News

CSAW'20 Best Paper Finalist: TeeRex: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX Enclaves

Das Paper „TeeRex: Discovery and Exploitation of Memory Corruption Vulnerabilities in SGX Enclaves“ von Tobias Cloosters, Michael Rodler und Lucas Davi wurde von CSAW Europe in die Finalrunde der zehn besten Paper des Jahres 2020 aufgenommen.

New Technology Fixes Security Vulnerabilities in Smart Contracts

Smart Contracts have made Ethereum the world's second largest crypto currency. However, recent criminal attacks exploited errors in the programmed contracts. Our research group, together with partners from industry, has developed and evaluated a technique that enables published smart contracts to be improved instantly.

New Technology Fixes Security Vulnerabilities in Smart Contracts

Smart contracts have made Ethereum the world's second largest crypto currency. However, recent criminal attacks have exploited errors in the contracts programmed. Together with partners, the paluno working group of Prof. Lucas Davi has developed and evaluated a technique that enables published smart contracts to be improved instantly.

New Research Assistant

In October Christian Niesler joined the group of Prof. Lucas Davi.

Lectures in the Winter Term 2020/2021

We have two lectures and a project group in the winter term.

Danger to Sensitive Data

In the course of our research on Trusted Execution Environments we discovered multiple vulnerabilities in security-critical software running in protected memory areas of modern Intel processors. In the worst-case scenario, harmful actions could be infiltrated into sensitive programs, e.g. into the software of fingerprint scanners. With the help of our team the affected vendors already patched their software.
Fingerprint Scanner

Danger to Sensitive Data

Security experts from paluno – The Ruhr Institute for Software Technology at the University of Duisburg-Essen revealed multiple vulnerabilities in security-critical software running in protected memory areas of modern Intel processors. In the worst-case scenario, harmful actions could be infiltrated into sensitive programs, e.g. into the software of fingerprint scanners. With the help of the researchers many vendors already patched their software.

DFG Funding for Research Project in the Field of Nano-Security

"RAINCOAT - Randomization in Secure Nano-Scale Microarchitectures" is a joint project of Lucas Davi and Tim Güneysu working together in the cluster of excellence CASA.

Sicherheitslücke in IP-Webcam gefunden

In der Bachelorarbeit von Lasse Bruns wurde die Sicherheit von IP-Webcams untersucht. IP-Webcams erlauben es dem Benutzer, über das Internet das Kamerabild abzurufen. Hierbei wurde eine Lücke festgestellt, die es erlaubt hat, ein unverschlüsseltes Backup der Konfigurationsdateien herunterzuladen. Dieses Backup enthält alle Einstellungen der Kamera, aber auch die Nutzernamen und Passwörter.