Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
SAN JOSE, CA -- (Marketwired) -- 08/12/15 -- Elastica (www.elastica.net), the leader in Data Science Powered Cloud Application Security, today released details about an injection vulnerability disclosed to Salesforce in early July which opened the door for attackers to use a trusted Salesforce application as a platform to conduct phishing attacks to steal end-users' login credentials and hijack accounts. On August 10, Salesforce patched the vulnerability, a finding validated by Elastica researchers.
Because the vulnerability existed in an actual Salesforce subdomain, end-users receiving phishing emails with the URL would likely have had no way of identifying it as malicious and there is a high probability such a URL would not have been detected by spam filters or other anti-phishing solutions. This vulnerability could have been used to attack Salesforce end-users, steal credentials and ultimately hijack accounts. Elastica researchers considered this to be a threat, as millions of users around the world log in to Salesforce every day.
Elastica reported the discovery to Salesforce, following standard disclosure guidelines for giving the company time to respond and address the issue. Elastica also provided details on how to mitigate the vulnerability. Because the vulnerability existed in a subdomain versus the primary Salesforce website, Salesforce considered it a low-impact threat.
Elastica Cloud Threat Labs discovered the vulnerability in "admin.salesforce.com," a subdomain used by Salesforce for blogging purposes. According to threat researchers, this particular subdomain was susceptible to a reflected Cross-site Scripting (XSS) vulnerability, where a specific function in the deployed application failed to filter the arbitrary input passed by the remote user as part of an HTTP request. The use of Salesforce's trusted server provided an opportunity for attackers to execute JavaScript to steal cookies and session identifiers, force users to visit phishing sites that extract credentials, and distribute malicious code to user machines. As detailed in the Elastica blog, the flaw enabled attackers to:
"Exploitation of XSS vulnerabilities is among the most prolific methods of Web application hacking today," said Dr. Aditya K. Sood, lead architect of Elastica Cloud Threat Labs. "Although this particular flaw was only present in a Salesforce subdomain, exploiting the trust of the company's primary domain could have allowed attackers to easily implement phishing attacks to gain access to user credentials. With stolen credentials, attackers can then access users' accounts and exfiltrate sensitive data undetected for long periods of time."
Salesforce uses Single Sign On (SSO), enabling users to easily access a variety of integrated applications through a central login. If phishing attacks implemented through this vulnerability were successful, attackers who secure login credentials gained access to a host of other services, including cloud applications, potentially multiplying the effects of the breach significantly.
The use of SSO makes this vulnerability a viable threat to all SaaS applications. If user login credentials are compromised, the attackers have the ability to infiltrate a variety of cloud applications accessible through the service. The Elastica CloudSOC solution mitigates this risk by using advanced data science to detect malicious behavior occurring within these apps and enables organizations to take immediate action if breached.
For an in-depth analysis of the Salesforce XSS flaw and accompanying video, please visit the Elastica Cloud Threat Labs blog: https://www.elastica.net/?p=2455
Interact with Elastica:
Join Elastica on LinkedIn: https://www.linkedin.com/company/elastica
Like Elastica on Facebook: https://www.facebook.com/ElasticaInc
Follow Elastica on Twitter: https://twitter.com/elasticainc
About Elastica:
Elastica is the leader in Data Science Powered Cloud Application Security. Its CloudSOC platform empowers companies to confidently leverage cloud applications and services while staying safe, secure and compliant. A range of Elastica Security Apps deployed on the extensible CloudSOC platform deliver the full life cycle of cloud application security, including auditing of shadow IT, real-time detection of intrusions and threats, protection against intrusions and compliance violations, and investigation of historical account activity for post-incident analysis. Elastica is venture-backed by the Mayfield Fund, Pelion Ventures, Third Point Ventures and is headquartered in San Jose, CA.
Learn more about Elastica at http://www.elastica.net.
Media Contact for Elastica
Aparna Aswani
Bhava Communications for Elastica
press@elastica.net
415-699-8331
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs
Publicado el 11-Oct-2016 • 12.48hs
Publicado el 15-Mar-2016 • 11.59hs
Publicado el 2-Feb-2017 • 11.38hs
Publicado el 20-Jun-2014 • 17.17hs
Publicado el 31-May-2011 • 05.13hs
Publicado el 25-Set-2008 • 17.54hs
Publicado el 1-Set-2016 • 16.11hs
Publicado el 31-Ago-2016 • 18.53hs
Publicado el 19-Ene-2017 • 15.47hs
Publicado el 4-Jul-2016 • 18.51hs