ZERT: VML, ANI and Third-party Patches
From Chaos Communication Camp 2007
ZERT: VML, ANI and Third-party Patches
| Speakers | |
|---|---|
| Gil Dabah | |
| Schedule | |
| Day | {{{day}}} |
| Room | Shelter Bar |
| Start time | 20:00 |
| Duration | 01:00 |
| Info | |
| ID | 2051 |
| Event type | Lecture |
| Track | Hacking |
| Language | English |
ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted?
In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).
[edit] Links
[edit] Recordings
- Please add here as soon as they are available
