
Salesforce ऑब्जेक्ट एक्सेस ऑडिटर
NCC Group Plc द्वारा ओपन सोर्स के रूप में जारी - https://www.nccgroup.com/
Jerome Smith @exploresecurity द्वारा विकसित (Viktor Gazdag @wucpi को धन्यवाद के साथ)
https://www.github.com/nccgroup/raccoon
AGPL के अंतर्गत जारी - अधिक जानकारी के लिए LICENSE देखें।
यह टूल पता लगाता है कि कौन से Profiles और Permission Sets (सक्रिय उपयोगकर्ताओं वाले) में ऑब्जेक्ट्स के दिए गए समूह के सभी रिकॉर्ड्स तक पढ़ने/संपादित/हटाने की अनुमतियों का कुछ संयोजन है, उनकी प्रभावी साझाकरण और ऑब्जेक्ट सेटिंग्स के आधार पर। इस आउटपुट से, उन गलत कॉन्फ़िगरेशनों की जाँच की जा सकती है जो संवेदनशील डेटा रखने वाले ऑब्जेक्ट्स तक अत्यधिक पहुँच की अनुमति दे सकते हैं। पृष्ठभूमि के लिए साथ में दी गई ब्लॉग पोस्ट देखें https://research.nccgroup.com/2021/06/28/are-you-oversharing-in-salesforce।
अनुशंसा की जाती है कि परिणामों को Salesforce कॉन्फ़िगरेशन के सीधे संदर्भ और/या प्रभावित Profiles और Permission Sets के परीक्षण के साथ मैन्युअल रूप से सत्यापित किया जाए। यदि विसंगतियाँ मिलें, तो कृपया अधिक से अधिक विवरण के साथ issue दर्ज करें।
आवश्यकताएँ:
requests मॉड्यूल (requirements.txt द्वारा कवर्ड)username + password + (वैकल्पिक) token या sessionId प्रदान करें (अधिक विवरण Authentication अनुभाग में)।एक JSON कॉन्फ़िग फ़ाइल बनाएँ (या config.json को टेम्पलेट के रूप में उपयोग करें) और आवश्यकतानुसार भरें:
{
"hostname": "somewhere.my.salesforce.com",
"username": "",
"password": "",
"token": "<optional token>",
"sessionId": "",
"objects": ["Account", "Contact"],
"checkLimits": true,
"debug": <optional debug level (0, 1 or 2)>
}
objects आपके लिए महत्वपूर्ण Salesforce ऑब्जेक्ट्स की सूची है (यानी वह डेटा जिसकी आप सबसे अधिक परवाह करते हैं)। औपचारिक API नामों का उपयोग करना सबसे विश्वसनीय तरीका है, लेकिन यदि कोई मेल नहीं मिलता है, तो Raccoon कुछ सरल मिलानों का प्रयास करेगा, उदाहरण के लिए प्रदर्शित लेबल के आधार पर। यदि Raccoon को अभी भी कोई मेल नहीं मिलता है, तो प्रोग्राम आगे बढ़ेगा लेकिन आउटपुट में इसे चिह्नित करेगा।
checkLimits आपको जाँच करने की सुविधा देता है कि जाँचे जा रहे इंस्टेंस के लिए 24 घंटे की घूमती अवधि में कितने API कॉल शेष हैं। Raccoon प्रति ऑब्जेक्ट अपेक्षाकृत कम कॉल करता है (प्रति रन एक निश्चित संख्या के अतिरिक्त), लेकिन शिष्टाचार के रूप में, यह पैरामीटर आपको आगे बढ़ने से पहले अपनी सीमाएँ जाँचने की अनुमति देता है। डिफ़ॉल्ट मान true है। चेकपॉइंट पर संभावित शेष अनुरोधों की कुल संख्या निश्चित नहीं है क्योंकि कॉलों की संख्या इस बात पर निर्भर करेगी कि कितने ऑब्जेक्ट में 'Controlled by Parent' साझाकरण मॉडल है। बताई गई संख्या यह मानकर चलती है कि सभी में यही है और इस प्रकार यह अधिकतम सीमा है।
चलाएँ:
git clone https://github.com/nccgroup/raccoon
pip3 install -r requirements.txt
python3 raccoon.py <config_file>
जब उपयोगकर्ता नाम और पासवर्ड का उपयोग किया जाता है, तो ध्यान दें कि सुरक्षा टोकन की भी आवश्यकता हो सकती है (यदि किसी परिभाषित Network Access सीमा के बाहर किसी IP पते से आ रहे हैं)। अधिक जानकारी के लिए इस लेख को देखें।
session ID विकल्प का उपयोग कई मामलों में उपयोगी है:
session ID प्राप्त करने के लिए:
sid कुकीज़ होती हैं: सुनिश्चित करें कि आप उसे लें जिसकी Domain विशेषता में my.salesforce.com या cloudforce.com शामिल होनमूना (संक्षिप्त और अनामीकृत) आउटपुट:
Raccoon - Salesforce object access auditor
- version 1.0
- https://www.github.com/nccgroup/raccoon
* Refer to README for usage notes including important limitations *
Target instance: somewhere.my.salesforce.com
- Login successful
4,969,529 API requests can be sent to this instance from a 24-hour limit of 5,000,000
- Up to 33 further requests are required to complete (3 requests sent so far)
- Do you want to continue? Enter 'y' to proceed: y
Validating objects
- Found object 'Accounts' with API name 'Account'
- Found object 'Contact' with API name 'Contact'
- Found object 'Quotes' with API name 'Quote__c'
- Found object 'Quote Lines' with API name 'QuoteLine__c'
Evaluating 28 Profiles and 104 Permission Sets
- Profiles with active users: 15
- Permission Sets with active users: 67
- Ignoring 50 unused Profiles and Permission Sets
Global Sharing Overrides (ALL records for ALL objects)
------------------------------------------------------
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- System Administrator 61/91 [I]
READ
Profiles
- Integration User [C] 1/1 [I]
- Analytics Cloud Integration User 1/1 [I]
Object Sharing (ALL records for EACH object)
--------------------------------------------
Account:
Organization-wide default sharing
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User [C] 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
* Accounts PS Group [C] 36/39 [I]
- Sales Operations [C] 24/26 [I]
- SharePoint User [C] 3/4 [I]
Sharing Rules (manual check required):
- Criteria-based rules configured
- Ownership-based rules configured
Contact:
Organization-wide default sharing
- Internal: Controlled by Parent
- External: <Undefined>
Parent object: 'Account'
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
- Sales Operations [C] 24/26 [I]
Quote__c:
Organization-wide default sharing
- Internal: Public Read/Write
- External: <Undefined>
READ/EDIT [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Sales User [C] 192/248 [I]