SBA Research is a research center for Information Security funded partly by the national initiative for COMET Competence Centers for Excellent Technologies.
On behalf of the Austrian Federal Ministry of Transport, Innovation and Technology (bmvit), a research team consisting of cbased (Community-Based Innovation Systems), SBA Research, and the Vienna University of Economics and Business (WU), examines the impact of the data protection legislation (EU-DSGVO), which will become effective May 2018, on Big… Read More
Tomasz Miksa has become the chair of the newly endorsed DMP Common Standards working group at the Research Data Alliance. He will present the goals of the group for the next 18 months at the 10th Research Data Alliance Plenary in Montreal, Canada. The group brings together a broad… Read More
Dimitris Simos is invited to give a colloquium talk at the University of Bergamo, Italy regarding “combinatorial methods and algorithms in security testing”.
Markus Klemen @ e-day 2016 SBA Research contributed two talks to this years’ e-day of the Austrian Chamber of Commerce. Markus Klemen talked about loyalty and motivation of employees with regard to ethical issues and psychological considerations. Peter Kieseberg described current social engineering tricks and attack vectors. Peter… Read More
SQL injection vulnerability in the RXTEC RXAdmin Login Page allows remote attackers to execute arbitrary SQL commands via several HTTP parameter. Read More
Polycom BToE Connector up to version 2.3.0 allows unprivileged windows users to execute arbitrary code with SYSTEM privileges. We recommend to update Polycom BToE Connector to version 3.0.0 or later. For further details, see the full security advisory. Read More
The vulnerability is caused by a buffer overflow in a memcpy operation when parsing specailly crafted KNXnet/IP packets in the Group messages monitor (aka. Falcon). An according proof-of-concept exploit which was tested on an affected ETS version installed on a Windows XP SP3 can be found below. The proof-of-concept exploit generates the UDP packet which triggers the vulnerability and should at least crash the application (it requires python and scapy to run). Read More
Markus Klemen erläutert am heutigen VISI!T Symposium (Verwaltung integriert sichere Informationstechnologie) die Herausforderungen der aktuell laufenden KIRAS Studie zum Entwurf eines Zertifizierungsstandards für E-Government. Der Grundgedanke des Symposiums “Verwaltung integriert sichere Informationstechnologie” (ViS!T) ist die multilaterale Diskussion des Themas IT-Sicherheit (in Strategien, IT-Vorhaben, Projekten) in den vier deutschsprachigen europäischen Staaten Deutschland,… Read More
Am 4. Juni 2014 diskutiert Markus Klemen mit Martin Köhler vom Austrian Institute of Technology (AIT) und Allan Hanbury von der Technischen Universität Wien über Big Data Herausforderungen, Stand der Technik und Wissenschaft sowie sicherheitstechnischen Überlegungen bei der IMAGINE14 Veranstaltung des BMVIT, der FFG, der OCG sowie von EUTEMA. Nähere… Read More
Edgar Weippl has been reelected Chair of IFIP Working Group 8.4. Established in 2001, the working group provides a reference point and a focus for multi-disciplinary research and practice in E-Business Information Systems. The intention is to extend the IFIP community’s focus on E-Business to recognize, acknowledge and facilitate research… Read More