SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Hamza Abusalah has an SBA paper accepted at Eurocrypt 2019 taking place in Darmstadt, Germany from May 19-23, 2019.Paper: Reversible Proofs of Sequential Work We are also excited to announce that the paper “XCLAIM: Trustless, Interoperable Cryptocurrency-Backed Assets” by Alexei Zamyatin is accepted at IEEE S&P… Read More
The first edition of sec4dev conference + bootcamp was hosted at TU Campus Gußhaus from February 25 -27, 2019 and welcomed more than 100 participants. After two all day bootcamps on Monday, the single track conference was kicked off on Tuesday morning with a keynote from Markus Sabadello on Decentralized… Read More
CONCORDIA is a major H2020 consortium to interconnect Europe’s Cybersecurity capabilities. It will establish a pilot for a Cybersecurity Competence Network and will lead the development of a common Cybersecurity Research & Innovation Roadmap for Europe. Press release
The sec4dev 2019 conference has officially started. The first day´s agenda was filled up with two all day boot camps. Thomas Konrad´s (SBA) participants learned how to hack themselves in the “Hack Yourself: Hands-On-Web Application Security from an Attacker´s perspective” boot camp. Philippe de Ryck (Pragmatic Web Security) introduced “A… Read More
Johanna Ullrich held a workshop at the first all female Hackathon at TU Wien on February 9, 2019. Women and Code is an initiative for women interested in coding/programming, front-end development and eager to learn something new. SBA supports Women and Code and their ambition to bring more women into… Read More
35 people attended the second SBA Security Meetup of 2019 held by Thomas Konrad. Participants explored some pretty smart techniques to achieve a balance between confidentiality/integrity and availability requirements, and how these techniques can help you solve a number of other problems. Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. ∞
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. ∞