Mandiant open sources tool to prevent leaky Salesforce misconfigs

Mandiant has released an open source tool to help Salesforce admins detect misconfigurations that could expose sensitive data.

Launched on Monday, AuraInspector targets access control issues in Salesforce Aura, the UI framework for Experience Cloud sites. While Aura components aren't inherently insecure, their complexity often leads to dangerous misconfigurations.

An example? If unauthenticated users gain access to all records in a Salesforce Account object, attackers can exploit the getItems method to steal data.

"This is a common misconfiguration encountered during real-world engagements," Mandiant said in its announcement.

Though typically limited to 2,000-records per request, attackers can bypass this by changing sort orders. It's an inconsistent method, and one that may yield duplicate records for attackers.

Another way to bypass this limit is to abuse the functionality of the GraphQL API, which is made available by default to all guest accounts.

Salesforce maintains the API isn't a vulnerability if object access is properly configured, but misconfigurations can expose broad swaths of sensitive information.

Mandiant said AuraInspector can also help prevent attackers from gaining access to Record Lists and admin panels via Home URLs, while also supporting other use cases.

The tool, available now for free, automates potential abuse techniques and recommended remediation strategies to help defenders identify damaging misconfigurations.

Mandiant says all of AuraInspector's operations are read-only and the tool will not make any modifications to Salesforce instances on its own.

Despite many customers switching to Lightning Web Components for new sites, Aura is still widely used for legacy functionality, and security companies continue to issue alerts about the dangers of Aura misconfigurations.

Varonis, for example, warned in July it is trivial to locate Salesforce Experience Cloud sites, and its own researchers were able to retrieve "troves of exposed sensitive records" by abusing Aura methods.

Infosec blogger Brian Krebs also drew attention to widespread issues with Salesforce Community sites in 2023 after discovering that banks and healthcare providers were leaking sensitive data through similar means. ®

Search
About Us
Website HardCracked provides softwares, patches, cracks and keygens. If you have software or keygens to share, feel free to submit it to us here. Also you may contact us if you have software that needs to be removed from our website. Thanks for use our service!
IT News
Feb 7
Whether they are building agents or folding proteins, LLMs need a friend

interview AI pioneer Vishal Sikka warns to never trust an LLM that runs alone

Feb 7
Study confirms experience beats youthful enthusiasm

Research shows productivity and judgment peak decades after graduation

Feb 6
Four horsemen of the AI-pocalypse line up capex bigger than Israel's GDP

AIpocolypse Amazon, Google, Meta, Microsoft eye $635B in infrastructure spend

Feb 6
Supermarket sorry after facial recognition alert flags right criminal, wrong customer

System worked as intended, but staff then kicked out innocent bystander

Feb 6
Microsoft starts the countdown for the end of Exchange Web Services

Windows giant might try turning it off and on again to see who notices

Feb 6
Romanian rail workers accused of bribery turned to ChatGPT for legal tips

Corruption probe takes detour as staff facing trial reportedly asked AI if seat-blocking scams caused financial damage