
Salesforce 객체 접근 감사 도구
NCC Group Plc가 오픈소스로 공개했습니다 - https://www.nccgroup.com/
Jerome Smith 개발 @exploresecurity (Viktor Gazdag @wucpi에게 감사드립니다)
https://www.github.com/nccgroup/raccoon
AGPL 라이선스로 배포됩니다 - 자세한 내용은 LICENSE를 참조하세요.
이 도구는 유효 공유 및 객체 설정을 기반으로, 지정된 객체 집합의 모든 레코드에 대해 읽기/편집/삭제 권한의 일부 조합을 가진 프로필 및 권한 세트(활성 사용자가 있는)를 식별합니다. 이 출력을 통해 민감한 데이터를 보유한 객체에 과도한 접근을 허용할 수 있는 잘못된 구성을 조사할 수 있습니다. 배경 정보는 관련 블로그 게시물 https://research.nccgroup.com/2021/06/28/are-you-oversharing-in-salesforce 를 참조하세요.
결과는 Salesforce 구성을 직접 참조하거나 영향을 받는 프로필 및 권한 세트를 테스트하여 수동으로 검증하는 것이 좋습니다. 불일치 사항이 발견되면 가능한 한 자세히 이슈를 등록해 주시기 바랍니다.
요구 사항:
requests 모듈 (requirements.txt에 포함됨)인증을 위해 username + password + (선택) token 또는 sessionId 중 하나를 제공하세요 (자세한 내용은 인증 섹션 참조).
JSON 구성 파일을 만들고(또는 config.json을 템플릿으로 사용) 필요에 따라 작성합니다:
{
"hostname": "somewhere.my.salesforce.com",
"username": "",
"password": "",
"token": "<optional token>",
"sessionId": "",
"objects": ["Account", "Contact"],
"checkLimits": true,
"debug": <optional debug level (0, 1 or 2)>
}
objects는 관심 있는 Salesforce 객체의 목록입니다(즉, 가장 중요하게 생각하는 데이터). 공식 API 이름을 사용하는 것이 가장 확실한 방법이지만, 일치하는 항목이 없으면 Raccoon은 예를 들어 표시 레이블을 기준으로 몇 가지 간단한 일치를 시도합니다. Raccoon이 여전히 일치 항목을 찾지 못하면 프로그램은 계속 진행하되 출력에 이를 표시합니다.
checkLimits를 사용하면 조사 중인 인스턴스에 대해 24시간 이동 기간 내 남은 API 호출 허용량을 확인할 수 있습니다. Raccoon은 객체당 비교적 적은 호출을 수행하지만(실행당 고정된 횟수에 추가로), 진행 전에 한도를 확인할 수 있는 편의 기능입니다. 기본값은 true입니다. 체크포인트에서 남은 가능한 총 요청 수는 정확하지 않습니다. 호출 수는 'Controlled by Parent' 공유 모델을 가진 객체 수에 따라 달라지기 때문입니다. 표시된 숫자는 모든 객체가 그런 경우를 가정하므로 최대치입니다.
실행:
git clone https://github.com/nccgroup/raccoon
pip3 install -r requirements.txt
python3 raccoon.py <config_file>
사용자 이름과 비밀번호를 사용하는 경우 정의된 네트워크 액세스 범위 밖의 IP 주소에서 접근한다면 보안 토큰도 필요할 수 있습니다. 자세한 내용은 이 문서를 참조하세요.
세션 ID를 사용하는 대안은 여러 경우에 유용합니다:
세션 ID를 얻으려면:
sid 쿠키가 있습니다: Domain 속성에 my.salesforce.com 또는 cloudforce.com이 포함된 쿠키를 가져와야 합니다.샘플(축약 및 익명화) 출력:
Raccoon - Salesforce object access auditor
- version 1.0
- https://www.github.com/nccgroup/raccoon
* Refer to README for usage notes including important limitations *
Target instance: somewhere.my.salesforce.com
- Login successful
4,969,529 API requests can be sent to this instance from a 24-hour limit of 5,000,000
- Up to 33 further requests are required to complete (3 requests sent so far)
- Do you want to continue? Enter 'y' to proceed: y
Validating objects
- Found object 'Accounts' with API name 'Account'
- Found object 'Contact' with API name 'Contact'
- Found object 'Quotes' with API name 'Quote__c'
- Found object 'Quote Lines' with API name 'QuoteLine__c'
Evaluating 28 Profiles and 104 Permission Sets
- Profiles with active users: 15
- Permission Sets with active users: 67
- Ignoring 50 unused Profiles and Permission Sets
Global Sharing Overrides (ALL records for ALL objects)
------------------------------------------------------
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- System Administrator 61/91 [I]
READ
Profiles
- Integration User [C] 1/1 [I]
- Analytics Cloud Integration User 1/1 [I]
Object Sharing (ALL records for EACH object)
--------------------------------------------
Account:
Organization-wide default sharing
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User [C] 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
* Accounts PS Group [C] 36/39 [I]
- Sales Operations [C] 24/26 [I]
- SharePoint User [C] 3/4 [I]
Sharing Rules (manual check required):
- Criteria-based rules configured
- Ownership-based rules configured
Contact:
Organization-wide default sharing
- Internal: Controlled by Parent
- External: <Undefined>
Parent object: 'Account'
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
- Sales Operations [C] 24/26 [I]
Quote__c:
Organization-wide default sharing
- Internal: Public Read/Write
- External: <Undefined>
READ/EDIT [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Sales User [C] 192/248 [I]
READ
Profiles
- Finance User [C] 16/20 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
QuoteLine__c:
Organization-wide default sharing
- Internal: Controlled by Parent
- External: <Undefined>
Parent object: 'Quote__c'
- Internal: Public Read/Write
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Sales User [C] 192/248 [I]
READ
Profiles
- Finance User [C] 16/20 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
Total API requests sent: 31
Raccoon은 출력의 장황함을 줄이기 위해 활성 사용자가 있는 프로필과 권한 세트만 검사합니다. 이에 대한 정보가 표시된 후 다음이 수행됩니다: