Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 18 guests online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Links to cool sites.arrow ZERT - Zeroday Emergency Response Team
Ethical Hacker Community Forums
January 09, 2009, 01:09:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2009 - May 4 - 9. Boot Camps & an Ethical Hacking Conf. www.chicagocon.com
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: ZERT - Zeroday Emergency Response Team  (Read 1656 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2442


Editor-In-Chief


View Profile WWW
« on: October 21, 2006, 07:09:04 PM »

ZERT, in a nutshell, is a group of security researchers that creates unofficial patches for zero day vulnerabilites before MS can.

Their Manifesto:

Quote
ZERT is a group of engineers with extensive experience in reverse engineering software, firmware and hardware coupled with liaisons from industry, community and incident response groups. While ZERT works with several Internet security operations and has liaisons to anti-virus and network operations communities, ZERT is not affiliated with a particular vendor.

ZERT members work together as a team to release a non-vendor patch when a so-called "0day" (zero-day) exploit appears in the open which poses a serious risk to the public, to the infrastructure of the Internet or both. The purpose of ZERT is not to "crack" products, but rather to "uncrack" them by averting security vulnerabilities in them before they can be widely exploited.

It is always a good idea to wait for a vendor-supplied patch and apply it as soon as possible, but there will be times when an ad-hoc group such as ours can release a working patch before a vendor can release their solution.

Their disclaimer:

Quote
Please keep in mind that while ZERT tests these patches, they are NOT official patches with vendor support and are provided as-is with no guarantee as to fitness for your particular environment. Use them at your own risk or wait for a vendor-supported patch.

http://zert.isotf.org/

Add your thoughts,
Don
Logged

CISSP, MCSE, CEH, Security+ SME
skel
Jr. Member
**
Offline Offline

Posts: 60


"Beam me up Scotty - Only hackers here"


View Profile
« Reply #1 on: October 23, 2006, 05:45:34 AM »

IMHO MS has never been a poineering company. MS has always had the philosopy of copy first and do better than the original.

So in this case too ZERT is pushing MS. I think more companies should be doing this. Eventually some of these unoffical patches may make windows more vulnerable and bring a bad name for MS products ( as if they dont have a bad name now  Grin he he he....)

Once MS feels threatned it will push their upgrades/ patches faster and better and ZERT will be no more.   Smiley
Logged

Skel
Kev
Guest
« Reply #2 on: October 26, 2006, 11:17:28 AM »

 We need even more organizations like this one. The reality is MS pushed almost brutally to be the words only OS. Sometimes in what might be considered almost unethical in their tactics. The US government certainly thought so years ago when they found them guilty.

  Well, MS has gotten what they wanted, at least as far as most home users are concerned and now is the most cash rich company in the world.    Therefore in my opinion they should do whatever it takes to make sure their system is really secure. They have had a history of “if it ain’t broke why fix it” and has never been good at taking preventative measures.  Only after damage is done and people lives have been messed up have they taken action. 
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2007, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.05 seconds with 24 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.