Hackers can now HACK you with just a Word Document! | Zero-Day Exploit!

Поделиться
HTML-код
  • Опубликовано: 24 авг 2024
  • Create your own native application from your website in minutes with AppMySite (no coding required): www.appmysite....
    This is the recently discovered Follina exploit which is assigned as CVE-2022-30190. It allows the hacker to get a Remote Code Execution (RCE) on your computer. In-order to trigger this exploit, the user need not even open the maldoc, he/she just needs to preview it!
    The vulnerability lies in the MS-MSDT URL protocol - Windows blindly executes code when this protocol is used along with some parameters and a powershell expression.
    DISCLAIMER
    This video is made only for educational purposes and to bring awareness in viewers about this zero day exploit, and it contains instructions on how to protect yourself from it. So take it the right away, do not use it on anyone without their consent. This is a serious thing.
    Check out John Hammond's video for a more in-depth explanation about this exploit: • Exploiting MSDT 0-Day ...
    A workaround for this vulnerability is to disable MSDT URL protocol on your computer. In-order to do that:
    1. Open cmd as administrator
    2. Backup your registry key with the command: reg export HKEY_CLASSES_ROOT\ms-msdt filename
    3. Disable MSDT: reg delete HKEY_CLASSES_ROOT\ms-msdt /f
    This should make you invulnerable to this exploit until the patch releases.
    Stay safe guys!
    Thanks for watching!
    SUBSCRIBE for more videos!
    Join my Discord: / discord
    Follow me on Instagram: / teja.techraj
    Website: techraj156.com​​​​​
    Blog: blog.techraj15...
    #zeroday

Комментарии • 133

  • @TechRaj156
    @TechRaj156  2 года назад +9

    Check out my FREE course on SQL Injection for Beginners, you also get a completion certificate: bit.ly/3MTMQ2Q

    • @Nxyy
      @Nxyy 2 года назад

      ur a lier u opened the file

  • @_JohnHammond
    @_JohnHammond 2 года назад +156

    Thanks so much for the shout-out, and especially thanks for showcasing the PoC! 🥰

    • @karthiksharath5622
      @karthiksharath5622 2 года назад +7

      You're an inspiration to all of us John! Thanks for all the effort!

    • @Riborwahz
      @Riborwahz 2 года назад +1

      John Hammond u had me as your subscriber thanks for the video with David Bombal

    • @smarterthinks
      @smarterthinks 2 года назад

      hey can anyone send me that file to me plsssss

    • @FNAFIGNITEDFREDDYCLUB
      @FNAFIGNITEDFREDDYCLUB 2 года назад

      Sure

    • @hanneshultgren6198
      @hanneshultgren6198 2 года назад

      And Thank you for share to us about this hack! hour unix father.

  • @gatorrade1680
    @gatorrade1680 2 года назад +40

    For anyone who is wondering: You can undo the workaround with this command "reg import backupregistry"
    Great video as allways, Raj 😎

    • @TheMessanger
      @TheMessanger 2 года назад

      Yeah bankruptcy filing will be needed when they take everything

    • @codeJamalonRH
      @codeJamalonRH 2 года назад

      @@TheMessanger 😭😭

    • @TheMessanger
      @TheMessanger 2 года назад

      @@codeJamalonRH don't worry if is not the hacker is your wife or family 😭

    • @codeJamalonRH
      @codeJamalonRH 2 года назад +1

      @@TheMessanger 😂😂😂

  • @lancemadrazo
    @lancemadrazo 2 года назад +3

    Your channel is too underrated, you'd make the next Jim Browning. Hell, your almost just as good as him

  • @adisonmasih
    @adisonmasih 2 года назад +2

    Damn. Never Thought About RTF & Preview Pane! Thanks A Lot For Keeping Us Updated.

  • @thembekileblessmore
    @thembekileblessmore 2 года назад +1

    Ok, now I can hack my professors and give myself higher grades.

  • @shivjain
    @shivjain 2 года назад +1

    Thanks!

  • @harshjain8345
    @harshjain8345 2 года назад +13

    Loving the consistency and the content as well! Keep them coming! Also.. seems like your shadow ban is removed since one of your videos got good amount of views within 2 weeks of uploading !

  • @timewalkwalker
    @timewalkwalker 2 года назад +2

    So cool microsoft really need to patch this many people uses these ms apps and this is really dangerous

  • @vladislavkaras491
    @vladislavkaras491 11 месяцев назад

    Impressive!
    Thanks for the video!

  • @_GhostMiner
    @_GhostMiner 2 года назад +2

    0:20 does this work only work when you have preview window enabled?
    I use details instead of preview.

  • @sher.5027
    @sher.5027 2 года назад +1

    Thanks for informing with short and best explanation. I liked, shared and subscribed. :)

  • @psylingames8371
    @psylingames8371 Год назад

    He’s so smart and knowledgeable. You earned a subscription!

  • @xopionxopion6170
    @xopionxopion6170 2 года назад

    Thanks for alerting us....
    And nice video,carry on...

  • @MERE8
    @MERE8 2 года назад

    Thank you! ❤

  • @sujeetkumarsinghmath
    @sujeetkumarsinghmath 2 года назад +4

    101 reasons to use linux

  • @GlobalSuccessNarratives
    @GlobalSuccessNarratives 2 года назад

    We need more content like this

  • @techywarrior1190
    @techywarrior1190 2 года назад

    again awesome video as always ,
    also please make a update video on yoyr rig as market crashes

  • @xsycl
    @xsycl 13 дней назад

    "i wont open it"
    proceeds to double click the file

  • @ytg6663
    @ytg6663 11 месяцев назад +1

    If there was NO Patch, how poc went public 🤣🤣🤣

  • @justinedawnz
    @justinedawnz 4 месяца назад

    Wow our computers can be hacked through word documents

  • @shaunzhang733
    @shaunzhang733 2 года назад +1

    Does this vulnerability affect users who use WPS office, Libreoffice and Softmaker Freeoffice?
    I use WPS office, by the way.

  • @press3626
    @press3626 7 месяцев назад +1

    this is so old lol, macro xlsm was a good time (=

  • @ItzFallen
    @ItzFallen 2 года назад

    You earned a sub!

  • @gallium-gonzollium
    @gallium-gonzollium 2 года назад

    Windows Sandbox: *I am 100 steps in front of you*

  • @nitishg29
    @nitishg29 2 года назад

    Make some videos on learning about hacking

  • @BiteYt69
    @BiteYt69 2 года назад +1

    Thanks brother for the video

  • @danixunboxing
    @danixunboxing 2 года назад

    Amazing Video bro, learned a lot from this best explanation on MSDT vulnerability. Big Love from Pakistan..

  • @hashimkhan3276
    @hashimkhan3276 Год назад +1

    Hello bro my friend hack my mobile i did not know I just click on link and they hack my all mobile and get picture of me live and also take my network cameras how I recover it I did not know something about hacking pleaze help me pleazeeeee he hack on kali linux😔😔😔😔

  • @thamimtommy7106
    @thamimtommy7106 2 года назад

    Hacker can hack your computer even though you don't have one 😂

  • @changeurlife89
    @changeurlife89 2 года назад +2

    Where I get that word file please tell me

    • @osissmpktmc
      @osissmpktmc 2 года назад +2

      Probably not allowed to get that, because of another purposes

    • @changeurlife89
      @changeurlife89 2 года назад

      Ok.. but i need to test..

    • @dontreadthis888
      @dontreadthis888 2 года назад

      Even if you got it, its useless for you, because you cannot get the reverse shell as it is controlled by the one who made this file

  • @mrva4477
    @mrva4477 2 года назад

    you dropped this👑👑

  • @thembekileblessmore
    @thembekileblessmore 2 года назад

    Can you do tutorial on how to make my own Follina?

  • @piotrek4259
    @piotrek4259 2 года назад

    Next: Hackers can now HACK you with just a RUclips Video!

  • @newuser4229
    @newuser4229 2 года назад

    But how can I create this?

  • @codedaily365
    @codedaily365 2 года назад +1

    Ik this!! THIS IS REALLY MESSED UP!!! i saw this on Network chucks recent video!
    Hope this exploit gets fixed soon.
    Btw i love ur videos! YOUR OLD SUBSCRIBER! lol

  • @acsai6274
    @acsai6274 Год назад

    Zero day attack is zero click attack

  • @xiaoshou6752
    @xiaoshou6752 2 года назад

    What exactly does disabling that protocol change to your computer? Will it impact its behaviour in some noticable way?

    • @OkSear
      @OkSear Год назад

      same thing I want to know

  • @bashdante3333
    @bashdante3333 2 года назад

    it will be a good idea if i try the last part of this video on work's computer?

  • @jacskyline
    @jacskyline 2 года назад

    Thanks for the video. I have a question. The direct execution on preview mode on Windows Explorer only occurs on rtf formats?

  • @leophysics
    @leophysics 2 года назад

    Is that macro vunrability . Is it work if macro is off?

  • @singularity2000
    @singularity2000 2 года назад

    Really dangerous

  • @youcefabed7880
    @youcefabed7880 Год назад

    bonjour j'ai besoin de votre aide monsieur

  • @user-qr8ty6ul9i
    @user-qr8ty6ul9i Год назад

    It doesn't work as you showed. windows bit defender can't let it enter.

  • @laxmikantsaraswat6319
    @laxmikantsaraswat6319 2 года назад

    the network chunk🔥

  • @kk9870
    @kk9870 2 года назад +1

    ❤️ I love you~ ❤️

    • @ividimitrova8030
      @ividimitrova8030 2 года назад +1

      I lov him more 😍👹

    • @kk9870
      @kk9870 2 года назад

      @@ividimitrova8030 KAK SMEESH PACHAVRO SKAPANA
      DA GORISH V ADA

  • @vinusuhas4978
    @vinusuhas4978 2 года назад

    what happened if u open through google docs itself?

  • @LShortcuts
    @LShortcuts 2 года назад

    Already installed the patch

  • @MdAbdullahAlMamun
    @MdAbdullahAlMamun 2 года назад

    wow good information thanks for shaeing

  • @techtechtech1264
    @techtechtech1264 2 года назад

    Please which android rat is the best Techraj?

  • @deepitprajapati5261
    @deepitprajapati5261 Год назад

    Can you post a video to setup our own FTP server

  • @mega_micro
    @mega_micro 2 года назад

    Is it possible on Win10?

  • @ozrencupac
    @ozrencupac 2 года назад

    Me who uses linux:
    I dont have these issues anymore

  • @VigneshVicky-ph1yn
    @VigneshVicky-ph1yn Год назад

    That's why I am using ubantu

  • @bingo8920
    @bingo8920 2 года назад

    you should work in Microsoft, you're really smart, thnx

    • @dontreadthis888
      @dontreadthis888 2 года назад

      Every cyber security person goes through this everyday, Its no big deal

  • @Dahlah.FightMe
    @Dahlah.FightMe 2 года назад +1

    Nice Bro :D

  • @duniamotivasi8342
    @duniamotivasi8342 2 года назад

    No reverse shell anymore

  • @4nkitpatel
    @4nkitpatel 2 года назад

    Is it solved today or we just have patch for it ?

  • @hoovyyyy
    @hoovyyyy 2 года назад

    How to rick roll a friend

  • @JontheRippa
    @JontheRippa 2 года назад

    Wow Verry good 👍

  • @stinkybooty1153
    @stinkybooty1153 10 месяцев назад

    did they patch this yet?

  • @arkodeepchatterjee
    @arkodeepchatterjee Год назад

    how to do this?

  • @bewithme6767
    @bewithme6767 2 года назад

    network chuck was here

  • @13part
    @13part 2 года назад

    how can i use it pls

  • @sadikmahmud7787
    @sadikmahmud7787 2 года назад

    That's amazing

  • @JohnPaulBuce
    @JohnPaulBuce 2 года назад

    never gonna click that file

  • @medfaroukkhabir
    @medfaroukkhabir 2 года назад

    you rickrolled us !

  • @chinesericexfarmer6067
    @chinesericexfarmer6067 2 года назад

    Will it work even if i don't hv internet connection

  • @mejnkrasz4926
    @mejnkrasz4926 2 года назад

    Very good and working crack thx

  • @sudarshanprasad9615
    @sudarshanprasad9615 2 года назад

    Yoo, where can I get this file ???

  • @DeejTiuz
    @DeejTiuz 2 года назад

    Kek, the delete string it's not working for me, it says if I want to delete it, I say yes and it gave me an error that it is does not exist xd

  • @betadv
    @betadv 2 года назад

    previewing the file opens the file :/

  • @Ghost-vx4yb
    @Ghost-vx4yb 2 года назад

    I have grapheneos it protects me from this

  • @tropojagashi9802
    @tropojagashi9802 Год назад

    so your saying text docs arent even safe now damn

  • @pRR5FSDiqyqznJ2t1LkSez
    @pRR5FSDiqyqznJ2t1LkSez 2 года назад

    now? i have been using this for long time

  • @realkitten7171
    @realkitten7171 2 года назад +1

    LMFAO next time don't put "without opening" into the thumbnail if in the video you clearly open the file.

  • @CodeBinge
    @CodeBinge 2 года назад

    You should've used @John Hammond's python script. Much easier to use(as they show it)
    EDIT: I only saw the part where you change the code and commented, didn't know you did later

  • @Ben_Anter
    @Ben_Anter Год назад

    why you lying? you can clearly see you double click on the file

  • @rshnthms
    @rshnthms 2 года назад +1

    What happens when we open within Google doc or outlook view

  • @hackersareherewhereareyou
    @hackersareherewhereareyou 2 года назад

    Bro we can hack using video

  • @robertwells3797
    @robertwells3797 2 года назад

    You literally clicked it to open the file 😂

  • @capebaldy4365
    @capebaldy4365 2 года назад

    oooh

  • @anha4259
    @anha4259 2 года назад

    We was already rickrolled

  • @fintsolutions3851
    @fintsolutions3851 Год назад

    ⬆️⬆️⬆️ you are a real master of the arts.

  • @S2M-BrainBites
    @S2M-BrainBites 2 года назад

    Is this working in android

  • @BugbountyPOCs41
    @BugbountyPOCs41 2 года назад

    Amog us

  • @selinapena3276
    @selinapena3276 2 года назад

    Lol 😂

  • @greenculturemedia
    @greenculturemedia 2 года назад

    From your command p. How can someone check if he is being hacked ? Or how can someone undo a hacker with command p

    • @giovannis.c.4518
      @giovannis.c.4518 2 года назад

      maybe with some tools like wireshark you could maybe see the network traffic but I don't think there is a magic command that tells you if you are hacked, if your antivirus doesn't detect it then is kind of difficult.

  • @panic_seller
    @panic_seller 2 года назад

    God knows how many zero day attacks are not reported out there. We have a virus in our company luckily Kaspersky can catch it, ofcourse I don't use company laptop with bogus antivirus🤣🤣

    • @xAffan
      @xAffan 2 года назад

      Use Linux

  • @shakibhoshen6803
    @shakibhoshen6803 2 года назад

    Nc

  • @itsankitbhusal
    @itsankitbhusal 2 года назад

    Le me using Debian 🤣

  • @crlfff
    @crlfff 2 года назад

    bruhhh an indian

  • @0zi146
    @0zi146 2 года назад +1

    numero uno egg

    • @0zi146
      @0zi146 2 года назад

      PIN ME PLEASEEEE

  • @jisz2982
    @jisz2982 2 года назад

    Nice

  • @cashappservices3954
    @cashappservices3954 2 года назад

    Cashapp blessing

  • @shoobooo9224
    @shoobooo9224 2 года назад

    word.exe lol

  • @prabhatmishra8422
    @prabhatmishra8422 2 года назад

    I'm curious to know that
    do u follow NetworkChuck 😅

  • @notamongyou
    @notamongyou 2 года назад +1

    It's not possible until the system is vulnerable, if you can hack me you will be rewarded 🙌🤍

    • @dontreadthis888
      @dontreadthis888 2 года назад

      Every system is vulnerable, This is a new zero-day CVE-202230190 i think

    • @xAffan
      @xAffan 2 года назад

      @@dontreadthis888 what if you are NOT running windows?

    • @dontreadthis888
      @dontreadthis888 2 года назад

      @@xAffan I was talking about windows users. But i'm not saying LINUX or MAC is safe, Every system has its own vulnerabilities maybe some linux vulnerabilities are not yet discovered

    • @xAffan
      @xAffan 2 года назад +1

      @@dontreadthis888 ik but Linux is much secure cus most servers and android run on it so big companies always check the kernel for vulnerabilities etc. But ye ur right and it's used less in desktop space so there's not much attackers so it's pretty secure

    • @dontreadthis888
      @dontreadthis888 2 года назад

      @@xAffan Yeah you're right, but i'm not saying its totally safe, cuz newer vulnerabilities are found often these days