Floragasse 7 – 5th floor, 1040 Vienna

SBA Research is a research center for Information Security
funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.

News

SBA Security Advisory – phpWhois – PHP Code Injection (CVE-2015-5243)

phpWhois and some of its forks in versions before 5.1.0 are prone to a code injection vulnerability due to insufficient sanitization of returned WHOIS data. This allows attackers controlling the WHOIS information of a requested domain to execute arbitrary PHP code in the context of the application. We recommend to update phpWhois to version jsmitty12: 5.1.0 or later. For further details, see the full security advisory. Read More
Logo SBA Security Advisories

Study on EU-DSGVO

On behalf of the Austrian Federal Ministry of Transport, Innovation and Technology (bmvit), a research team consisting of cbased (Community-Based Innovation Systems), SBA Research, and the Vienna University of Economics and Business (WU), examines the impact of the data protection legislation (EU-DSGVO), which will become effective May 2018, on Big… Read More

SBA Research @ e-day 2016

Markus Klemen @ e-day 2016 SBA Research contributed two talks to this years’ e-day of the Austrian Chamber of Commerce. Markus Klemen talked about loyalty and motivation of employees with regard to ethical issues and psychological considerations. Peter Kieseberg described current social engineering tricks and attack vectors. Peter… Read More

SBA Security Advisory – KNX management software ETS – remote code execution vulnerability (CVE-2015-8299)

The vulnerability is caused by a buffer overflow in a memcpy operation when parsing specailly crafted KNXnet/IP packets in the Group messages monitor (aka. Falcon). An according proof-of-concept exploit which was tested on an affected ETS version installed on a Windows XP SP3 can be found below. The proof-of-concept exploit generates the UDP packet which triggers the vulnerability and should at least crash the application (it requires python and scapy to run). Read More
Logo SBA Security Advisories

Markus Klemen zum Thema Secure E-Government am VIS!T Symposium

Markus Klemen erläutert am heutigen VISI!T Symposium (Verwaltung integriert sichere Informationstechnologie) die Herausforderungen der aktuell laufenden KIRAS Studie zum Entwurf eines Zertifizierungsstandards für E-Government. Der Grundgedanke des Symposiums “Verwaltung integriert sichere Informationstechnologie” (ViS!T) ist die multilaterale Diskussion des Themas IT-Sicherheit (in Strategien, IT-Vorhaben, Projekten) in den vier deutschsprachigen europäischen Staaten Deutschland,… Read More