<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure Business Austria &#187; News</title>
	<atom:link href="http://www.sba-research.org/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sba-research.org</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 10:39:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Web Salon 2012</title>
		<link>http://www.sba-research.org/2012/02/01/web-salon-2012/</link>
		<comments>http://www.sba-research.org/2012/02/01/web-salon-2012/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 13:46:46 +0000</pubDate>
		<dc:creator>mleithner</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=2081</guid>
		<description><![CDATA[Heute (1. Februar) um 19 Uhr bietet Manuel Leithner im Rahmen des Web Salon 2012, veranstaltet von saferinternet.at, in Form eines Webinars praktische Tips und Informationen zum Thema Sicherheit auch für Computerunvertraute an. Die Teilnahme ist frei, Anmeldung jedoch erforderlich.]]></description>
			<content:encoded><![CDATA[<p>Heute (1. Februar) um 19 Uhr bietet <a href="http://www.sba-research.org/team/researchers/manuel-leithner/" title="Manuel Leithner">Manuel Leithner</a> im Rahmen des <a href="http://www.saferinternet.at/news/news-detail/archive/2012/jaenner/30/article/web-salon-2012-239/" title="Web Salon 2012">Web Salon 2012</a>, veranstaltet von saferinternet.at, in Form eines Webinars praktische Tips und Informationen zum Thema Sicherheit auch für Computerunvertraute an. Die Teilnahme ist frei, Anmeldung jedoch erforderlich.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2012/02/01/web-salon-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BSidesVienna Public Transport Talk</title>
		<link>http://www.sba-research.org/2012/01/23/bsidesvienna-public-transport-talk/</link>
		<comments>http://www.sba-research.org/2012/01/23/bsidesvienna-public-transport-talk/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 12:04:22 +0000</pubDate>
		<dc:creator>mleithner</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[news]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=2055</guid>
		<description><![CDATA[At BSidesVienna 2012, Manuel Leithner gave a talk on public transport titled &#8220;Hackers on a train &#8211; Toying with transportation&#8221;, detailing equipment and possible flaws in the on-board network infrastructure and ticketing system of WESTbahn.]]></description>
			<content:encoded><![CDATA[<p>At <a href="http://www.securitybsides.com/w/page/48231836/BSidesVienna2012" title="BSidesVienna 2012" target="_blank">BSidesVienna 2012</a>, <a href="http://www.sba-research.org/team/researchers/manuel-leithner/" title="Manuel Leithner" target="_blank">Manuel Leithner</a> gave a talk on public transport titled &#8220;Hackers on a train &#8211; Toying with transportation&#8221;, detailing equipment and possible flaws in the on-board network infrastructure and ticketing system of WESTbahn.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2012/01/23/bsidesvienna-public-transport-talk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sieg beim iCTF 2011</title>
		<link>http://www.sba-research.org/2011/12/03/sieg-beim-ictf-2011/</link>
		<comments>http://www.sba-research.org/2011/12/03/sieg-beim-ictf-2011/#comments</comments>
		<pubDate>Sat, 03 Dec 2011 02:40:26 +0000</pubDate>
		<dc:creator>mleithner</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1975</guid>
		<description><![CDATA[Das Team der TU Wien &#8220;We_0wn_Y0u&#8221; konnte beim iCTF 2011 unter der Leitung von Adrian Dabrowski den Sieg erringen. In einem bis zuletzt spannenden neunstündigem Wettbewerb gegen über 85 internationale Mitbewerberteams stellten auch Martin Mulazzani, Peter Frühwirt und Manuel Leithner als Vertreter von SBA Research ihre Fähigkeiten rund um Angriffe auf und Verteidigung von IT-Infrastruktur [...]]]></description>
			<content:encoded><![CDATA[<p>Das Team der TU Wien &#8220;We_0wn_Y0u&#8221; konnte beim <a title="iCTF 2011 homepage" href="http://ictf.cs.ucsb.edu/index.php" target="_blank">iCTF 2011</a> unter der Leitung von Adrian Dabrowski den Sieg erringen. In einem bis zuletzt spannenden neunstündigem Wettbewerb gegen über 85 internationale Mitbewerberteams stellten auch <a title="Martin Mulazzani" href="http://www.sba-research.org/team/researchers/martin-mulazzani/">Martin Mulazzani</a>, <a title="Peter Frühwirt" href="http://www.sba-research.org/team/researchers/peter-fruhwirt/">Peter Frühwirt</a> und <a title="Manuel Leithner" href="http://www.sba-research.org/team/researchers/manuel-leithner/">Manuel Leithner</a> als Vertreter von SBA Research ihre Fähigkeiten rund um Angriffe auf und Verteidigung von IT-Infrastruktur unter Beweis.</p>
<p>Das finale Scoreboard ist <a title="iCTF 2011 Scoreboard" href="http://scoreboard.ictf2011.info/" target="_blank">hier</a> ersichtlich. Mit einem breit gefächertem internationalen Teilnahmefeld (u.A. USA, Russland und China) zählt die iCTF zu den größten Capture the Flag-Contests weltweit. <a href="http://www.sba-research.org/2011/12/03/sieg-beim-ictf-2011/hacker03/">Foto</a></p>
<p>Pressecoverage von <a title="Der Standard" href="http://derstandard.at/1322872932446/ICTF-Team-der-TU-Wien-gewann-internationalen-Hacker-Wettbewerb" target="_blank">Standard</a>, <a title="Die Presse" href="http://diepresse.com/home/techscience/internet/sicherheit/714387/TU-Wien-gewinnt-internationalen-HackerWettbewerb?_vl_backlink=/home/techscience/index.do" target="_blank">Presse</a>, <a title="Kurier" href="http://kurier.at/techno/4466995.php" target="_blank">Kurier</a>, <a title="Krone" href="http://www.krone.at/Digital/TU_Wien_gewinnt_internationalen_Hacker-Wettbewerb-Grosser_Erfolg-Story-304460" target="_blank">Krone</a>, <a title="Österreich" href="http://www.oe24.at/digital/TU-Wien-Team-gewann-Hacker-Wettbewerb-ICTF/48476695" target="_blank">Österreich</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/12/03/sieg-beim-ictf-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure development of web-applications – Secure Coding I + II</title>
		<link>http://www.sba-research.org/2011/09/29/secure-development-of-web-applications-%e2%80%93-secure-coding-i-ii/</link>
		<comments>http://www.sba-research.org/2011/09/29/secure-development-of-web-applications-%e2%80%93-secure-coding-i-ii/#comments</comments>
		<pubDate>Thu, 29 Sep 2011 13:27:44 +0000</pubDate>
		<dc:creator>lzechner@</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1938</guid>
		<description><![CDATA[Severin Winkler is holding several lessons on secure development of web-applications in cooperation with CON•ECT. The core components of these talks are the top ten security leaks of web applications in 2010 identified by OWASP. The lessons include advanced security topics necessary for the development of modern web-applications and offer a focus on attack scenarios and counter strategies. [...]]]></description>
			<content:encoded><![CDATA[<p>Severin Winkler is holding several lessons on secure development of web-applications in cooperation with CON•ECT. The core components of these talks are the top ten security leaks of web applications in 2010 identified by OWASP. The lessons include advanced security topics necessary for the development of modern web-applications and offer a focus on attack scenarios and counter strategies. (<a href="http://www.conect.at/de/conect_eventmanagement/veranstaltungen/business_academy/detaildarstellung.html?no_cache=1&amp;tx_posseminar_pi%5Buid%5D=590" target="_blank">mehr&#8230;</a>)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/09/29/secure-development-of-web-applications-%e2%80%93-secure-coding-i-ii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>USENIX Security &#8217;11: Dark Clouds on the Horizon</title>
		<link>http://www.sba-research.org/2011/06/22/usenix-security-11-dark-clouds-on-the-horizon/</link>
		<comments>http://www.sba-research.org/2011/06/22/usenix-security-11-dark-clouds-on-the-horizon/#comments</comments>
		<pubDate>Wed, 22 Jun 2011 09:27:31 +0000</pubDate>
		<dc:creator>mmulazzani</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1718</guid>
		<description><![CDATA[In August we will present our work on cloud storage security at the 20th USENIX Security Symposium in San Francisco. The paper, in essence, outlines new attacks on cloud storage services that use server-side data deduplication. It includes a security analysis of Dropbox, a popular cloud storage service. By manipulating the client software unauthorized data [...]]]></description>
			<content:encoded><![CDATA[<p>In August we will present our work on cloud storage security at the 20th USENIX Security Symposium in San Francisco. The paper, in essence, outlines new attacks on cloud storage services that use server-side data deduplication. </p>
<p>It includes a security analysis of Dropbox, a popular cloud storage service. By manipulating the client software unauthorized data access becomes possible, if the hash values of the files are known to an attacker. This attack is completely undetectable to the victim, and novel compared to recent attacks discussed in the media. Data possession proofs which have been used so far in the context of assessing whether a cloud storage operator is still in possession of a file are the only countermeasure.</p>
<p>We further define online slack space as a method to hide data in the cloud to thwart forensic investigations. Compared to regular file slack all files are stored in the cloud without leaving any evidence on local persistent storage.</p>
<p>You can find the paper here: <a href="http://www.sba-research.org/wp-content/uploads/publications/dropboxUSENIX2011.pdf">Dark Clouds on the Horizon: Using Cloud Storage as Attack Vector and Online Slack Space</a>. We have contacted Dropbox and they implemented countermeasures for our attacks while investigating the use of data possession proofs on the client side. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/06/22/usenix-security-11-dark-clouds-on-the-horizon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Leak in Tor for Android (Orbot)</title>
		<link>http://www.sba-research.org/2011/05/02/leak-in-tor-for-android-orbot/</link>
		<comments>http://www.sba-research.org/2011/05/02/leak-in-tor-for-android-orbot/#comments</comments>
		<pubDate>Mon, 02 May 2011 15:35:44 +0000</pubDate>
		<dc:creator>mleithner</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1667</guid>
		<description><![CDATA[While performing traffic analysis on the current development version of Orbot, the official Android for Tor app, Manuel Leithner (Junior Researcher, SBA Research gGmbH) discovered that certain types of traffic (including VPN, GPS and videos) were not tunnelled through Tor. He subsequently developed a patch that enables full and enforced transparent proxying for all TCP [...]]]></description>
			<content:encoded><![CDATA[<p>While performing traffic analysis on the current development version of <a href="http://www.torproject.org/docs/android.html.en">Orbot</a>, the official Android for Tor app, Manuel Leithner (Junior Researcher, SBA Research gGmbH) discovered that certain types of traffic (including VPN, GPS and videos) were not tunnelled through Tor. He subsequently developed a <a href="https://lists.mayfirst.org/pipermail/guardian-dev/2011-May/000246.html">patch</a> that enables full and enforced transparent proxying for all TCP and DNS traffic through the anonymisation service.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/05/02/leak-in-tor-for-android-orbot/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IEEE Internet Computing Special Issue on Security and Privacy in Social Networks</title>
		<link>http://www.sba-research.org/2011/02/02/ieee-internet-computing-special-issue-on-security-and-privacy-in-social-networks/</link>
		<comments>http://www.sba-research.org/2011/02/02/ieee-internet-computing-special-issue-on-security-and-privacy-in-social-networks/#comments</comments>
		<pubDate>Wed, 02 Feb 2011 15:46:08 +0000</pubDate>
		<dc:creator>mhuber</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1356</guid>
		<description><![CDATA[Our manuscript &#8220;Friend-in-the-middle Attacks: Exploiting Social Networking Sites for Spam&#8221; has been accepted for the upcoming special issue on Security and Privacy in Social Networks in the IEEE Journal of Internet Computing in May/Jun 2011. Preprint is available here. In this article we have introduced friend-in-the-middle (FITM) attacks which are active eavesdropping attacks against social [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Our manuscript &#8220;Friend-in-the-middle Attacks: Exploiting Social Networking Sites for Spam&#8221; has been accepted for the upcoming special issue on Security and Privacy in Social Networks in the IEEE Journal of Internet Computing in May/Jun 2011. <a href="http://www.sba-research.org/wp-content/uploads/publications/FITM_InternetComputing_preprint.pdf">Preprint is available here</a>.</p>
<p style="text-align: justify;">In this article we have introduced friend-in-the-middle (FITM) attacks which are active eavesdropping attacks against social networking sites. By cloning a user’s authentication cookie which is transmitted in an unencrypted way, it becomes possible to completely impersonate the user. This can then be used to collect sensitive information in an automated fashion which ultimately enables large context-aware spam campaigns that propagate via social phishing. FITM attacks are applicable to the great majority of currently deployed SNSs, such as Facebook, Friendster, and Orkut. Based on FITM attacks we described three subsequent exploits: (1) Friend injection, (2) Application injection, and (3) Social engineering. We furthermore evaluated the impact of a large-scale spam attack on basis of FITM attacks. We therefore set-up a Tor exit node and analyzed the passing through HTTP traffic. Our experiments showed that finding possible FITM attack seeds for spam campaigns is cheap regarding time and hardware resources. Our attack simulation results furthermore suggest that based on the 4000 possible Facebook attack seeds we observed within two weeks, ~300.000 users could have been targeted with context-aware spam.</p>
<p style="text-align: justify;">There are a number of limited protection strategies available to social networking users, such as using browser extensions such as <a href="https://www.eff.org/https-everywhere">EFF HTTPS Everywhere</a>. The Tor browser bundles include the EFF HTTPS Everywhere extension <a href="https://blog.torproject.org/blog/tor-browser-bundle-updates">since May 2010</a>. Social networking providers ultimately have to protect their users against FITM attacks by securing the communication channels of their services with HTTPS. At the time of writing <a href="http://blog.facebook.com/blog.php?post=486790652130">Facebook has announced </a>that they will offer optional HTTPS support for their web service. We strongly advice users to make use of this option once it will become available to everyone.</p>
<p style="text-align: justify;"><a href="http://ieeexplore.ieee.org/xpl/freeabs_all.jsp?arnumber=5696718">Entry in IEEE Xplore</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/02/02/ieee-internet-computing-special-issue-on-security-and-privacy-in-social-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Information Security Knowledge Management Survey</title>
		<link>http://www.sba-research.org/2011/01/12/information-security-knowledge-management-survey/</link>
		<comments>http://www.sba-research.org/2011/01/12/information-security-knowledge-management-survey/#comments</comments>
		<pubDate>Wed, 12 Jan 2011 12:54:07 +0000</pubDate>
		<dc:creator>sfenz</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1318</guid>
		<description><![CDATA[We kindly ask you to participate in our information security knowledge management survey. The survey is conducted by publicly-funded research institutions SBA Research (AT), Newcastle University (UK), and Vienna University of Technology (AT). We conduct the survey to explore potential ways of enabling companies and professionals to share information security knowledge through the application of [...]]]></description>
			<content:encoded><![CDATA[<p>We kindly ask you to participate in our information security knowledge management survey. The survey is conducted by publicly-funded research institutions SBA Research (AT), Newcastle University (UK), and Vienna University of Technology (AT). We conduct the survey to explore potential ways of enabling companies and professionals to share information security knowledge through the application of collaborative semantic web technologies. The aggregated survey results will be published within publically-accessible research publications.</p>
<p>Survey: <a href="http://www.sba-research.org/survey/index.php?sid=73314">http://www.sba-research.org/survey/index.php?sid=73314</a></p>
<p>Thank you for your support.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2011/01/12/information-security-knowledge-management-survey/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CCS &amp; AISec</title>
		<link>http://www.sba-research.org/2010/10/18/ccs-aisec/</link>
		<comments>http://www.sba-research.org/2010/10/18/ccs-aisec/#comments</comments>
		<pubDate>Mon, 18 Oct 2010 07:58:48 +0000</pubDate>
		<dc:creator>sschrittwieser</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1308</guid>
		<description><![CDATA[We are attending CCS 2010 in Chicago and present a poster and a paper at the AISec Workshop, http://www.aisec.info.]]></description>
			<content:encoded><![CDATA[<p>We are attending CCS 2010 in Chicago and present a poster and a paper at the AISec Workshop, <a href="http://www.aisec.info" target="_blank">http://www.aisec.info</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/10/18/ccs-aisec/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;INFORM&#8221; awarded 2nd place</title>
		<link>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/</link>
		<comments>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/#comments</comments>
		<pubDate>Wed, 23 Jun 2010 10:15:40 +0000</pubDate>
		<dc:creator>mmulazzani</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.sba-research.org/?p=1196</guid>
		<description><![CDATA[﻿﻿The SBA FIT-IT proposal &#8220;INFORM&#8221; (Internet Forensic Framework) has been awarded the 2nd place in the competition for the best proposal among all proposals for &#8220;Trust in IT-Systems&#8221; in 2009. The goal of &#8220;INFORM&#8221; is to study current challenges in computer forensics and to produce tools that enricht the toolset of a forensic analysist. In [...]]]></description>
			<content:encoded><![CDATA[<p>﻿﻿The SBA FIT-IT proposal &#8220;INFORM&#8221; (Internet Forensic Framework) has been awarded the 2nd place in the competition for the best proposal among all proposals for &#8220;Trust in IT-Systems&#8221; in 2009.</p>
<p>The goal of &#8220;INFORM&#8221; is to study current challenges in computer forensics and to produce tools that enricht the toolset of a forensic analysist. In the traditional approach, the seizure of the suspects hard drives is used to analyse traces of malicious activities. With the widesread availability of hard drive encryption tools, online file storate systems and bootable Linux distributions that leave no traces on the hard drive, new tools and procedures are needed to support the evidence collection process. Social networks and anonymization networks pose further challenges for online forensics that will be adressed by &#8220;INFORM&#8221;.</p>
<p>The news report on <a href="http://futurezone.orf.at/stories/1651626/" target="_blank">futurezone</a> and <a href="http://derstandard.at/1276413772355/Onlineverbrecher-automatisch-verstehen" target="_blank">derstandard</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.sba-research.org/2010/06/23/inform-awarded-2nd-place/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

