LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 August 2015 | | Platform | Quiet Systems | | Series | DKSR-M-2015-08 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF DEF CON 23 week shows the same trust failure on three consumer stacks and, in press, a professional radio: Sense (civil GNSS / geofence) and C2 (open AP, telnet, FTP, cleartext telemetry) are unsigned. ### Key judgments 1. **[Assessment — High confidence]** Four distinct public records this month: Qihoo Phantom 3 GPS (7–8 Aug), Satterfield AR.Drone (8 Aug), Robinson Bebop (9 Aug), U-Today Rodday press (20 Aug). 2. **[Assessment — High confidence]** No CVE on any of the four. Parrot open-AP is a known class (Pleban 2014, Kamkar 2013), re-demonstrated live. 3. **[Inference — Moderate confidence]** Four signals, not five. Status stays short. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. Qihoo Unicorn Team: GPS spoof of DJI Phantom 3 *Event / publication dates: DEF CON 23 talk 7 August 2015. Forbes 8 August 2015. eWeek / SCMP 10 August 2015* | Field | Value | | --- | --- | | Component | hardware | | Product | DJI Phantom 3 (geofence / no-fly logic driven by civil GPS). Talk also covers phones and a car. | | CVE / advisory | no CVE | | Patch | none at the GPS C/A layer | | Exploit status | public writeup | | Taxonomy | CWE-345 (class) · CAPEC-148 · OWASP IoT I7 | **Verified record — [Fact — B2] Forbes 8 Aug 2015 https://www.forbes.com/sites/thomasbrewster/2015/08/08/qihoo-hacks-drone-gps/ · eWeek 10 Aug 2015 https://www.eweek.com/security/chinese-unicorn-team-hacks-gps-at-defcon/ · SCMP 10 Aug 2015 https://www.scmp.com/tech/article/1848328/us300-device-chinese-cybersecurity-researchers-claim-they-can-take-over-drones** **Exposure.** Unauthenticated civil GNSS drives GEO / no-fly. Sense collapses a policy into Move (forced landing or bypass). **Intelligence assessment.** [Assessment — High confidence] 7–8 August 2015 and Phantom 3 as the demonstrated airframe. Researchers said a chip-level fix would not reach fielded airframes. **Opportunity.** Passport geofence as a GNSS-trust function, not a hard interlock. **LRRK relevance.** Sense-Move-Act. Control Fabric (policy). **Confidence.** High. ## 02. Satterfield: Parrot AR.Drone open Wi-Fi and telnet *Event / publication dates: DEF CON 23 IoT Village, 8 August 2015. The Register 18 August 2015; Ars Technica 20 August 2015* | Field | Value | | --- | --- | | Component | firmware | | Product | Parrot AR.Drone (BusyBox Linux, open AP, telnet root) | | CVE / advisory | no CVE | | Patch | none found as a CVE. Satterfield told press Parrot already knew. | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — B2] Ars Technica https://arstechnica.com/information-technology/2015/08/parrot-drones-easily-taken-down-or-hijacked-researchers-demonstrate/ · The Register 18 Aug 2015 https://www.theregister.com/security/2015/08/18/parrot-drone-pwned-and-possibly-killed-with-wi-fi-log-in/581837** **Exposure.** Default-open C2 and host services. Move/Act. **Intelligence assessment.** [Assessment — High confidence] 8 August 2015 venue. High that this is a known class, not a new CVE. **Opportunity.** Same baseline as Pleban 2014 and Maldrone. Do not invent an ID. **LRRK relevance.** Control Fabric. **Confidence.** High. ## 03. Robinson: Parrot Bebop de-auth, app pairing, open FTP *Event / publication dates: DEF CON 23 session 9 August 2015* | Field | Value | | --- | --- | | Component | firmware | | Product | Parrot Bebop (open Wi-Fi, official app pairing, open telnet, open FTP for media) | | CVE / advisory | no CVE | | Patch | none found as a CVE | | Exploit status | public writeup | | Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 | **Verified record — [Fact — B2] Ars Technica https://arstechnica.com/information-technology/2015/08/parrot-drones-easily-taken-down-or-hijacked-researchers-demonstrate/** **Exposure.** Unauthenticated C2, de-auth plus pairing, open media FTP. Move/Act and payload (camera media). Talk also notes GPS-jamming effects on return-to-home. **Intelligence assessment.** [Assessment — High confidence] 9 August 2015 and Bebop as the named product. Moves the Parrot open-AP class from AR.Drone onto Bebop. **Opportunity.** Watch Hooper ARDiscovery (June 2016) on the same product. **LRRK relevance.** Control Fabric. Sense (camera store). **Confidence.** High. ## 04. U-Today: Rodday professional-UAV thesis in press *Event / publication dates: 20 August 2015 (Dutch and English U-Today)* | Field | Value | | --- | --- | | Component | firmware | | Product | Unnamed professional UAV (same as 2015-07-A) | | CVE / advisory | no CVE | | Patch | none. Supervisor quoted: software upgrade is not enough; hardware change / recall implied. | | Exploit status | public writeup | **Verified record — [Fact — A1] U-Today EN 20 Aug 2015 https://www.utoday.nl/news/61794/Student_hacks_professional_drone · U-Today NL https://www.utoday.nl/news/61792/Student_hackt_professionele_drone** **Exposure.** Unauthenticated / cleartext professional telemetry. Same radio as the July thesis. Move/Act. **Intelligence assessment.** [Assessment — High confidence] 20 August 2015. Same case family as 2015-07-A and 2016-03-A. Full technical slides come in March 2016. **Opportunity.** Date the press. Map the public-control-link case at RSA (March 2016). Do not invent a manufacturer or CVE. **LRRK relevance.** Control Fabric. Watch. **Confidence.** High. ## Forward indicators 1. Petrovsky APM/PX4 Virus Bulletin (September 2015). 2. Rodday RSA / Black Hat Asia (March 2016). 3. Hooper Bebop ARDiscovery (June 2016). > **Collection integrity.** Four verified signals. Not padded to five. Rodday taxonomy reserved for 2016-03. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>