@incollection{MeyerSomorovskyWeissetal.2014, author = {Meyer, Christopher and Somorovsky, Juraj and Weiss, Eugen and Schwenk, J{\"o}rg and Schinzel, Sebastian and Tews, Erik}, title = {Revisiting SSL/TLS Implementations: New Bleichenbacher Side Channels and Attacks.}, series = {23rd USENIX Security Symposium (USENIX Security 14)}, booktitle = {23rd USENIX Security Symposium (USENIX Security 14)}, publisher = {USENIX Association}, address = {San Diego, CA}, isbn = {ISBN 978-1-931971-}, pages = {733 -- -748}, year = {2014}, language = {en} } @article{SchinzelThuenemannLoehr2014, author = {Schinzel, Sebastian and Th{\"u}nemann, Maximilian and L{\"o}hr, Dennis}, title = {Internetzensus - Das Internet scannen und auf Schwachstellen untersuchen}, series = {iX - Security kompakt}, journal = {iX - Security kompakt}, number = {4}, issn = {4018837005}, year = {2014}, language = {de} } @incollection{AviramSchinzelSomorovskyetal.2016, author = {Aviram, Nimrod and Schinzel, Sebastian and Somorovsky, Juraj and Heninger, Nadia and Dankel, Maik and Steube, Jens and Valenta, Luke and Adrian, David and Halderman, J. Alex and Dukhovni, Viktor and K{\"a}sper, Emilia and Cohney, Shaanan and Engels, Susanne and Paar, Christof and Shavitt, Yuval}, title = {DROWN: Breaking TLS Using SSLv2}, series = {25th Usenix Security Symposium}, booktitle = {25th Usenix Security Symposium}, publisher = {Usenix Association.}, address = {Austin, TX.}, pages = {689 -- 706}, year = {2016}, language = {mul} } @incollection{SchmittSchinzel2012, author = {Schmitt, Isabell and Schinzel, Sebastian}, title = {WAFFle: Fingerprinting Filter Rules of Web Application Firewalls}, series = {6th USENIX Workshop on Offensive Technologies (WOOT 2012)}, booktitle = {6th USENIX Workshop on Offensive Technologies (WOOT 2012)}, address = {Seattle.}, pages = {34 -- 40}, year = {2012}, language = {en} } @incollection{JagerSchinzelSomorovsky2012, author = {Jager, Tibor and Schinzel, Sebastian and Somorovsky, Juraj}, title = {Bleichenbacher's Attack Strinkes Again: Breaking PKCS\#1 v1.5 in XML Encryption}, series = {17th European Symposium on Research in Computer Security (ESORCIS 2012)}, booktitle = {17th European Symposium on Research in Computer Security (ESORCIS 2012)}, year = {2012}, language = {mul} } @incollection{FreilingSchinzel2011, author = {Freiling, Felix and Schinzel, Sebastian}, title = {Detecting Hidden Storage Side Channel Vulnerabilities in Networked Applications}, series = {IFIP sec2011 - Future Challenges in Security and Privacy for Academia and Industry}, booktitle = {IFIP sec2011 - Future Challenges in Security and Privacy for Academia and Industry}, edition = {Volume 354}, publisher = {Springer, Berlin, Heidelberg}, isbn = {978-3-642-21423-3}, doi = {10.1007/978-3-642-21424-0_4}, pages = {41 -- 55}, year = {2011}, language = {de} } @incollection{Schinzel2011, author = {Schinzel, Sebastian}, title = {An Efficient Mitigation Method for Timing Side Channels on the Web}, series = {2nd International Workshop on Constructive Side-Channel Analysis and Secure Design (COSADE 2011)}, booktitle = {2nd International Workshop on Constructive Side-Channel Analysis and Secure Design (COSADE 2011)}, year = {2011}, language = {en} } @article{SchinzelSchmitt2012, author = {Schinzel, Sebastian and Schmitt, Isabell}, title = {{\"U}ber Umwege - Seitenkanalangriffe auf Netzwerkanwendungen}, series = {iX - Magazin f{\"u}r professionelle Informationstechnik}, journal = {iX - Magazin f{\"u}r professionelle Informationstechnik}, number = {11}, year = {2012}, language = {mul} } @article{SchinzelWeidemannWiegensteinetal.2011, author = {Schinzel, Sebastian and Weidemann, Frederik and Wiegenstein, Andreas and Schumacher, Markus}, title = {SAP-Security - Sicherheitsl{\"o}cher in eigenem ABAP-Code stopfen}, series = {iX - Magazin f{\"u}r professionelle Informationstechnik}, journal = {iX - Magazin f{\"u}r professionelle Informationstechnik}, number = {07}, year = {2011}, language = {mul} } @incollection{AtkinsonGerbigBarthetal.2012, author = {Atkinson, Colin and Gerbig, Ralph and Barth, Florian and Freiling, Felix and Schinzel, Sebastian and Hadasch, Frank and Maedche, Alexander and M{\"u}ller, Benjamin}, title = {Reducing the Incidence of Unintended, Human-Caused Information Flows in Enterprise Systems}, series = {Enterprise Distributed Object Computing Conference Workshops (EDOCW), 2012 IEEE 16th International}, booktitle = {Enterprise Distributed Object Computing Conference Workshops (EDOCW), 2012 IEEE 16th International}, edition = {3M4SE 2012}, doi = {10.1109/EDOCW.2012.12}, pages = {11 -- 18}, year = {2012}, language = {en} } @incollection{SchinzelSchmuckerEbinger2009, author = {Schinzel, Sebastian and Schmucker, Martin and Ebinger, Peter}, title = {Security mechanisms of a legal peer-to-peer file sharing system (http://www.iadis.net/dl/Search_list_open.asp?code=6365)}, series = {IADIS International Journal on Computer Science and Information Systems}, booktitle = {IADIS International Journal on Computer Science and Information Systems}, year = {2009}, language = {en} } @incollection{EbingerSchinzelSchmuckler2008, author = {Ebinger, Peter and Schinzel, Sebastian and Schmuckler, Martin}, title = {Security mechanisms of a legal peer-to-peer file sharing system}, series = {IADIS International Conference Applied Computing}, booktitle = {IADIS International Conference Applied Computing}, year = {2008}, language = {en} } @article{Schinzel2012, author = {Schinzel, Sebastian}, title = {Side Channel Attacks: Error messages and verbose log entries can tip off intruders}, series = {LINUX Magazine}, journal = {LINUX Magazine}, number = {\#143}, year = {2012}, language = {en} } @article{Schinzel2012, author = {Schinzel, Sebastian}, title = {Seitenkan{\"a}le mit Untiefen: Manche Webanwendungen spielen Angreifern unfreiwillig Informationen zu}, series = {ADMIN Magazin}, journal = {ADMIN Magazin}, year = {2012}, language = {de} } @incollection{BauerSchinzelFelixetal.2016, author = {Bauer, Johannes and Schinzel, Sebastian and Felix, C. and Freiling, Andreas}, title = {Information leakage behind the curtain: Abusing anti-EMI features for covert communication}, series = {Hardware Oriented Security and Trust (HOST), 2016 IEEE International Symposium on}, booktitle = {Hardware Oriented Security and Trust (HOST), 2016 IEEE International Symposium on}, doi = {10.1109/HST.2016.7495570}, pages = {130 -- 134}, year = {2016}, language = {en} } @book{Schinzel2012, author = {Schinzel, Sebastian}, title = {Unintentional and Hidden Information Leaks in Networked Software Applications}, edition = {Dissertation}, address = {University of Erlangen-Nuernberg}, pages = {1 -- 103}, year = {2012}, language = {en} } @incollection{WiegensteinSchumacherSchinzeletal.2009, author = {Wiegenstein, Andreas and Schumacher, Markus and Schinzel, Sebastian and Weidemann, Frederik}, title = {Sichere ABAP-Programmierung}, series = {Rheinwerk Verlag GmbH}, booktitle = {Rheinwerk Verlag GmbH}, isbn = {978-3-8362-1357-8}, pages = {1 -- 372}, year = {2009}, language = {de} } @incollection{SchumiloAschermannGawliketal.2017, author = {Schumilo, Sergej and Aschermann, Cornelius and Gawlik, Robert and Schinzel, Sebastian and Holz, Thorsten}, title = {kAFL: Hardware-Assisted Feedback Fuzzing for OS Kernels}, series = {26th Usenix Security Symposium}, booktitle = {26th Usenix Security Symposium}, year = {2017}, language = {en} } @incollection{PoddebniakSomorovskySchinzeletal.2018, author = {Poddebniak, Damian and Somorovsky, Juraj and Schinzel, Sebastian and Lochter, Manfred and R{\"o}sler, Paul}, title = {Attacking Deterministic Signature Schemes using Fault Attacks}, series = {3rd IEEE European Symposium on Security and Privacy}, booktitle = {3rd IEEE European Symposium on Security and Privacy}, year = {2018}, language = {mul} } @incollection{PoddebniakDresenMuelleretal.2018, author = {Poddebniak, Damian and Dresen, Christian and M{\"u}ller, Jens and Ising, Fabian and Schinzel, Sebastian and Friedberg, Simon and Somorovsky, Juraj and Schwenk, J{\"o}rg}, title = {Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration Channels}, series = {USENIX Security 2018}, booktitle = {USENIX Security 2018}, edition = {27th}, address = {Baltimore, MD, USA}, isbn = {978-1-931971-46-1}, year = {2018}, language = {en} }