LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 May 2016 | | Platform | Quiet Systems | | Series | DKSR-M-2016-05 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF First dated public structured analysis of a DJI Phantom 3 Standard software stack — not only the GNSS geofence. Course paper, not a vendor advisory. ### Key judgments 1. **[Assessment — High confidence]** Document date 11 May 2016 on the MIT 6.857 course PDF. Spring 2016 project. 2. **[Assessment — High confidence]** Product: Phantom 3 Standard (OpenWRT 14.07 on aircraft and controller; DJI GO; Wi-Fi). No CVE. 3. **[Inference — Moderate confidence]** Main operator recommendation is change the Wi-Fi password at first use. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. MIT 6.857: Security Analysis of DJI Phantom 3 Standard *Event / publication dates: 11 May 2016 (course PDF date)* | Field | Value | | --- | --- | | Component | firmware | | Product | DJI Phantom 3 Standard (OpenWRT 14.07 on aircraft and controller; DJI GO; Wi-Fi) | | CVE / advisory | no CVE | | Patch | none as a CVE | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · OWASP IoT I1 | **Verified record — [Fact — A1] https://courses.csail.mit.edu/6.857/2016/files/9.pdf · course project list https://courses.csail.mit.edu/6.857/2016/projects** **Exposure.** Weak / default Wi-Fi, exposed services, data-at-rest on the aircraft. C2 and Sense (stored logs/media). **Intelligence assessment.** [Assessment — High confidence] Document date and product. This is a course report, not a vendor advisory. **Opportunity.** Pair with Luo DEF CON 24 (August) on Phantom 3 Advanced. **LRRK relevance.** Control Fabric. Watch. **Confidence.** High on date and product. ## Forward indicators 1. Luo DEF CON 24 Phantom 3 Advanced (August 2016). > **Collection integrity.** One course paper. Not padded. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>