SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
The Horizon 2020 Research and Innovation Action MyHealth – MyData (MHMD) developed an open biomedical information network centered on the connection between organizations and individuals. Key elements of this innovation, implemented through this new model, include: Privacy-preserving data publishing via synthetic data Blockchain Dynamic consent Personal… Read More
The kick-off meeting of the FFG BRIDGE 1 project GASTRIC (Gene Anonymisation and Synthetisation for Privacy) took place on July 15th, 2020 at SBA Research. The GASTRIC project addresses the challenge to preserve the privacy of individuals taking part in microbiome studies… Read More
“TikTok collects a lot of user data. But other apps do that as well. You can use such data to influence political developments in other countries. […]” Read the full article at futurezone.at. Read More
The paper “Supporting complex decision making by semantic technologies“ by Stefan Fenz has won the best in-use paper award at ESWC20. ESWC20 was held online from June 2 – June 4, 2020. Congrats! You can find the paper here.
Digital approaches to proximity tracing on Smartphones are expected to contribute significantly to master the Covid-19 pandemic. Several approaches went live since May, and a heated discussion on centralised versus decentralised approaches arose. Beyond technical considerations, like their underlying working principle, constraints due to dependencies on the underlying hardware and… Read More
For many companies, the crisis was a rapid driver of digitalization – as a result, the hacker scene has experienced another real upswing. The topic of IT security has thus also gained in importance. As usual, participants will be provided with exciting community news, expert interviews, trends and the most… Read More
This document provides an overview of the architecture of the L-band Digital Aeronautical Communications System (LDACS), which provides a secure, scalable and spectrum efficient terrestrial data link for civil aviation. LDACS is a scheduled, reliable multi-application cellular broadband system with support for IPv6. N.Mäurer, T.Gräupl, C.Schmitt: L-band Digital Aeronautical Communications… Read More
Monsta FTP 2.10.1 or below is prone to a stored cross-site scripting vulnerability in the language setting due to insufficient output encoding. Read More
Monsta FTP 2.10.1 or below is prone to a server-side request forgery vulnerability due to insufficient restriction of the web fetch functionality. This allows attackers to read arbitrary local files and interact with arbitrary third-party services. Read More
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments. Read More
Together with sipgate and ISMK Stralsund, Gabriel Gegenhuber, researcher at SBA Research and University of Vienna, and Michael Pucher, researcher at SBA research, discovered and investigated a vulnerability in the Voice of LTE (VoLTE) stack that is broadly used within MediaTek-based smartphones. ∞
In the Mediatek modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. ∞