Macro-Less Code Exec in MSWord
sensepost.com
sensepost.com
If they're at that level then there's really not much you can do but avoid having them get the stuff in the first place.
It is just stupid design and there is no excuse this is still in a supported application in 2017. But then again, what would you expect from Microsoft Office.
The warning is a security feature, but they didn't elaborate on how you can bypass it with "proper syntax modification". If that's true, then it should be considered at least somewhat exploitable.
Just thought I'd say that it's possible to the see the IP you are connecting to. Not sure if you'd like to update the video or not.
Why are they connected as root via ssh? Any good reason for that? Just to troll people like me?