WS4 - Salesforce Apex Predator: Breaking Salesforce Sites
Description
Instructed by: Nitay Bachrach
Level of Difficulty: Intermediate
Abstract:
Salesforce Sites are one of the most under-tested attack surfaces in enterprise security. When pentesters encounter them, most skip past - the Aura framework doesn't behave like a standard web application, and standard web testing techniques don't apply. Salesforce sites run on proprietary frameworks (Aura and LWR) with their own API surfaces, access models, and injection patterns. In March 2026, ShinyHunters demonstrated what that blind spot costs: sensitive data exfiltrated from hundreds of organizations through sites no one had tested.
This workshop teaches pentesters and red teamers a complete offensive methodology for Salesforce Experience Sites, going well past the record enumeration that makes up most public guidance on the topic.
Attendees will enumerate objects and dump records via the Aura API, then learn to identify and invoke custom Apex controllers running in system mode - controllers that bypass standard access management mechanisms, and which are surprisingly common and criminally underexplored. We cover SOQL injection in depth: why normal SQL injection tests fail, and how to exploit it. We cover deterministic route enumeration as an unauthenticated user, and LWR sites - Salesforce's next-generation framework - including the release of LWRed, a new open-source scanner built specifically for them.
Pre-Requisites:
Knowledge (required):
· No Salesforce experience needed - platform fundamentals are taught in the first module
· Basic familiarity with how web applications work (HTTP requests and responses)
Skills (recommended, not required):
· Web application penetration testing experience (comfortable with Burp Suite or an equivalent intercepting proxy)
· Familiarity with injection concepts - SQL injection experience is helpful but not required; SOQL is taught from scratch
Tickets for good, not greed Humanitix dedicates 100% of profits from booking fees to charity


