Camp 2007 - 1.01

Chaos Communication Camp 2007
To infinity and beyond

Gadi Evron
Gil Dabah
Tag 3
Raum Shelter Bar
Beginn 20:00
Dauer 01:00
ID 2051
Veranstaltungstyp Vortrag
Track Hacking
Sprache englisch

ZERT: VML, ANI and Third-party Patches

Assembly - lots of it.

ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted?

In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).

