day coincide; cutoff is 7 August 2016.*

| Field | Value |
| --- | --- |
| Venue | DEF CON |
| Component | software |
| Product | DJI Phantom 3 |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Talk title *Drones Hijacking - multi-dimensional attack vectors and countermeasures*; speaker Aaron Luo (Trend Micro); DEF CON 24 official archive https://defcon.org/html/links/dc-archives/dc-24-archive.html. After-record: media.defcon.org updated slides (`DEF CON 24 - Aaron-Luo-Drones-Hijacking-Multi-Dimensional-Attack-Vectors-And-Countermeasures-UPDATED.pdf`) and video (`DEF CON 24 - Aaron Luo - Drones Hijacking - multi-dimensional attack vectors - countermeasures.mp4`); DEF CON 24 video-and-slides RSS. InfoconDB is a cross-check only. **[Fact — A1]** CVE / advisory: none found. Exploit-DB ID: none found. GitHub research repo: https://github.com/Aaron-Luo/DEFCON24 (talk-named repo for the GPS-related research code; named as a record, not reproduced). Exploit-status: public writeup.

**Exposure.** Move and Act: hijack of maneuver on the Phantom 3. Sense: unauthenticated civil GPS feeding geofence and RTH. Control path: radio / Wi-Fi / FPV / app / SDK named as the other dimensions of the same stack. Update path is not a disclosed item in the inventory.

**Intelligence assessment.** **[Assessment — High confidence]** This is DEF CON 24’s only inventoried kinematic main-stage talk. **[Assessment — High confidence]** Failure class is the Phantom 3 stack as a whole (command-path surfaces plus unauthenticated civil GPS), so geofence and RTH can be made to serve a false position and the operator can lose maneuver. **[Uncertainty]** No vendor advisory or CVE was assigned in the talk window; whether a later DJI firmware closed any named surface is outside this cutoff. **[Inference — Moderate confidence]** Combined with 2015 Unicorn Team civil-GNSS work, RTH / geofence is a Sense-to-Move coupling, not a separate radio exploit.

**Opportunity.** Passport Phantom 3 (and later DJI stacks) for command-path authentication and for whether geofence / RTH consume unauthenticated civil GNSS. Do not treat the GitHub URL as a patch or as a PoC to run. Watch for a CVE this talk never received.

**LRRK relevance.** Move / Act on a named consumer airframe. Sense via civil GNSS into geofence and RTH. Control Fabric (radio / Wi-Fi / app / SDK). Lab and Passport the stack, not a single packet. KAT: GNSS fix to flight-mode logic.

**Confidence.** High on the official DC24 record, media archive, and the inventory GitHub URL as a named record. Moderate on later firmware state (not in window). Nil on CVE and EDB.

## Forward indicators

1. A DJI advisory or CVE is retroactively tied to this 2016 Phantom 3 showing (inventory: none).
2. A later BH/DC talk separates command-path takeover from GNSS-fed geofence / RTH as distinct Passport questions.
3. The talk-named GitHub record is archived, moved, or cited by a vendor response; still a named record only.

> **Collection integrity.** Built from leftover inventory 2016-04 only. Official sources: defcon.org DC24 archive; media.defcon.org DC24 presentations and video-and-slides; DEF CON 24 RSS; GitHub URL copied from the inventory as a named record. InfoconDB cross-check only. Black Hat Europe 2016 and DEF CON 24 villages remain NIL for kinematic titles. Slides, video, and repo contents treated as metadata; hijack procedures, GNSS recipes, and payloads excluded. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none found / none found / https://github.com/Aaron-Luo/DEFCON24 / public writeup.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>