SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
At Digital Days 2020 on September 30 and October 1, everything will revolve around new trends and the most burning issues surrounding FutureTech and digitization. With respect to the current situation the main stage program will be streamed live from the Erste Campus. Under the motto “Digital Capital of People”,… Read More
The ongoing global pandemic has caused a rising demand for automated contact tracing solutions. While it is a desirable goal to automatically notify persons who may have been in contact with an infected person, this comes with many problems for Security and Privacy. This year´s workshop will cover these problems… Read More
As guests in the Discover CEE blog from Raiffeisen Bank International Stefan Jakoubi and Philipp Reisinger discuss benefits and risks, the shared responsibility model and their top three takeaways. Read up on the details here!
The ARES 2020 Conference, hosted by SBA Research, is currently taking place as all-digital conference. We are very happy to presenting a diverse program to more than 300 participants from over 43 countries, including: 27 full papers (acceptance rate: 21.26%) and 6 short papers 82 workshop… Read More
SBA Research is happy to announce that we are now part of the interactive NGI stakeholder Map. The NGI Map provides information about active participants in the European NGI initiative and is one pillar in advancing the NGI ecosystem. The NGI initiative funds European innovative research projects that make… Read More
“From robotics and sensor technology to questions of biology and economics, all the way to safety, ethical and social implications, everything comes together here.” With this quote Thomas Neubauer introduces the relevance of resilience, digital agriculture and security in an interview with “Der Standard” & “… Read More
While taking a university course on security, Philipp Danzinger discovered two critical related vulnerabilities in KeePassRPC, an addon for the popular password manager KeePass. Both vulnerabilities allow a malicious web site to read and leak (unlocked) KeePass databases, while being very hard or impossible to detect, provided the KeePassRPC addon is… Read More
The System Administrator Appreciation Day is an annual commemoration for system administrators. It was invented by Ted Kekatos and is held on the last Friday in July since 2000. Kekatos was inspired by a Hewlett-Packard ad by employees thanking a system administrator with flowers and fruit baskets for installing new… Read More
Edgar Weippl discusses points of criticism regarding data security, use and distribution of the social video-sharing network TikTok in his interview with austrian news TV Café Puls. Watch the interview at Café Puls.
In the online attack / defense CTF competition ENOWARS4, We_0wn_Y0u got the 2nd place out of 154 teams! A big thanks to ENOFLAG and TU Berlin for hosting the event! Congratulations to all members of… Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. ∞
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. ∞