SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
The vulnerability is caused by a buffer overflow in a memcpy operation when parsing specailly crafted KNXnet/IP packets in the Group messages monitor (aka. Falcon). An according proof-of-concept exploit which was tested on an affected ETS version installed on a Windows XP SP3 can be found below. The proof-of-concept exploit generates the UDP packet which triggers the vulnerability and should at least crash the application (it requires python and scapy to run). Read More
Die Mitarbeiter und Mitarbeiterinnen von SBA Research legten zusammen, um für unbegleitete jugendliche Flüchtlinge, die im Laura Gatner Haus der Diakonie leben, Winterjacken und Winterschuhe für die kalte Jahreszeit besorgen zu können. Im Rahmen der Weihnachtsfeier des Laura Gatner Hauses wurde der Scheck im Wert von 3710 € zusammen mit… Read More
“Weitaus ernsthafter ist ein Projekt der Wiener IT-Sicherheitsexperten Katharina Krombholz und Adrian Dabrowski. Sie wollen mit dem “P3F”-Projekt das Problem der “analogen Lücke” lösen. … Krombholz und Dabrowski haben schon Kontakte zu großen IT-Konzernen aufgenommen und ihr Projekt beispielsweise bei Facebook vorgestellt.” derStandard.at
Dimitris Simos, Bernhard Garn of the research team and Severin Winkler, Peter Aufner, Andreas Bernauer of the security testing team of SBA Research found a RXSS vulnerability in W3C online tidy services using combinatorial testing methodologies and demonstrated its applicability to web application security testing. These novel research methods have… Read More
Adrian Dabrwoski received the award for the best student paper at ACSAC 2014 for his paper. You can find a preprint here. Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, and Edgar Weippl. Imsi-Catch Me If You Can: Imsi-Catcher-Catchers. In Proceedings of the 30th Annual Computer Security Applications Conference… Read More
Lukasz Olejnik, INRIA Privatics, France gives a talk about “Introduction to transparency, privacy and security analyses of Real-Time Bidding”. Abstract Wednesday, December 10, 2014, 11.00 – 12.00 TU Wien, Seminarraum 2/253, Hauptgebäude (Karlsplatz 13) This event is hosted by the IEEE CS/SMCS Austria Chapter.
‘Edgar Weippl, Wissenschaftlicher Leiter des Wiener Forschungsinstituts für Informationssicherheit SBA Research lobt den Ansatz des Planspiels: “Der Schwerpunkt auf Optimierung der Kommunikation zwischen den Akteuren ist positiv zu betrachten…”‘ (futurezone)
Markus Klemen was invited to participate as panelist in the inagurate (ISC)2 Security Congress EMEA 2014, which took place from 9th to 10th of December 2014 in London, UK. The Panel was about “Educating the Future: What Can Employers be Doing?”. (ISC)2 is the global, not-for-profit leader in educating and certifying information security professionals throughout… Read More
The research on Combinatorial Security Testing (CST) by the MATRIS group of SBA Research is amongst the top five nominations for the Houska prize, Austria's largest private award for application-oriented research, in the category non-university research. ... ∞