<?xml version="1.0" encoding="UTF-8"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
<title>P281 - Sicherheit 2018 - Sicherheit, Schutz und Zuverlässigkeit</title>
<link href="http://dl.gi.de/handle/20.500.12116/20074" rel="alternate"/>
<subtitle/>
<id>http://dl.gi.de/handle/20.500.12116/20074</id>
<updated>2026-07-21T15:56:02Z</updated>
<dc:date>2026-07-21T15:56:02Z</dc:date>
<entry>
<title>Sicherheit 2018 - Sicherheit, Schutz und Zuverlässigkeit</title>
<link href="http://dl.gi.de/handle/20.500.12116/21007" rel="alternate"/>
<author>
<name/>
</author>
<id>http://dl.gi.de/handle/20.500.12116/21007</id>
<updated>2019-03-25T12:16:46Z</updated>
<published>2018-01-01T00:00:00Z</published>
<summary type="text">Sicherheit 2018 - Sicherheit, Schutz und Zuverlässigkeit
Langweg, Hanno; Meier, Michael; Witt, Bernhard C.; Reinhardt, Delphine
</summary>
<dc:date>2018-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>SDN Ro2tkits: A Case Study of Subverting A Closed Source SDN Controller</title>
<link href="http://dl.gi.de/handle/20.500.12116/16297" rel="alternate"/>
<author>
<name>Röpke, Christian</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/16297</id>
<updated>2019-02-01T13:57:05Z</updated>
<published>2018-01-01T00:00:00Z</published>
<summary type="text">SDN Ro2tkits: A Case Study of Subverting A Closed Source SDN Controller
Röpke, Christian
Langweg, Hanno; Meier, Michael; Witt, Bernhard C.; Reinhardt, Delphine
An SDN controller is a core component of the SDN architecture. It is responsible for managing an underlying network while allowing SDN applications to program it as required. Because of this central role, compromising such an SDN controller is of high interest for an attacker. A recently published SDN rootkit has demonstrated, for example, that a malicious SDN application is able to manipulate an entire network while hiding corresponding malicious actions. However, the facts that this attack targeted an open source SDN controller and applied a specific way to subvert this system leaves important questions unanswered: How easy is it to attack closed source SDN controllers in the same way? Can we concentrate on the already presented technique or do we need to consider other attack vectors as well to protect SDN controllers?

In this paper, we elaborate on these research questions and present two new SDN rootkits, both targeting a closed source SDN controller. Similar to previous work, the first one is based on Java reflection.
In contrast to known reflection abuses, however, we must develop new techniques as the existing ones can only be adopted in parts. Additionally, we demonstrate by a second SDN rootkit that an attacker is by no means limited to reflection-based attacks. In particular, we abuse aspect-oriented programming capabilities to manipulate core functions of the targeted system. To tackle the security issues raised in this case study, we discuss several countermeasures and give concrete suggestions to improve SDN controller security.
</summary>
<dc:date>2018-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Is MathML dangerous?</title>
<link href="http://dl.gi.de/handle/20.500.12116/16299" rel="alternate"/>
<author>
<name>Späth, Christopher</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/16299</id>
<updated>2019-02-01T13:57:05Z</updated>
<published>2018-01-01T00:00:00Z</published>
<summary type="text">Is MathML dangerous?
Späth, Christopher
Langweg, Hanno; Meier, Michael; Witt, Bernhard C.; Reinhardt, Delphine
HTML5 forms the basis for modern web development and merges different standards. One of these standards is MathML. It is used to express and display mathematical statements. However, with more standards being natively integrated into HTML5 the processing model gets inherently more complex.
In this paper, we evaluate the security risks of MathML. We created a semi-automatic test suite and studied the JavaScript code execution and the XML processing in MathML. We added also the Content-Type handling of major browsers to the picture. We discovered a novel way to manipulate the browser’s status line without JavaScript and found two novel ways to execute JavaScript code, which allowed us to bypass several sanitizers. The fact, that JavaScript code embedded in MathML can access session cookies worsens matters even more.
</summary>
<dc:date>2018-01-01T00:00:00Z</dc:date>
</entry>
<entry>
<title>Hashing of personally identifiable information is not sufficient</title>
<link href="http://dl.gi.de/handle/20.500.12116/16294" rel="alternate"/>
<author>
<name>Marx, Matthias</name>
</author>
<author>
<name>Zimmer, Ephraim</name>
</author>
<author>
<name>Mueller, Tobias</name>
</author>
<author>
<name>Blochberger, Maximilian</name>
</author>
<author>
<name>Federrath, Hannes</name>
</author>
<id>http://dl.gi.de/handle/20.500.12116/16294</id>
<updated>2019-02-01T13:57:05Z</updated>
<published>2018-01-01T00:00:00Z</published>
<summary type="text">Hashing of personally identifiable information is not sufficient
Marx, Matthias; Zimmer, Ephraim; Mueller, Tobias; Blochberger, Maximilian; Federrath, Hannes
Langweg, Hanno; Meier, Michael; Witt, Bernhard C.; Reinhardt, Delphine
It is common practice of web tracking services to hash personally identifiable information
(PII), e. g., e-mail or IP addresses, in order to avoid linkability between collected data sets of web
tracking services and the corresponding users while still preserving the ability to update and merge data
sets associated to the very same user over time. Consequently, these services argue to be complying
with existing privacy laws as the data sets allegedly have been pseudonymised. In this paper, we
show that the finite pre-image space of PII is bounded in such a way, that an attack on these hashes
is significantly eased both theoretically as well as in practice. As a result, the inference from PII
hashes to the corresponding PII is intrinsically faster than by performing a naive brute-force attack.
We support this statement by an empirical study of breaking PII hashes in order to show that hashing
of PII is not a sufficient pseudonymisation technique.
</summary>
<dc:date>2018-01-01T00:00:00Z</dc:date>
</entry>
</feed>
