Learn, hack!

Hacking and security documentation: slides, papers, video and audio recordings. All in high-quality, daily updated, avoiding security crap documents. Spreading hacking knowledge, for free, enjoy. Follow on .

ZERT: VML, ANI and Third-party Patches

URL
http://dewy.fem.tu-ilmenau.de/CCC/CCCamp07/video/m4v/cccamp07-en-2051-ZERT_VML_ANI_and_Third-party_Patches.m4v
File name
cccamp07-en-2051-ZERT_VML_ANI_and_Third-party_Patches.m4v
File size
142.2 MB
MD5
9874790813cbc352f75a16d78ace414e
SHA1
39dea69dd830f2f38aee2728a6dae9c480bf95dc

ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted? In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).

About us

Secdocs is a project aimed to index high-quality IT security and hacking documents. These are fetched from multiple data sources: events, conferences and generally from interwebs.

Statistics

Serving 8166 documents and 531.0 GB of hacking knowledge, indexed from 2419 authors from 163 security conferences.

Contribute

To support this site and keep it alive, you can click on the buttons below. Any help is really appreciated! This service is provided for free, but real money is needed to pay bills.

Flattr this Click here to lend your support to: Keep live SecDocs for an year and make a donation at www.pledgie.com !