# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 August 2015 |
| Platform | Quiet Systems |
| Series | DKSR-M-2015-08 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

DEF CON 23 week shows the same trust failure on three consumer stacks and, in press, a professional radio: Sense (civil GNSS / geofence) and C2 (open AP, telnet, FTP, cleartext telemetry) are unsigned.

### Key judgments

1. **[Assessment — High confidence]** Four distinct public records this month: Qihoo Phantom 3 GPS (7–8 Aug), Satterfield AR.Drone (8 Aug), Robinson Bebop (9 Aug), U-Today Rodday press (20 Aug).
2. **[Assessment — High confidence]** No CVE on any of the four. Parrot open-AP is a known class (Pleban 2014, Kamkar 2013), re-demonstrated live.
3. **[Inference — Moderate confidence]** Four signals, not five. Status stays short.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. Qihoo Unicorn Team: GPS spoof of DJI Phantom 3

*Event / publication dates: DEF CON 23 talk 7 August 2015. Forbes 8 August 2015. eWeek / SCMP 10 August 2015*

| Field | Value |
| --- | --- |
| Component | hardware |
| Product | DJI Phantom 3 (geofence / no-fly logic driven by civil GPS). Talk also covers phones and a car. |
| CVE / advisory | no CVE |
| Patch | none at the GPS C/A layer |
| Exploit status | public writeup |
| Taxonomy | CWE-345 (class) · CAPEC-148 · OWASP IoT I7 |

**Verified record — [Fact — B2] Forbes 8 Aug 2015 https://www.forbes.com/sites/thomasbrewster/2015/08/08/qihoo-hacks-drone-gps/ · eWeek 10 Aug 2015 https://www.eweek.com/security/chinese-unicorn-team-hacks-gps-at-defcon/ · SCMP 10 Aug 2015 https://www.scmp.com/tech/article/1848328/us300-device-chinese-cybersecurity-researchers-claim-they-can-take-over-drones**

**Exposure.** Unauthenticated civil GNSS drives GEO / no-fly. Sense collapses a policy into Move (forced landing or bypass).

**Intelligence assessment.** [Assessment — High confidence] 7–8 August 2015 and Phantom 3 as the demonstrated airframe. Researchers said a chip-level fix would not reach fielded airframes.

**Opportunity.** Passport geofence as a GNSS-trust function, not a hard interlock.

**LRRK relevance.** Sense-Move-Act. Control Fabric (policy).

**Confidence.** High.
## 02. Satterfield: Parrot AR.Drone open Wi-Fi and telnet

*Event / publication dates: DEF CON 23 IoT Village, 8 August 2015. The Register 18 August 2015; Ars Technica 20 August 2015*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Parrot AR.Drone (BusyBox Linux, open AP, telnet root) |
| CVE / advisory | no CVE |
| Patch | none found as a CVE. Satterfield told press Parrot already knew. |
| Exploit status | public writeup |
| Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 |

**Verified record — [Fact — B2] Ars Technica https://arstechnica.com/information-technology/2015/08/parrot-drones-easily-taken-down-or-hijacked-researchers-demonstrate/ · The Register 18 Aug 2015 https://www.theregister.com/security/2015/08/18/parrot-drone-pwned-and-possibly-killed-with-wi-fi-log-in/581837**

**Exposure.** Default-open C2 and host services. Move/Act.

**Intelligence assessment.** [Assessment — High confidence] 8 August 2015 venue. High that this is a known class, not a new CVE.

**Opportunity.** Same baseline as Pleban 2014 and Maldrone. Do not invent an ID.

**LRRK relevance.** Control Fabric.

**Confidence.** High.
## 03. Robinson: Parrot Bebop de-auth, app pairing, open FTP

*Event / publication dates: DEF CON 23 session 9 August 2015*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Parrot Bebop (open Wi-Fi, official app pairing, open telnet, open FTP for media) |
| CVE / advisory | no CVE |
| Patch | none found as a CVE |
| Exploit status | public writeup |
| Taxonomy | CAPEC-115 · ATT&CK ICS T0860 · T1692.001 (T0855) · OWASP IoT I1 · I2 · EMB3D TID-406 |

**Verified record — [Fact — B2] Ars Technica https://arstechnica.com/information-technology/2015/08/parrot-drones-easily-taken-down-or-hijacked-researchers-demonstrate/**

**Exposure.** Unauthenticated C2, de-auth plus pairing, open media FTP. Move/Act and payload (camera media). Talk also notes GPS-jamming effects on return-to-home.

**Intelligence assessment.** [Assessment — High confidence] 9 August 2015 and Bebop as the named product. Moves the Parrot open-AP class from AR.Drone onto Bebop.

**Opportunity.** Watch Hooper ARDiscovery (June 2016) on the same product.

**LRRK relevance.** Control Fabric. Sense (camera store).

**Confidence.** High.
## 04. U-Today: Rodday professional-UAV thesis in press

*Event / publication dates: 20 August 2015 (Dutch and English U-Today)*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | Unnamed professional UAV (same as 2015-07-A) |
| CVE / advisory | no CVE |
| Patch | none. Supervisor quoted: software upgrade is not enough; hardware change / recall implied. |
| Exploit status | public writeup |

**Verified record — [Fact — A1] U-Today EN 20 Aug 2015 https://www.utoday.nl/news/61794/Student_hacks_professional_drone · U-Today NL https://www.utoday.nl/news/61792/Student_hackt_professionele_drone**

**Exposure.** Unauthenticated / cleartext professional telemetry. Same radio as the July thesis. Move/Act.

**Intelligence assessment.** [Assessment — High confidence] 20 August 2015. Same case family as 2015-07-A and 2016-03-A. Full technical slides come in March 2016.

**Opportunity.** Date the press. Map the public-control-link case at RSA (March 2016). Do not invent a manufacturer or CVE.

**LRRK relevance.** Control Fabric. Watch.

**Confidence.** High.

## Forward indicators

1. Petrovsky APM/PX4 Virus Bulletin (September 2015).
2. Rodday RSA / Black Hat Asia (March 2016).
3. Hooper Bebop ARDiscovery (June 2016).

> **Collection integrity.** Four verified signals. Not padded to five. Rodday taxonomy reserved for 2016-03. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
