Skip to main content

'follina' Zero-Day Vulnerability

Zero day vulnerability is a broad term that describes any recently discovered security vulnerability that hackers can use to attack system. It is called zero-day because the vulnerability is just discovered and the developers have 'zero-day' to patch it.

What is follina?

Follina is a recently discovered vulnerability in the Microsoft Office especially in the Microsoft Word. It allows hackers to attack your system through a '.doc' file. If you open the file the file is blank and does not contain anything. But as soon as you open the file, you can see a diagnosis window or a program compatibility troubleshooter. And while it is busy doing that, you are already hacked.


(In the above picture, the picture at the left is the victim's point of view and the one at right is the hacker's point of view)

While you open the '.doc' file, you might also have another application open other than the program compatibility troubleshooter. It is the application that is being opened by the script included in the '.doc' file. The script can also be used to reverse shell into your computer which means any one who sent you the file can have complete access of your computer.  

How to become safe?

The major way of spreading of files like this is the Internet. Some measure to be safe from things like this are: 

1. Don't download any random file from the Internet

2. Don't open any suspicious link that you get in your e-mail.

3. Don't download any suspicious file from your e-mail if you are not sure what it is.

4. If you encounter something that is not usual then seek help from any expert or you can also      search in Google for any help.

This post does not contain all the information about this newly discovered vulnerability. I would recommend you to go to a better site rather than referring to this post.

Comments

Popular posts from this blog

How to run LOIC in Ubuntu or any other Linux distribution.

You wanting to use LOIC means that you are planning to perform a DOS attack. The most popular software that helps you to perform DOS attack is LOIC but the software is not available for Linux. So, today I'll teach you how to use LOIC in any Linux distro. 1. Open terminal and run the following command: sudo apt-get install mono-complete 2. Download the LOIC software by clicking here . 3. Extract it and place it in the Desktop. 4. Open terminal and type the following commands: cd Desktop sudo mono LOIC.exe Now your LOIC should run properly.  The video tutorial in YouTube has been removed for violating Community Guidelines. Sorry about that. 

Will there be a Windows 11?

 It has been five years since the latest Windows, Windows 10 has released. People have now raised a question, 'Will there be a new Windows or Windows 11?'.  As far as I think, there might not be a new version of Windows. If a new version of Windows arrives the interface have to be new and people will need some to learn how to use properly and this might be difficult for huge companies and offices. And there might also be some programs that run only in the current version of Windows and the programs may be corrupt and not work properly if it is running in a new OS and people might have to make a new program that runs in the new OS. So instead of a new version of Windows, Microsoft might add new features and bring updates for the current version of Windows, Windows 10 and make it better and continue the current version rather than bringing up a new one.

6 most addictive Android games for free!!!

 If you are bored and just want some good game to kill your time, you are at the right place. In this post, you will find some exciting games that can be a great help to kill your time. These games are completely free to download and can run on low specs phones also. 1. Brain Dots Brain Dots is a game published by Translimit,Inc. In this game you will find two dots of different colors (blue and pink) and your task is to bring the two dots together by drawing lines. The game gets difficult as your levels increase. Click here to download the game. 2. Plague Inc Plague Inc is published by Ndemic Creation and Miniclip. It is a disease based game where you have to spread your disease all over the world by not letting any country develop an antidote of your disease. If all the countries get infected and if all the people die you win the game. Click here to download the game. 3. Eerskraft Eerskraft is a Minecraft like game but it is completely free and does not take much resources and s...