← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Def Cuts

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/Def Cuts/specials/dc-01-wasp.md
Imported-content SHA-256
e4aa9966fc84b31164d5d1ec83fe2d4e378a44abcbafa6b2621e8a90fa60a8a0
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Def Cuts

**LRRK Watch / Conference Record** — Public DEF CON / Black Hat signals on software, firmware, and hardware that move physical systems.

| Field | Value |
| --- | --- |
| Collection cutoff | 7 August 2011 |
| Platform | Quiet Systems |
| Series | DC-S-01 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Image rights require separate verification before publication. |

## Executive read

### BLUF

The same WASP research at Black Hat USA 2011 and DEF CON 19 treats a surplus target-drone airframe plus open autopilot and XBee telemetry as a standoff RF payload truck — the aircraft is the sensor, not a vendor-CVE victim.

### Key judgments

1. **[Assessment — High confidence]** Inventory 2011-01 (*Aerial Cyber Apocalypse: If we can do it... they can too.*) and 2011-02 (*Wireless Aerial Surveillance Platform*) are one research program (Perkins / Tassey), shown on consecutive Las Vegas stages, not two independent disclosures.
2. **[Assessment — High confidence]** The named failure class is a hobby/surplus kinematic stack used to carry wireless and cellular collection payloads over an ArduPilot + XBee datalink. No CVE, Exploit-DB ID, or talk-tied GitHub repo was attached.
3. **[Inference — Moderate confidence]** Open autopilot plus commodity telemetry on a surplus airframe is a Control Fabric / payload-integration pattern that later aerial-collection talks inherit; it is not evidence of a catalogued command-link flaw in a named OEM UAS.

## 01. WASP: surplus airframe shown as a standoff RF payload truck

*Event / publication dates: Black Hat USA 2011 briefing, 3 August 2011 (Wed 16:45 PT); DEF CON 19 presentation, 7 August 2011 (Sun 16:00 PT). DEF CON 19 last day is the collection cutoff.*

| Field | Value |
| --- | --- |
| Venue | Black Hat USA; DEF CON |
| Component | hardware |
| Product | WASP (surplus target-drone airframe; ArduPilot; XBee telemetry) |
| CVE / advisory | none found |
| Patch | none |
| Exploit status | public writeup |

**Verified record — [Fact — A1]** Richard Perkins and Mike Tassey (speaker-card order reverses between venues) presented the Wireless Aerial Surveillance Platform at Black Hat USA 2011 (*Aerial Cyber Apocalypse: If we can do it... they can too.*, official archive https://blackhat.com/html/bh-us-11/bh-us-11-archives.html) and again at DEF CON 19 (*Wireless Aerial Surveillance Platform*, official archive https://defcon.org/html/links/dc-archives/dc-19-archive.html). DEF CON after-record is on media.defcon.org: slides (`DEF CON 19 - Tassey-Perkins-Wireless-Aerial-Surveillance-Platform.pdf`) and video (`DEF CON 19 - Mike Tassey and Rich Perkins - Wireless Aerial Surveillance Platform.mp4`); a copy of the slides also sits on defcon.org under `dc-19-presentations`. Named after-record outlets covering the Black Hat showing: Wired (2011-08), Dark Reading / Threatpost wardriving-to-warflying piece, ABC News WASP feature. InfoconDB is a cross-check only. **[Fact — A1]** CVE / advisory: none found. Exploit-DB ID: none found. GitHub research repo: none found. Exploit-status on both venue records: public writeup.

**Exposure.** Sense and payload: the airframe carries wireless / cellular collection. Move is the delivery of that payload to standoff range. The kinematic object is the attacker platform, not a hijacked OEM drone. The ArduPilot + XBee path is the Control Fabric of the truck, not a disclosed takeover of a third-party command link.

**Intelligence assessment.** **[Assessment — High confidence]** Merging 2011-01 and 2011-02 into one special is required by the inventory: same speakers, same WASP class, same week, two venues. **[Assessment — High confidence]** Physical consequence stated by the record is an autonomous UAV used as an RF / cellular payload truck, not loss of someone else’s aircraft. **[Uncertainty]** No vendor advisory or product CVE was assigned; surplus airframe identity beyond “target-drone / WASP” is not a Passport SKU. **[Inference — Moderate confidence]** Later DEF CON / Black Hat aerial-collection talks (Snoopy, Phantom perch-and-stare, Danger Drone) sit on this “UAS as sensor” pattern.

**Opportunity.** Passport WASP as a payload-integration case (open autopilot + commodity telemetry + surplus airframe), not as a CVE. Lab whether a later fleet still treats ArduPilot + XBee as an unauthenticated command path. Watch for a vendor advisory that this 2011 record never produced.

**LRRK relevance.** Sense (collection payload). Control Fabric (ArduPilot + XBee on the truck). Watch / Lab for the airframe-as-attacker class. Not Campaign of a named OEM flight stack.

**Confidence.** High on the two official venue records, the media.defcon.org after-record, and the single-research merge. Moderate on after-record outlet color. Nil on CVE, EDB, and a talk-tied repo.

## Forward indicators

1. A CVE, vendor advisory, or Exploit-DB ID is later tied to this 2011 WASP showing (inventory: none).
2. A later BH/DC talk cites WASP as precedent for UAV-as-payload-truck rather than UAV-as-victim.
3. A Passport on open autopilot plus XBee-class telemetry records authentication state instead of “hobby, therefore out of scope.”

> **Collection integrity.** Built from leftover inventory 2011-01 and 2011-02 only (same research, both venues). Official sources: blackhat.com USA 2011 archives; defcon.org DC19 archive; media.defcon.org DC19 presentations and video-and-slides; named Wired / Dark Reading / ABC News after-records. InfoconDB used as cross-check, not sole evidence. Slides and video treated as metadata; how-to, payload recipes, and RF procedures excluded. Black Hat Europe 2011 remains NIL for kinematic briefings. No invented talks. CVE / EDB / GitHub / exploit-status copied from the inventory: none found / none found / none found / public writeup.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>