由 NCC Group Plc 以开源形式发布 - https://www.nccgroup.com/
由 Jerome Smith @exploresecurity 开发(感谢 Viktor Gazdag @wucpi)
https://www.github.com/nccgroup/raccoon
根据 AGPL 发布 - 更多信息请参阅 LICENSE。
该工具基于有效的共享和对象设置,确定哪些配置文件(Profile)和权限集(Permission Set)(具有活跃用户)对给定对象集中的所有记录具有某些读取/编辑/删除权限组合。通过此输出,可以调查那些可能允许过度访问包含敏感数据的对象的错误配置。相关背景请参阅随附的博客文章 https://research.nccgroup.com/2021/06/28/are-you-oversharing-in-salesforce。
建议直接参考 Salesforce 配置和/或对受影响的配置文件与权限集进行测试,以手动验证结果。如果发现差异,请提交问题,并提供尽可能多的详细信息。
要求:
requests 模块(由 requirements.txt 覆盖)username + password +(可选)token 或 sessionId(更多详情见身份验证部分)。创建一个 JSON 配置文件(或将 config.json 用作模板),并按需填写:
{
"hostname": "somewhere.my.salesforce.com",
"username": "",
"password": "",
"token": "<optional token>",
"sessionId": "",
"objects": ["Account", "Contact"],
"checkLimits": true,
"debug": <optional debug level (0, 1 or 2)>
}
objects 是您关注的 Salesforce 对象列表(即您最关心的数据)。使用正式的 API 名称是最可靠的方法,但如果找不到匹配项,Raccoon 将尝试基于(例如)显示标签进行一些简单匹配。如果 Raccoon 仍然找不到匹配项,程序将继续运行,但会在输出中标记出来。
checkLimits 允许您检查所调查实例在 24 小时滚动周期内剩余的 API 调用配额。Raccoon 对每个对象进行的调用相对较少(此外每次运行还有固定数量的调用),但出于礼貌,此参数允许您在继续之前检查您的限制。默认值为 true。检查点的可能剩余请求总数并不确定,因为调用次数将取决于有多少对象采用“Controlled by Parent”共享模型。所述数字假定所有对象都采用该模型,因此是一个最大值。
运行:
git clone https://github.com/nccgroup/raccoon
pip3 install -r requirements.txt
python3 raccoon.py <config_file>
使用用户名和密码时,请注意可能还需要安全令牌(如果来自任何已定义网络访问范围之外的 IP 地址)。更多信息请参阅这篇文章。
在许多情况下,使用会话 ID 替代方法很有用:
获取会话 ID 的方法:
sid Cookie:请确保选择其 Domain 属性包含 my.salesforce.com 或 cloudforce.com 的那个示例(节选且匿名化的)输出:
Raccoon - Salesforce object access auditor
- version 1.0
- https://www.github.com/nccgroup/raccoon
* Refer to README for usage notes including important limitations *
Target instance: somewhere.my.salesforce.com
- Login successful
4,969,529 API requests can be sent to this instance from a 24-hour limit of 5,000,000
- Up to 33 further requests are required to complete (3 requests sent so far)
- Do you want to continue? Enter 'y' to proceed: y
Validating objects
- Found object 'Accounts' with API name 'Account'
- Found object 'Contact' with API name 'Contact'
- Found object 'Quotes' with API name 'Quote__c'
- Found object 'Quote Lines' with API name 'QuoteLine__c'
Evaluating 28 Profiles and 104 Permission Sets
- Profiles with active users: 15
- Permission Sets with active users: 67
- Ignoring 50 unused Profiles and Permission Sets
Global Sharing Overrides (ALL records for ALL objects)
------------------------------------------------------
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- System Administrator 61/91 [I]
READ
Profiles
- Integration User [C] 1/1 [I]
- Analytics Cloud Integration User 1/1 [I]
Object Sharing (ALL records for EACH object)
--------------------------------------------
Account:
Organization-wide default sharing
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User [C] 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
* Accounts PS Group [C] 36/39 [I]
- Sales Operations [C] 24/26 [I]
- SharePoint User [C] 3/4 [I]
Sharing Rules (manual check required):
- Criteria-based rules configured
- Ownership-based rules configured
Contact:
Organization-wide default sharing
- Internal: Controlled by Parent
- External: <Undefined>
Parent object: 'Account'
- Internal: Public Read Only
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Integration User 1/1 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
READ
Profiles
- Read Only [C] 192/199 [I]
- Sales User [C] 192/248 [I]
- Finance User [C] 16/20 [I]
- Standard User 6/3075 [I]
Permission Sets (* Groups)
- Sales Operations [C] 24/26 [I]
Quote__c:
Organization-wide default sharing
- Internal: Public Read/Write
- External: <Undefined>
READ/EDIT [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Sales User [C] 192/248 [I]
READ
Profiles
- Finance User [C] 16/20 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
QuoteLine__c:
Organization-wide default sharing
- Internal: Controlled by Parent
- External: <Undefined>
Parent object: 'Quote__c'
- Internal: Public Read/Write
- External: <Undefined>
READ/EDIT/DELETE [C]ustom Active/Total [G]uest[E]xt[I]nt
Profiles
- Sales User [C] 192/248 [I]
READ
Profiles
- Finance User [C] 16/20 [I]
Permission Sets (* Groups)
- Mulesoft Integration [C] 2/2 [I]
Total API requests sent: 31
Raccoon 仅检查具有活跃用户的配置文件(Profile)和权限集(Permission Set),以减少输出中的冗余信息。程序会显示相关信息,之后:
如果权限是通过权限集组(Permission Set Group)而非单个权限集授予的,则名称左侧会显示一个星号作为缩进标记,而不是通常的连字符(如上述示例输出中的 Accounts PS Group)。此外,还会显示该配置文件或权限集是否为自定义(对于权限集,自定义意味着“由管理员创建”,否则“是标准的,并与特定权限集许可证相关”[参考])。