SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
Adrian Dabrwoski received the award for the best student paper at ACSAC 2014 for his paper. You can find a preprint here. Adrian Dabrowski, Nicola Pianta, Thomas Klepp, Martin Mulazzani, and Edgar Weippl. Imsi-Catch Me If You Can: Imsi-Catcher-Catchers. In Proceedings of the 30th Annual Computer Security Applications Conference… Read More
Markus Klemen was invited to participate as panelist in the inagurate (ISC)2 Security Congress EMEA 2014, which took place from 9th to 10th of December 2014 in London, UK. The Panel was about “Educating the Future: What Can Employers be Doing?”. (ISC)2 is the global, not-for-profit leader in educating and certifying information security professionals throughout… Read More
“That would have never occurred to experts.” – Opportunities and Limits of Digital Citizen Participation Today the event “Digital Discourse | Insights into Lived Participation”, supported by SBA Research and organized by Liquid Participation, took place. What expectations are linked to participatory online processes? How is the process design for… Read More
ESORICS 2015 will be held in Vienna from September 21-25. SBA Research is the local organizer, Edgar Weippl serves together with Peter Y A Ryan (University of Luxembourg) as Program Chair. Submission Deadline: April 4, 2015 … Read More
For the second time in a row the Best Paper Award of the International Conference on Preservation of Digital Objects (iPRES 2014) has been awarded to the researchers from SBA. In this year´s edition… Read More
SBA Research participates with three topics at the European Researchers’ Night: Security on the Internet: Facebook, WhatsApp, Instagramm & Co. Hollywood Hacking: A Reality Check Digital Forensics – CSI in IT… Read More
What is Shellshock? On 24/09/2014, a security vulnerability was published as CVE-2014-6271 (also Shellshock or Bashbleed). The vulnerability is in the command line software bash which is used in practically all Linux systems as the default shell. Due to an error when parsing environment variables, it is possible to execute… Read More
New paper “Send and Pretend: Exploiting Transcript Consistency Issues in End-to-End Encrypted Group Chats”, was recently accepted for the 35th USENIX Security Symposium. The paper is a collaboration between SBA, the University of Vienna, and the Interdisciplinary Transformation University Austria (IT:U). It was authored by Gabriel K. Gegenhuber, Moritz Grefner, Maximilian Günther, Matthäus Wininger, David Schmidt, and Aljosha Judmayer. ∞
The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets (CVE-2026-16969), custom attributes (CVE-2026-18360) and datastore upload (CVE-2026-18361) functions. ∞
We are proud to celebrate the outstanding achievements of our researchers, who were recognized at the University of Vienna Faculty of Computer Science's Best-of-the-Best Awards on June 24. ∞