用 ForceHound 走通一条攻击路径
netspi.com | 博客 | #privilege-escalation | #bloodhound | #attack-path | #salesforce | #open-source-tools | #forcehound | #crm-security
摘要
ForceHound 系列第二篇:借助 BloodHound 图数据演示两种 Salesforce 提权场景——普通用户经 ManageUsers/AssignPermissionSets 传递式获取 ModifyAllData,以及未限制授权范围的 Connected App 暴露面分析。
- 发布时间
- 收录时间
Skip to content