# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 December 2013 |
| Platform | Quiet Systems |
| Series | DKSR-M-2013-12 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

SkyJack automates the AR.Drone open-Wi-Fi GCS failure into a flying, repeatable hijack. The known missing command authentication is now a public tool. A same-month workshop paper offers an open UAV-network simulation testbed — methodology, not a fielded-product bug.

### Key judgments

1. **[Assessment — High confidence]** Samy Kamkar, 2 December 2013 (blog + GitHub). Named-outlet coverage the same week (Ars Technica; Computerworld 4 December; BBC). Parrot “unable to comment yet” / “looking into the allegation.”
2. **[Assessment — High confidence]** Target is Parrot AR.Drone and AR.Drone 2.0: open Wi-Fi AP, Parrot OUI MACs, no command authentication. No CVE. No Parrot patch identified in December 2013 coverage.
3. **[Inference — Moderate confidence]** UAVSim (Javaid / Sun / Alam, GLOBECOM Wi-UAV, 9 December) is a jamming-impact testbed, not a product vulnerability.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. SkyJack: autonomous wireless takeover of Parrot AR.Drone 1/2

*Event / publication dates: Samy Kamkar, 2 December 2013 (blog + GitHub). Ars Technica same week (notes Monday 2 December). Computerworld 4 December 2013. BBC December 2013.*

| Field | Value |
| --- | --- |
| Component | software / firmware |
| Product | Parrot AR.Drone and AR.Drone 2.0 (open Wi-Fi AP, Parrot OUI MACs, no command authentication). SkyJack software on Linux / Raspberry Pi; also ground-only. |
| CVE / advisory | no CVE |
| Patch | none |
| Exploit status | public writeup |
| Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 |

**Verified record — [Fact — A1]** Samy Kamkar, “SkyJack: autonomous drone hacking,” 2 December 2013; GitHub samyk/skyjack; Dan Goodin, Ars Technica, December 2013 (half a million Parrot units cited); Lucian Constantin, Computerworld, 4 December 2013; Leo Kelion, BBC News, December 2013 (Ross Anderson: authenticate commands or encrypt the link). http://samy.pl/skyjack/ · http://sa.my/skyjack/ · https://github.com/samyk/skyjack · https://arstechnica.com/information-technology/2013/12/flying-hacker-contraption-hunts-other-drones-turns-them-into-zombies/ · https://www.computerworld.com/article/1605263/hacker-built-drone-can-hunt-hijack-other-drones.html · https://www.bbc.com/news/technology-25217378

**Exposure.** Unauthenticated Wi-Fi C2. Deauth then owner-impersonation is the published failure class. Move and Act on a mass-market airframe.

**Intelligence assessment.** [Assessment — High confidence] Era-defining public automation of the 2010–2012 AR.Drone design. [Uncertainty] Not a catalogued CVE. Not reported as a wild criminal campaign. BBC: Parrot unable to comment yet.

**Opportunity.** Passport command authentication vs open AP. Watch Pleban SPIE 2014 (out of range). A December 2013 GitHub question on Phantom Wi-Fi is a question, not a case.

**LRRK relevance.** Control Fabric. Watch. Lab open-Wi-Fi GCS. Sense-Move-Act.

**Confidence.** High.

## 02. UAVSim: UAV-network cyber simulation testbed

*Event / publication dates: IEEE GLOBECOM 2013 Workshops / Wi-UAV, Atlanta, 9–13 December 2013 (workshop date given by authors as 9 December 2013).*

| Field | Value |
| --- | --- |
| Component | software |
| Product | UAVSim (OMNeT++ / OS3-based UAV network simulator) |
| CVE / advisory | no CVE |
| Patch | not applicable |
| Exploit status | none public |

**Verified record — [Fact — A1]** Ahmad Y. Javaid, Weiqing Sun, Mansoor Alam, “UAVSim: A simulation testbed for unmanned aerial vehicle network cyber security analysis,” 2013 IEEE Globecom Workshops, pp. 1432–1436. https://doi.org/10.1109/glocomw.2013.6825196

**Exposure.** Simulation of UAV C2 / RF availability under jamming. Later related work names GPS jamming/spoofing as intended modules; the 2013 reported experiment is jamming.

**Intelligence assessment.** [Assessment — High confidence] First open simulation testbed paper aimed at UAV-network cyber experiments. [Assessment — Moderate confidence] Methodology, not a fielded-product bug.

**Opportunity.** Do not treat a simulator paper as a product CVE. Watch Marty MAVLink thesis (March 2014, out of range).

**LRRK relevance.** Lab. Watch (methodology).

**Confidence.** High on the paper. Moderate as a case.

## Forward indicators

1. Pleban, Band, Creutzburg, SPIE 2014 AR.Drone 2.0 — out of range.
2. Joseph A. Marty, AFIT MAVLink thesis, 14 March 2014 — out of range.
3. A dated DJI Phantom security writeup (first verified public cases start 2014).

> **Collection integrity.** Two signals. SkyJack GitHub Phantom question excluded (a question, not a case). Pleban / Marty / Phantom writeups are 2014. Not padded. Public sources only. No invented CVEs. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
