SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
On June 17, SBA Research and its partner Condignum hosted the second edition of the sec4dev Dialogues event series. Security for Software Developers is essential. The current threat landscape and security incidents in recent years make it clear: the topic is more relevant than ever. This… Read More
Cyberduck and Mountain Duck improper handle TLS certificate pinning for
untrusted certificates (e.g., self-signed), since the certificate's
fingerprint is stored as SHA-1, although SHA-1 is considered weak and
should be replaced with SHA-256 or SHA-512. ... Read More
Cyberduck and Mountain Duck improper handle TLS certificate pinning for
untrusted certificates (e.g., self-signed), unnecessary installing it to the
Windows Certificate Store of the current user without any restrictions.
This potentially allows attackers to bypass certificate-based authentication
or authorization of other programs that trust this certificate store. ... Read More
Spusu is an Austrian mobile network operator and operates as a mobile virtual network operator (MVNO) using the Drei network. Spusu offers premium-quality mobile plans at affordable prices. Since 2021, Spusu has also been fulfilling its role as a technology leader by expanding regional… Read More
In mid-May, Jeanine Lefèvre, head of Office of Equal Opportunities at SBA Research, attended the important Viennese conference on Excellent research requires the right framework which set the tone for non-discriminatory research. Around 80 experts in science, politics, and gender equality came together to discuss strategies for… Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. Read More
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Read More
In mid-May, our colleague Reinhard Kugler, applied research consultant at SBA Research, gave a talk on Tracing the Invisible: how to create Observability on Edge Devices with eBPF. His presentation focused on tracing protocols in embedded systems by instrumenting the kernel. He discussed protocols such as SPI, I2C, and… Read More
For over 25 years, Infraprotect has supported companies in the fields of crisis, emergency, risk, and security management, as well as crisis communication and R&D. The company provides tailored crisis management solutions to clients from a variety of sectors, including manufacturing, critical infrastructure, and public services. Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. ∞
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. ∞