Before the emergence of the way a new type of phishing attack, that is not turned on by PPT case macros, program execution, on this Freebuf also relevant articles are introduced, "the new PPT phishing analysis" , "do not need a macro, PPT can used to deliver malicious programs " . But none of this paper describes how the production of such files, so, here today to share methods of making the file, and I hope you understand this defense.
First, create a regular PPTX file, just fill in some content, as shown below:
After insertion of a button operation, the specific location as shown below:
To select the blank here after that, select, pull the trigger position in the page, the interface will pop up after the action set:
Select the mouse over -> Run program:
Select the program you want to run 可在后面直接加参数
, such as a calculator, and then click OK.
Now it appears as a colored area, so that he should be set, right click -> Format Shape, the fill and line color to No
Finally, save the file as PPSX file.
final effect: