ZERT, the Zeroday Emergency Response Team, hit the news in the past 2 years with third-party patches to 0day attacks such as VML and ANI. What's behind these vulnerabilities, and how were the patches constracted? In this lecture we will discuss the VML and ANI vulnerabilities in depth (assembly knowledge required), and the ZERT response mechanisms. We will then proceed and describe how the ZERT patches were built (whether to avoid collisions with the real patch when it comes out, or how generic patching in-memory was accomplished).
Secdocs is a project aimed to index high-quality IT security and hacking documents. These are fetched from multiple data sources: events, conferences and generally from interwebs.
Serving 8166 documents and 531.0 GB of hacking knowledge, indexed from 2419 authors from 163 security conferences.