LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 December 2013 | | Platform | Quiet Systems | | Series | DKSR-M-2013-12 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF SkyJack automates the AR.Drone open-Wi-Fi GCS failure into a flying, repeatable hijack. The known missing command authentication is now a public tool. A same-month workshop paper offers an open UAV-network simulation testbed — methodology, not a fielded-product bug. ### Key judgments 1. **[Assessment — High confidence]** Samy Kamkar, 2 December 2013 (blog + GitHub). Named-outlet coverage the same week (Ars Technica; Computerworld 4 December; BBC). Parrot “unable to comment yet” / “looking into the allegation.” 2. **[Assessment — High confidence]** Target is Parrot AR.Drone and AR.Drone 2.0: open Wi-Fi AP, Parrot OUI MACs, no command authentication. No CVE. No Parrot patch identified in December 2013 coverage. 3. **[Inference — Moderate confidence]** UAVSim (Javaid / Sun / Alam, GLOBECOM Wi-UAV, 9 December) is a jamming-impact testbed, not a product vulnerability. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. SkyJack: autonomous wireless takeover of Parrot AR.Drone 1/2 *Event / publication dates: Samy Kamkar, 2 December 2013 (blog + GitHub). Ars Technica same week (notes Monday 2 December). Computerworld 4 December 2013. BBC December 2013.* | Field | Value | | --- | --- | | Component | software / firmware | | Product | Parrot AR.Drone and AR.Drone 2.0 (open Wi-Fi AP, Parrot OUI MACs, no command authentication). SkyJack software on Linux / Raspberry Pi; also ground-only. | | CVE / advisory | no CVE | | Patch | none | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — A1]** Samy Kamkar, “SkyJack: autonomous drone hacking,” 2 December 2013; GitHub samyk/skyjack; Dan Goodin, Ars Technica, December 2013 (half a million Parrot units cited); Lucian Constantin, Computerworld, 4 December 2013; Leo Kelion, BBC News, December 2013 (Ross Anderson: authenticate commands or encrypt the link). http://samy.pl/skyjack/ · http://sa.my/skyjack/ · https://github.com/samyk/skyjack · https://arstechnica.com/information-technology/2013/12/flying-hacker-contraption-hunts-other-drones-turns-them-into-zombies/ · https://www.computerworld.com/article/1605263/hacker-built-drone-can-hunt-hijack-other-drones.html · https://www.bbc.com/news/technology-25217378 **Exposure.** Unauthenticated Wi-Fi C2. Deauth then owner-impersonation is the published failure class. Move and Act on a mass-market airframe. **Intelligence assessment.** [Assessment — High confidence] Era-defining public automation of the 2010–2012 AR.Drone design. [Uncertainty] Not a catalogued CVE. Not reported as a wild criminal campaign. BBC: Parrot unable to comment yet. **Opportunity.** Passport command authentication vs open AP. Watch Pleban SPIE 2014 (out of range). A December 2013 GitHub question on Phantom Wi-Fi is a question, not a case. **LRRK relevance.** Control Fabric. Watch. Lab open-Wi-Fi GCS. Sense-Move-Act. **Confidence.** High. ## 02. UAVSim: UAV-network cyber simulation testbed *Event / publication dates: IEEE GLOBECOM 2013 Workshops / Wi-UAV, Atlanta, 9–13 December 2013 (workshop date given by authors as 9 December 2013).* | Field | Value | | --- | --- | | Component | software | | Product | UAVSim (OMNeT++ / OS3-based UAV network simulator) | | CVE / advisory | no CVE | | Patch | not applicable | | Exploit status | none public | **Verified record — [Fact — A1]** Ahmad Y. Javaid, Weiqing Sun, Mansoor Alam, “UAVSim: A simulation testbed for unmanned aerial vehicle network cyber security analysis,” 2013 IEEE Globecom Workshops, pp. 1432–1436. https://doi.org/10.1109/glocomw.2013.6825196 **Exposure.** Simulation of UAV C2 / RF availability under jamming. Later related work names GPS jamming/spoofing as intended modules; the 2013 reported experiment is jamming. **Intelligence assessment.** [Assessment — High confidence] First open simulation testbed paper aimed at UAV-network cyber experiments. [Assessment — Moderate confidence] Methodology, not a fielded-product bug. **Opportunity.** Do not treat a simulator paper as a product CVE. Watch Marty MAVLink thesis (March 2014, out of range). **LRRK relevance.** Lab. Watch (methodology). **Confidence.** High on the paper. Moderate as a case. ## Forward indicators 1. Pleban, Band, Creutzburg, SPIE 2014 AR.Drone 2.0 — out of range. 2. Joseph A. Marty, AFIT MAVLink thesis, 14 March 2014 — out of range. 3. A dated DJI Phantom security writeup (first verified public cases start 2014). > **Collection integrity.** Two signals. SkyJack GitHub Phantom question excluded (a question, not a case). Pleban / Marty / Phantom writeups are 2014. Not padded. Public sources only. No invented CVEs. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>