Skip to main content

Command Palette

Search for a command to run...

Drone Hacking Tool Analysis: DroneSploit

Published
2 min readView as Markdown
Drone Hacking Tool Analysis: DroneSploit
C
酷愛計算機技術Ardently Love Computer Technology 長期關註反洗錢反欺詐Long-term Focus on Anti-Money Laundering and Anti-Fraud 精通支付結算的技術、系統、流程和製度Proficient in the Technology, System, Process and Institution of Payment and Settlement

August 17, 2021


DroneSploit is a dedicated exploit framework which comprises of various drone hacking techniques. It targets WiFi based Commercial-Off-The-Shelf drones and was first observed in in the wild in early December of 2019.

Here at DroneSec we like to think of drones as flying computers and like any computer system, they contain a significant amount of data which if left vulnerable could present a cyber risk. Understanding these risks can help you to better secure your drone ecosystem and prevent financial, data, or asset loss.

  • Overview

The framework consists of both old and new attack vectors against a variety of drone types, including passive and active monitoring, deauth attacks and vectors to break into closed drone-controller circuits. The aim is to automate and streamline the process, being simple to conduct and visualise the results in real-time.

The framework is limited in its ability to only target WiFi-based drones (e.g. AR Drone, DJI Tello, Mavic Mini) but not RF-based drones (DJI Phantom 4, Mavic Pro etc) but the goal being to bring together as many exploits as possible for drones under one roof. By typically Information Security standards, it seeks to make users aware of the risks and perform simulated attacks against their own systems in order to better protect them.

  • Recommendations

As with any WiFi-based drone systems, ensure appropriate attack-vectors have been identified and simulated against. For drones that allow modification of their Wireless Access Points (WAPs) and associated passwords, customise these before flight operations, disable open-connectivity and ensure networks are protected with up-to-date encryption standards. Where possible, use MAC filtering to ensure only your trusted devices can connect. Review your drones’ action-policy for what happens when it loses connectivity and document the process for any unexpected actions it might take.

  • References

https://github.com/dhondta/dronesploit

https://github.com/dhondta/dronesploit/blob/master/docs/blackhat-eu19-arsenal.pdf

https://portswigger.net/daily-swig/black-hat-europe-new-tool-offers-metasploit-like-framework-for-hacking-into-drones

More from this blog

Penetration Test、Python、Weaponization

721 posts

微信 smartcat9999 反欺詐Anti-Fraud 反洗錢Anti-Money Laundering 反逃稅Anti-Tax Evasion 滲透測試Penetration Test 武器化Weaponization