hack::cheltenham | Slightly SOSLed - Locating and Testing SOSL Injection | Nick Dunn @IOActive
hack::cheltenham | Slightly SOSLed - Locating and Testing SOSL Injection | Nick Dunn  @IOActive
Uploaded October 2024 | Updated September 2026, 1 week ago
Nick Dunn, IOActive Senior Security Consultant, presented an exploration into SOSL injection vulnerabilities in February 2024 during a hack::cheltenham event.

ABSTRACT:

The Salesforce platform allows a platform-specific vulnerability within the Apex code, known as SOSL injection; while conceptually similar to SQL injection, the testing and exploitation entails different payloads and approaches.

With concerns stemming from the minimal documentation available online, the exploration will attempt to shed light on the Apex code and custom API issue - its consequences and the working methods for detecting and confirming the existence of the vulnerabilities found within; probing in detail the different payloads useful for detection and exploitation, the consequences of a vulnerable site and finally, discussions on solutions to fix the occurrences of the issue.

Learn more about IOActive by visiting our website: ioactive.com
hack::cheltenham | Slightly SOSLed - Locating and Testing SOSL Injection | Nick Dunnhack::soho | Lost in Translation: Challenges of Internationalisation | Colin CassidyBreaking Bad: The Science Behind Security Intelligence - IOActivehack::soho | May 2026 | Ham Radio for Hackers: Its illegal to push this buttonhack::soho | Agentic AI in the Wild: Risks, Reality & Framework | Max Corbridge, Secure AgenticsIOActive Webinar | Are You Trading Stocks Securely? Exposing Security Flaws in Trading TechnologiesIOActive Freakshow Party- Gladiator Joust Test Round!Fake coins by Fernando Arnaboldi, IOActivehack::soho | Lessons from the Demo Scene | Pete Beckhack::soho | Reviewing COBOL for Fun and Profit | Nick DunnIOActive Research | Owning a Bitcoin ATM | leveraging the glitch cliphack::soho | Introducing wSAST - Code Analysis Framework for Consultants | Peter Winter-Smith
IOActive, Inc. |

hack::cheltenham | Slightly SOSL'ed - Locating and Testing SOSL Injection | Nick Dunn

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER