<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Explore Security &#187; Salesforce</title>
	<atom:link href="https://www.exploresecurity.com/category/salesforce/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.exploresecurity.com</link>
	<description>IT security tools, techniques and commentary</description>
	<lastBuildDate>Wed, 15 Jun 2022 09:21:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6.1</generator>
		<item>
		<title>Exception Handling and Data Integrity in Salesforce</title>
		<link>https://www.exploresecurity.com/exception-handling-and-data-integrity-in-salesforce/</link>
		<comments>https://www.exploresecurity.com/exception-handling-and-data-integrity-in-salesforce/#comments</comments>
		<pubDate>Wed, 15 Jun 2022 09:21:02 +0000</pubDate>
		<dc:creator>Jerome</dc:creator>
				<category><![CDATA[Salesforce]]></category>

		<guid isPermaLink="false">http://www.exploresecurity.com/?p=481</guid>
		<description><![CDATA[Robust exception handling is one of the tenets of best practice for development, no matter what the coding language. This blog post, published in full on the NCC Group research site, explores the curious circumstances in which a developer trying to do the right thing – but without appreciating the full effects – could lead [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Robust exception handling is one of the tenets of best practice for development, no matter what the coding language. This <a href="https://research.nccgroup.com/2022/06/14/exception-handling-and-data-integrity-in-salesforce/">blog post</a>, published in full on the NCC Group research site, explores the curious circumstances in which a developer trying to do the right thing – but without appreciating the full effects – could lead to data integrity issues in a Salesforce Organization. These issues revolve around the automatic rollback mechanism that the Salesforce platform provides to try to maintain data integrity. However, as is so often the case, the devil is in the detail. On the basis of recent code reviews, it is apparently under-appreciated how the addition of exception handling in Apex (the Salesforce development language) can affect the rollback mechanism, which in turn can affect data integrity. The precise impact will vary according to what&#8217;s being done to which data, but the potential for consequences detrimental to security is clear.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.exploresecurity.com/exception-handling-and-data-integrity-in-salesforce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you oversharing (in Salesforce)?</title>
		<link>https://www.exploresecurity.com/are-you-oversharing-in-salesforce/</link>
		<comments>https://www.exploresecurity.com/are-you-oversharing-in-salesforce/#comments</comments>
		<pubDate>Mon, 28 Jun 2021 11:42:18 +0000</pubDate>
		<dc:creator>Jerome</dc:creator>
				<category><![CDATA[Salesforce]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[tool]]></category>

		<guid isPermaLink="false">http://www.exploresecurity.com/?p=468</guid>
		<description><![CDATA[Unauthorised access to data is a primary concern of clients who commission a Salesforce assessment. The Salesforce documentation acknowledges that the sharing model is a &#8220;complex relationship between role hierarchies, user permissions, sharing rules, and exceptions for certain situations&#8221;. It is often said that complexity and security are natural enemies. Salesforce empowers its users with [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>Unauthorised access to data is a primary concern of clients who commission a Salesforce assessment. The Salesforce documentation acknowledges that the sharing model is a &#8220;complex relationship between role hierarchies, user permissions, sharing rules, and exceptions for certain situations&#8221;. It is often said that complexity and security are natural enemies. Salesforce empowers its users with a multifaceted sharing framework in order to cover a wide variety of business use cases. But with great power comes great responsibility. This <a href="https://research.nccgroup.com/2021/06/28/are-you-oversharing-in-salesforce/">blog post</a> over on the NCC Group research site discusses the topic of misconfigured sharing, and announces the release of a new open-source tool <a href="https://www.github.com/nccgroup/raccoon">Raccoon</a> to help identify such misconfigurations, which could otherwise expose sensitive data.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.exploresecurity.com/are-you-oversharing-in-salesforce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Salesforce Security with Remote Working</title>
		<link>https://www.exploresecurity.com/salesforce-security-with-remote-working/</link>
		<comments>https://www.exploresecurity.com/salesforce-security-with-remote-working/#comments</comments>
		<pubDate>Fri, 02 Oct 2020 11:38:18 +0000</pubDate>
		<dc:creator>Jerome</dc:creator>
				<category><![CDATA[Salesforce]]></category>
		<category><![CDATA[Event monitoring]]></category>

		<guid isPermaLink="false">http://www.exploresecurity.com/?p=466</guid>
		<description><![CDATA[With Coronavirus still active across the world, life is far from settled, but the uptake of remote working is surely here to stay. From a security standpoint, organisations may feel less comfortable at the moment simply because staff are working out of sight. Whether that feeling is justified will depend on the technical measures put [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>With Coronavirus still active across the world, life is far from settled, but the uptake of remote working is surely here to stay. From a security standpoint, organisations may feel less comfortable at the moment simply because staff are working out of sight. Whether that feeling is justified will depend on the technical measures put in place to facilitate remote working. Salesforce provides logging of authentication events as part of the standard platform. This <a href="https://research.nccgroup.com/2020/10/02/salesforce-security-with-remote-working/">blog post</a> over on the NCC Group research site takes a look at monitoring these events in various contexts as a way to increase assurance.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.exploresecurity.com/salesforce-security-with-remote-working/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Salesforce Policy Deviation Checker</title>
		<link>https://www.exploresecurity.com/salesforce-policy-deviation-checker/</link>
		<comments>https://www.exploresecurity.com/salesforce-policy-deviation-checker/#comments</comments>
		<pubDate>Tue, 29 Sep 2020 12:18:25 +0000</pubDate>
		<dc:creator>Jerome</dc:creator>
				<category><![CDATA[Salesforce]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.exploresecurity.com/?p=478</guid>
		<description><![CDATA[SFPolDevChk is a quick tool to show which Profiles in a Salesforce instance have become desynced from an Organization in terms of password and session policies, with any deviations highlighted. Published as an NCC Group open source project.]]></description>
				<content:encoded><![CDATA[<p>SFPolDevChk is a quick tool to show which Profiles in a Salesforce instance have become desynced from an Organization in terms of password and session policies, with any deviations highlighted. Published as an NCC Group open source <a href="https://github.com/nccgroup/SFPolDevChk">project</a>.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.exploresecurity.com/salesforce-policy-deviation-checker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Common Insecure Practices with Configuring and Extending Salesforce</title>
		<link>https://www.exploresecurity.com/common-insecure-practices-with-configuring-and-extending-salesforce/</link>
		<comments>https://www.exploresecurity.com/common-insecure-practices-with-configuring-and-extending-salesforce/#comments</comments>
		<pubDate>Tue, 02 Jun 2020 11:36:31 +0000</pubDate>
		<dc:creator>Jerome</dc:creator>
				<category><![CDATA[Salesforce]]></category>

		<guid isPermaLink="false">http://www.exploresecurity.com/?p=464</guid>
		<description><![CDATA[This blog post on the NCC Group research site discusses the most common findings from a sample of over 35 security assessments of Salesforce customer deployments. The assessments covered a mixture of configuration and code review, and the common issues were sorted into broad categories: Deviation From Salesforce Baseline Standard, Deviation From Security Best Practice, [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>This <a href="https://research.nccgroup.com/2020/06/02/common-insecure-practices-with-configuring-and-extending-salesforce/">blog post</a> on the NCC Group research site discusses the most common findings from a sample of over 35 security assessments of Salesforce customer deployments. The assessments covered a mixture of configuration and code review, and the common issues were sorted into broad categories: Deviation From Salesforce Baseline Standard, Deviation From Security Best Practice, Authentication Issues, File Handling, Insecure Code, Unhandled Security Alerts and Critical Updates Pending (now since merged by Salesforce), and Broken Access Controls.</p>
]]></content:encoded>
			<wfw:commentRss>https://www.exploresecurity.com/common-insecure-practices-with-configuring-and-extending-salesforce/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
