Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
raccoon — Salesforce 对象访问审计器 | Kitploit
工具/GitHubGitHub/nccgroup/raccoon
云基础设施安全漏洞分析配置审计云安全身份与访问管理 (IAM)错误配置数据库安全
GitHubnccgroup/raccoon

raccoon

Salesforce 对象访问审计器

查看仓库
1187203年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
网站

Raccoon:Salesforce 对象访问审计器

由 NCC Group Plc 以开源形式发布 - https://www.nccgroup.com/

由 Jerome Smith @exploresecurity 开发(感谢 Viktor Gazdag @wucpi)

https://www.github.com/nccgroup/raccoon

根据 AGPL 发布 - 更多信息请参阅 LICENSE。

描述

该工具基于有效的共享和对象设置,确定哪些配置文件(Profile)和权限集(Permission Set)(具有活跃用户)对给定对象集中的所有记录具有某些读取/编辑/删除权限组合。通过此输出,可以调查那些可能允许过度访问包含敏感数据的对象的错误配置。相关背景请参阅随附的博客文章 https://research.nccgroup.com/2021/06/28/are-you-oversharing-in-salesforce。

建议直接参考 Salesforce 配置和/或对受影响的配置文件与权限集进行测试,以手动验证结果。如果发现差异,请提交问题,并提供尽可能多的详细信息。

使用方法

要求:

  • Python 3
  • Python requests 模块(由 requirements.txt 覆盖)
  • 一个具有以下最低权限的账户:
    • “API Enabled”
    • “View Setup and Configuration”
    • “Modify Metadata Through Metadata API Functions”(参见‘账户权限’说明)
    • 对所有待审计对象的读取权限(或授予“View All Data”)
  • 对于身份验证,请提供 username + password +(可选)token 或 sessionId(更多详情见身份验证部分)。

创建一个 JSON 配置文件(或将 config.json 用作模板),并按需填写:

{
	"hostname": "somewhere.my.salesforce.com",
	"username": "",
	"password": "",
	"token": "<optional token>",
	"sessionId": "",
	"objects": ["Account", "Contact"],
	"checkLimits": true,
	"debug": <optional debug level (0, 1 or 2)>
}

objects 是您关注的 Salesforce 对象列表(即您最关心的数据)。使用正式的 API 名称是最可靠的方法,但如果找不到匹配项,Raccoon 将尝试基于(例如)显示标签进行一些简单匹配。如果 Raccoon 仍然找不到匹配项,程序将继续运行,但会在输出中标记出来。

checkLimits 允许您检查所调查实例在 24 小时滚动周期内剩余的 API 调用配额。Raccoon 对每个对象进行的调用相对较少(此外每次运行还有固定数量的调用),但出于礼貌,此参数允许您在继续之前检查您的限制。默认值为 true。检查点的可能剩余请求总数并不确定,因为调用次数将取决于有多少对象采用“Controlled by Parent”共享模型。所述数字假定所有对象都采用该模型,因此是一个最大值。

运行:

git clone https://github.com/nccgroup/raccoon
pip3 install -r requirements.txt
python3 raccoon.py <config_file>

身份验证

使用用户名和密码时,请注意可能还需要安全令牌(如果来自任何已定义网络访问范围之外的 IP 地址)。更多信息请参阅这篇文章。

在许多情况下,使用会话 ID 替代方法很有用:

  • 单点登录,即无法直接登录 Salesforce
  • 已强制启用 MFA
  • 获取 API 令牌困难(需要时)
  • 避免凭据意外遗留在文件中

获取会话 ID 的方法:

  • 登录 Salesforce,如有必要请切换到经典模式
  • 使用浏览器的 Inspect 工具显示 Cookie
  • 有时会有多个 sid Cookie:请确保选择其 Domain 属性包含 my.salesforce.com 或 cloudforce.com 的那个

输出

示例(节选且匿名化的)输出:

Raccoon - Salesforce object access auditor
- version 1.0
- https://www.github.com/nccgroup/raccoon
* Refer to README for usage notes including important limitations *

Target instance: somewhere.my.salesforce.com
- Login successful

4,969,529 API requests can be sent to this instance from a 24-hour limit of 5,000,000
- Up to 33 further requests are required to complete (3 requests sent so far)
- Do you want to continue? Enter 'y' to proceed: y

Validating objects
- Found object 'Accounts' with API name 'Account'
- Found object 'Contact' with API name 'Contact'
- Found object 'Quotes' with API name 'Quote__c'
- Found object 'Quote Lines' with API name 'QuoteLine__c'

Evaluating 28 Profiles and 104 Permission Sets
- Profiles with active users: 15
- Permission Sets with active users: 67
- Ignoring 50 unused Profiles and Permission Sets

Global Sharing Overrides (ALL records for ALL objects)
------------------------------------------------------

  READ/EDIT/DELETE                           [C]ustom Active/Total [G]uest[E]xt[I]nt
  Profiles
  - System Administrator                              61/91                    [I]

  READ
  Profiles
  - Integration User                         [C]      1/1                      [I]
  - Analytics Cloud Integration User                  1/1                      [I]

Object Sharing (ALL records for EACH object)
--------------------------------------------

Account:
  Organization-wide default sharing
  - Internal: Public Read Only
  - External: <Undefined>

  READ/EDIT/DELETE                           [C]ustom Active/Total [G]uest[E]xt[I]nt
  Profiles
  - Integration User                         [C]      1/1                      [I]
  Permission Sets (* Groups)
  - Mulesoft Integration                     [C]      2/2                      [I]

  READ
  Profiles
  - Read Only                                [C]      192/199                  [I]
  - Sales User                               [C]      192/248                  [I]
  - Finance User                             [C]      16/20                    [I]
  - Standard User                                     6/3075                   [I]
  Permission Sets (* Groups)
  * Accounts PS Group                        [C]      36/39                    [I]
  - Sales Operations                         [C]      24/26                    [I]
  - SharePoint User                          [C]      3/4                      [I]

  Sharing Rules (manual check required):
  - Criteria-based rules configured
  - Ownership-based rules configured

Contact:
  Organization-wide default sharing
  - Internal: Controlled by Parent
  - External: <Undefined>
  Parent object: 'Account'
  - Internal: Public Read Only
  - External: <Undefined>

  READ/EDIT/DELETE                           [C]ustom Active/Total [G]uest[E]xt[I]nt
  Profiles
  - Integration User                                  1/1                      [I]
  Permission Sets (* Groups)
  - Mulesoft Integration                     [C]      2/2                      [I]

  READ
  Profiles
  - Read Only                                [C]      192/199                  [I]
  - Sales User                               [C]      192/248                  [I]
  - Finance User                             [C]      16/20                    [I]
  - Standard User                                     6/3075                   [I]
  Permission Sets (* Groups)
  - Sales Operations                         [C]      24/26                    [I]

Quote__c:
  Organization-wide default sharing
  - Internal: Public Read/Write
  - External: <Undefined>

  READ/EDIT                                  [C]ustom Active/Total [G]uest[E]xt[I]nt
  Profiles
  - Sales User                               [C]      192/248                  [I]

  READ
  Profiles
  - Finance User                             [C]      16/20                    [I]
  Permission Sets (* Groups)
  - Mulesoft Integration                     [C]      2/2                      [I]

QuoteLine__c:
  Organization-wide default sharing
  - Internal: Controlled by Parent
  - External: <Undefined>
  Parent object: 'Quote__c'
  - Internal: Public Read/Write
  - External: <Undefined>

  READ/EDIT/DELETE                           [C]ustom Active/Total [G]uest[E]xt[I]nt
  Profiles
  - Sales User                               [C]      192/248                  [I]

  READ
  Profiles
  - Finance User                             [C]      16/20                    [I]
  Permission Sets (* Groups)
  - Mulesoft Integration                     [C]      2/2                      [I]

Total API requests sent: 31

Raccoon 仅检查具有活跃用户的配置文件(Profile)和权限集(Permission Set),以减少输出中的冗余信息。程序会显示相关信息,之后:

  • 首先显示全局共享覆盖(Global Sharing Overrides),因为被允许具有“View All Data”和“Modify All Data”的配置文件与权限集对所有对象都拥有权限。
  • 然后依次审计每个对象,首先考虑读取+编辑+删除权限,其次是读取+编辑,最后仅读取。一个配置文件或权限集在输出中只会列出一次(位于包含最高有效权限集合的部分)。这是为了避免重复——例如,具有“Modify All Data”的配置文件显然对指定的所有对象都拥有读取+编辑+删除权限;因此,它只会显示在“Global Sharing Overrides”下,而不会同时出现在每个对象的结果中。唯一的例外是,具有全局“View All Data”权限的配置文件或权限集在对象级别启用了额外的编辑/删除权限。
  • 对于每个对象,会突出显示共享规则(Sharing Rules)的存在,但不会进一步说明其具体内容。

如果权限是通过权限集组(Permission Set Group)而非单个权限集授予的,则名称左侧会显示一个星号作为缩进标记,而不是通常的连字符(如上述示例输出中的 Accounts PS Group)。此外,还会显示该配置文件或权限集是否为自定义(对于权限集,自定义意味着“由管理员创建”,否则“是标准的,并与特定权限集许可证相关”[参考])。

下载工具