News

All Tasks Back Online

Written on 21.12.24 by Lea Gröber

Dear all,

all tasks are online again. Happy hacking!

Tasks Online and Additional Hints on Sheet 04

Written on 20.12.24 by Lea Gröber

Hello everyone,

the exercises E4: XSS Attacks and E4: Advanced XSS 1 are active again. Further, we updated exercise sheet 04 with additional hints.

We are still working on the remaining two exercises.

CSRF + XSS Challenges down for maintanance

Written on 19.12.24 by Alexander Ponticello

Dear students,

due to some technical issues, the CSRF + XSS challenges are currently not working as expected. We are working on the issues, for the time being, these challenges are deactivated in the scoreboard and not exploitable on the website. The affected front-end will still show as usual,… Read more

Dear students,

due to some technical issues, the CSRF + XSS challenges are currently not working as expected. We are working on the issues, for the time being, these challenges are deactivated in the scoreboard and not exploitable on the website. The affected front-end will still show as usual, however the corresponding back-end services are offline.

All other challenges are unaffected and can be exploited as usual.

We apologize for the inconvenience and will release another news once the issues is resolved.

 

Best,

Alexander

Tutorial 5 cancelled today

Written on 09.12.24 by Simeon Hoffmann

Hi all,

unfortunately, Joys is sick today and thus tutorial 5 is cancelled. Roman offered that flexible students can join his tutorial session (tutorial 4, E2 5, SR 3, 10:15) instead today.

Simeon

Update to "canary" challenge, scoreboard prizes

Written on 06.12.24 (last change on 06.12.24) by Simeon Hoffmann

Dear students,
unfortunately, there was a small mistake in the "canary" challenge. We fixed the problem, but some offsets might have changed. We will accept exploits with both offsets, the new and the old one, in case you already solved the task.

In addition, let me take this opportunity to… Read more

Dear students,
unfortunately, there was a small mistake in the "canary" challenge. We fixed the problem, but some offsets might have changed. We will accept exploits with both offsets, the new and the old one, in case you already solved the task.

In addition, let me take this opportunity to announce that there will be small prizes for the top 3 scoring teams on the scoreboard at the end of the lecture ;)
Simeon

Points for sheet 1, sample solution for sheet 2

Written on 03.12.24 by Simeon Hoffmann

Dear students,

we just released the points for sheet 1 and the sample solution for sheet 2.

Also, please remember to submit on time as we cannot take any late submissions. You can always upload a preliminary solution early, and reupload in case you make changes.

Simeon

Submissions: No hand-written notes and no LLM-generated content, please.

Written on 29.11.24 by Till Schlüter

Dear students,

We have two more requests regarding the exercise sheet submissions:

1. No hand-written submissions

To make our tutor's lifes easier, please do not submit (scans/pictures of) hand-written notes.

For exercise sheet E2, we strongly discourage handing in such documents, but will… Read more

Dear students,

We have two more requests regarding the exercise sheet submissions:

1. No hand-written submissions

To make our tutor's lifes easier, please do not submit (scans/pictures of) hand-written notes.

For exercise sheet E2, we strongly discourage handing in such documents, but will still accept them (as the deadline is already approaching). Starting from exercise sheet E3, however, we will no longer accept hand-written notes in submissions.

2. No LLM-generated content

In addition, we want to remind you of our policy regarding the use of large language models (LLMs) to solve the exercises (as outlined in the intro lecture): you may use LLMs to polish your writing or make your submission more readable, but not to generate any actual content. Keep in mind that one purpose of the exercises is to prepare you for the exam, where no LLMs will be available.

Thanks,
Till

Screenshots in submissions

Written on 21.11.24 by Till Schlüter

Dear students,

When you submit code, please only submit it as source files. Do not submit screenshots. You can upload a ZIP file as submission to CMS.

Tutorial details

Written on 31.10.24 (last change on 31.10.24) by Simeon Hoffmann

Hey everyone,

after manually reassigning the tutorials for some people, tutorial assignments are now fixed. If you want to attend another tutorial, please find someone from your preferred tutorial to swap with.

Short reminder that tutorials start on Nov 7th, so there are no tutorials on Monday.… Read more

Hey everyone,

after manually reassigning the tutorials for some people, tutorial assignments are now fixed. If you want to attend another tutorial, please find someone from your preferred tutorial to swap with.

Short reminder that tutorials start on Nov 7th, so there are no tutorials on Monday. The first sheet will be released next week Wednesday, on Nov 6th. Checkout the timetable for the latest details.

Simeon

Tutorials assigned

Written on 29.10.24 by Till Schlüter

Dear students,

The tutorials have been assigned. You should now see the tutorial slot assigned to you on your personal status page.
If you have not been assigned to a tutorial and think this is a mistake, please reach out to us via email to security-core-24@cispa.de as soon as possible.

Till

Question Sheet 0

Written on 15.10.24 (last change on 15.10.24) by Simeon Hoffmann

Hey all,

we just uploaded question sheet 0. This sheet is not graded, and meant to make you familiar with the tooling. It will be discussed in the tutorials.

Simeon

Introduction and general lecture schedule

Written on 15.10.24 by Nils Ole Tippenhauer

Dear student of Security'24,

for this week, we have prepared an introductory lecture as video, as Katharina and Nils are both traveling. You will find the link to the video/slides in the material collection here on CMS. From next week on, all lectures will be in-person, starting with the lecture on… Read more

Dear student of Security'24,

for this week, we have prepared an introductory lecture as video, as Katharina and Nils are both traveling. You will find the link to the video/slides in the material collection here on CMS. From next week on, all lectures will be in-person, starting with the lecture on October 22nd. We also plan to release an ungraded tutorial exercise (Q0) soon - you will also find it in the material collection. Please use the Askbot feature on CMS if you have any questions after watching the intro video!

Regards,

Nils

Show all

Security

The Security core lecture ("Stammvorlesung") will be offered in the winter term 2024/2025.

 

Lectures

We plan to offer the lecture as a in-person class. Note: For the first week of the term (14.-18.10.) we will offer a pre-recorded introduction video as both Katharina and Nils are not in Saarbrücken. The main lecture content starts in the second week, with an in-person lecture on October 22nd. All later classes will be in-person as well.

The schedule for the two lectures per week is as follows:

  • Tuesday 16:15-17:45 (GHH)
  • Wednesday 12:15-13:45 (GHH)

Registration

Registration in this CMS is required until October 27, 2024. LSF exam registration is required to participate in the exams (and will be possible until ~1 week before the final exam).

Tutorials

Details on tutorials will be announced later

Exams

Tentatively scheduled for: 
Final: 19.2.25 10am-12pm
Re-exam: 19.03. 2-4pm.

Location: We will have GHH for both. In addition, for the first date we will have all 3 lecture halls in E1 3, for the re-exam HS002 in E1 3. Room assignment for students will be done via CMS shortly before the exam.

Mental Health

Being a student is challenging and might be very overwhelming. If you need support during times of struggle, reach out to friends, family, or faculty you trust. The student union at UdS also offers a counseling service that you may contact. You do not have to go through this alone! If for whatever reason (e.g., a personal emergency) you cannot attend the lectures or deliver your work in time, please let us know and we will make appropriate arrangements.

Privacy Policy | Legal Notice
If you encounter technical problems, please contact the administrators.