No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Salesforce ‘Ghost Sites’ Expose Sensitive Corporate Data

May 31, 2023
in Protection
0
Salesforce 'Ghost Sites' Expose Sensitive Corporate Data



Salesforce customers are abandoning their sites without deactivating them, leaving sensitive corporate, vendor, and user data behind.

The problem occurs within what the service calls “Communities,” busy sites that allow partners, vendors, and customers to collaborate within a company’s Salesforce environment. By their nature, Communities contain lots of potentially high-value business and personal information, which can be exposed when administrators aren’t diligent enough.

Sometimes, for example, companies will move from Salesforce to other providers, taking their domains with them. When they do that, though, many forget to erase what they’ve left behind. Researchers from Varonis are calling these forgotten Communities “ghost sites,” in a report published May 31.

Ghost sites may be forgotten, but they’re not without their hidden treasures. “It’s the same website, the same Community,” emphasizes Nitay Bachrach, security researcher for Varonis, “but now that things have changed, it’s more problematic. All of [the unerased data] is available for anyone.”

How Ghost Sites are Created

Every company wants a good, clean URL. For instance, a Salesforce customer called “Acme” might choose the custom domain “partners.acme.org” to point to its Community site at “partners.acme.org/00d400.live.siteforce.com.”

If Acme one day decides to leave Salesforce for another provider, it might choose to take “partners.acme.org” with them, modifying the DNS record to point to a new site hosted by, say, AWS. In this process, the researchers found, “many companies stop at just modifying DNS records. They do not remove the custom domain in Salesforce, nor do they deactivate the site.”

Put simply: While the URL has moved on, the site continues to exist, with all of the potentially sensitive communications, business records, and other business and personal information therein.

And it gets worse: Salesforce enables companies to automate the uploading of certain data streams that they may wish to share with partners and customers, using sharing rules.

“Basically, you set up a rule — you set up conditions — and any data that meets these conditions are shared,” explains Or Emanuel, Varonis’ director of research. “And this still applies for ghost sites because, again, Salesforce doesn’t know the difference. So the data, as long as it still meets the requirements, keeps [being sent out].”

The Risks Ghost Sites Pose

So what’s the problem with this situation? No malicious actor could easily know the precise internal domain associated with a company’s extant Salesforce site, after all. However, these sites can nonetheless be exploited.

The researchers pointed out that “tools that index and archive DNS records — such as SecurityTrails and other similar tools — makes identifying ghost sites much easier.”

Also, “because ghost sites are still active in Salesforce, the siteforce domain still resolves, meaning it’s available under the right circumstances,” according to the Varonis analysis. “A straightforward GET request results in an error — but there is another way to gain access.”

Specifically, attackers can simply change the host header: “This would trick Salesforce into believing that the site was accessed as “https://partners.acme.org/” and Salesforce would serve the site to the attacker.”

Adding to the risk is the fact that old, obsolete sites are less maintained and therefore less secure, increasing the ease of an attack.

Bottom line? When a Salesforce site is no longer active or needed, companies should always deactivate.

If they don’t, they leave not only their own data exposed, but also the data of the partners and users who have connected to their Community. And of course, partners and users don’t have the same ability to account for and deactivate sites they’ve merely connected to.

“So it’s [also] a risk management sense,” Bachrach says of the third-parties caught up in any potential mess.

Editorial Team

Editorial Team

Related Posts

You Can Get These Nothing Over-Ear Headphones for $79 Right Now
Protection

You Can Get These Nothing Over-Ear Headphones for $79 Right Now

March 19, 2026
Meta Has Announced the End of the Metaverse, and I'm a Little Sad
Protection

Meta Has Announced the End of the Metaverse, and I’m a Little Sad

March 19, 2026
The New Amazon Echo Studio Speaker Is Under $200 Right Now
Protection

The New Amazon Echo Studio Speaker Is Under $200 Right Now

March 18, 2026
Apple Finally Has a Fix for Your iPhone's Buggy Keyboard
Protection

Apple Finally Has a Fix for Your iPhone’s Buggy Keyboard

March 18, 2026
An Amazon Echo Spot Is Just $50 Right Now
Protection

An Amazon Echo Spot Is Just $50 Right Now

March 18, 2026
Spotify's New 'Exclusive Mode' Can Make Your Music Sound Better, but There's a Catch
Protection

Spotify’s New ‘Exclusive Mode’ Can Make Your Music Sound Better, but There’s a Catch

March 18, 2026
Load More
Next Post
Dow Jones Futures Fall Ahead Of House Debt-Ceiling Vote; C3.ai Dives Ahead Of Earnings

Dow Jones Futures Fall Ahead Of House Debt-Ceiling Vote; C3.ai Dives Ahead Of Earnings

Popular News

  • SEC approves tokenized securities to trade alongside traditional stocks

    SEC approves tokenized securities to trade alongside traditional stocks

    0 shares
    Share 0 Tweet 0
  • Bitcoin Vs. Quantum: Saylor Says The Threat Is Over A Decade Off

    0 shares
    Share 0 Tweet 0
  • The 6 biggest changes to Social Security over the past 20 years that affect how much money you’ll get in retirement

    0 shares
    Share 0 Tweet 0
  • 6 Best Forex Brokers in Malaysia for 2023 • Benzinga

    0 shares
    Share 0 Tweet 0
  • Eurazeo saw 86pc rise in private debt fundraising last year

    0 shares
    Share 0 Tweet 0

Latest News

Yen under pressure as BOJ and Fed hold rates steady

Yen under pressure as BOJ and Fed hold rates steady

March 19, 2026
0

Yen under pressure as BOJ and Fed hold rates steady

Institutions Are Using XRP As Collateral, Says Ripple Prime CEO

Institutions Are Using XRP As Collateral: Ripple Prime CEO

March 19, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ripple Prime is pitching XRP not just...

Investors react to BOJ’s decision to hold rates

Investors react to BOJ’s decision to hold rates

March 19, 2026
0

Investors react to BOJ’s decision to hold rates

SEC Approves Nasdaq Tokenization Trading Trial

SEC Approves Nasdaq Tokenization Trading Trial

March 19, 2026
0

Nasdaq has been given the regulatory green light to offer some tokenized stocks, which will trade alongside traditional securities on...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.