With the help of Salesforce Sites, businesses can build specialized communities where partners and clients could work collaboratively.
But when these communities are no longer required, they are frequently preserved rather than shut down. These sites aren’t examined for vulnerabilities since they aren’t maintained, and the administrators don’t update the security measures in accordance with contemporary guidelines.
Apparently, Varonis Threat Labs on its recent findings discovered that since these ghost sites were not properly deactivated, they were easily accessible to attackers who were using them to put illicit data, exploiting the sites.
They added that the exposed data did not only consist of the old data of the sites, but also fresh records that were disclosed to guest user, who shared configuration in the Salesforce environment.
Salesforce Ghost Sites
According to Varonis Threat Labs, Salesforce ghost sites are created when a company, instead of using unappealing internet URLs uses a custom domain name. This is done so that the or
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Read the original article: