Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 31 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow Links to cool sites.arrow ZERT - Zeroday Emergency Response Team
EH-Net
May 25, 2013, 11:24:43 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: ZERT - Zeroday Emergency Response Team  (Read 3899 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4169


Editor-In-Chief


View Profile WWW
« on: October 21, 2006, 07:09:04 PM »

ZERT, in a nutshell, is a group of security researchers that creates unofficial patches for zero day vulnerabilites before MS can.

Their Manifesto:

Quote
ZERT is a group of engineers with extensive experience in reverse engineering software, firmware and hardware coupled with liaisons from industry, community and incident response groups. While ZERT works with several Internet security operations and has liaisons to anti-virus and network operations communities, ZERT is not affiliated with a particular vendor.

ZERT members work together as a team to release a non-vendor patch when a so-called "0day" (zero-day) exploit appears in the open which poses a serious risk to the public, to the infrastructure of the Internet or both. The purpose of ZERT is not to "crack" products, but rather to "uncrack" them by averting security vulnerabilities in them before they can be widely exploited.

It is always a good idea to wait for a vendor-supplied patch and apply it as soon as possible, but there will be times when an ad-hoc group such as ours can release a working patch before a vendor can release their solution.

Their disclaimer:

Quote
Please keep in mind that while ZERT tests these patches, they are NOT official patches with vendor support and are provided as-is with no guarantee as to fitness for your particular environment. Use them at your own risk or wait for a vendor-supported patch.

http://zert.isotf.org/

Add your thoughts,
Don
Logged

CISSP, MCSE, CSTA, Security+ SME
skel
Jr. Member
**
Offline Offline

Posts: 60


"Beam me up Scotty - Only hackers here"


View Profile
« Reply #1 on: October 23, 2006, 05:45:34 AM »

IMHO MS has never been a poineering company. MS has always had the philosopy of copy first and do better than the original.

So in this case too ZERT is pushing MS. I think more companies should be doing this. Eventually some of these unoffical patches may make windows more vulnerable and bring a bad name for MS products ( as if they dont have a bad name now  Grin he he he....)

Once MS feels threatned it will push their upgrades/ patches faster and better and ZERT will be no more.   Smiley
Logged

Skel
Kev
Guest
« Reply #2 on: October 26, 2006, 11:17:28 AM »

 We need even more organizations like this one. The reality is MS pushed almost brutally to be the words only OS. Sometimes in what might be considered almost unethical in their tactics. The US government certainly thought so years ago when they found them guilty.

  Well, MS has gotten what they wanted, at least as far as most home users are concerned and now is the most cash rich company in the world.    Therefore in my opinion they should do whatever it takes to make sure their system is really secure. They have had a history of “if it ain’t broke why fix it” and has never been good at taking preventative measures.  Only after damage is done and people lives have been messed up have they taken action. 
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.241 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.