Camp 2007 - 1.01
Chaos Communication Camp 2007
To infinity and beyond
Speakers | |
---|---|
Gadi Evron | |
Gil Dabah |
Schedule | |
---|---|
Day | 3 |
Room | Shelter Bar |
Start time | 20:00 |
Duration | 01:00 |
Info | |
ID | 2051 |
Event type | Lecture |
Track | Hacking |
Language | English |
Feedback | |
---|---|
Did you attend this event? Give Feedback |
ZERT: VML, ANI and Third-party Patches
Assembly - lots of it.
ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted?
In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).