Camp 2007 - 1.01

Chaos Communication Camp 2007
To infinity and beyond

Speakers
Gil Dabah
Gadi Evron
Schedule
Day 3
Room Shelter Bar
Start time 20:00
Duration 01:00
Info
ID 2051
Event type Lecture
Track Hacking
Language English
Feedback

ZERT: VML, ANI and Third-party Patches

Assembly - lots of it.

ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted?

In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).