Skip to content

Commit 6a5200e

Browse files
authored
Merge pull request OWASP-Benchmark#129 from zirons1/master
Update Contrast config flags and Contrast readme.txt
2 parents 526355b + 2076f75 commit 6a5200e

File tree

2 files changed

+3
-4
lines changed

2 files changed

+3
-4
lines changed

pom.xml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -298,9 +298,8 @@
298298
-Dcontrast.dir=${basedir}/tools/Contrast/working
299299
-Dcontrast.log.daily=true
300300
-Dcontrast.level=debug
301-
-Dcontrast.noteamserver.enable=true
302-
-Dcontrast.teamserver.suppress=true
303301
-Dcontrast.assess.threshold.entries=100000
302+
-Dcontrast.agent.java.standalone_app_name=OWASPBenchmark
304303
</cargo.jvmargs>
305304
<cargo.servlet.port>8443</cargo.servlet.port>
306305
<cargo.protocol>https</cargo.protocol>

tools/Contrast/readme.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,6 @@ DISCLAIMER: OWASP does not endorse any commercial tools, including this one. Ben
22

33
Contrast is a commercial tool. If you are interested in running Contrast on the Benchmark, you'll have to get a license for it from the vendor just like you would for any commercial tool. Once you have it, you need to place the contrast.jar file in this directory in order to run the Benchmark with Contrast using one of the runBenchmark_wContrast scripts, and then crawl the Benchmark to generate scan results with one of the runCrawler scripts.
44

5-
See the Tool Scanning Tips page at OWASP (https://owasp.org/www-project-benchmark/#div-scanning_tips) for the latest instructions on how to scan the Benchmark with any vulnerability detection tool, including Contrast.
5+
Contrast has also released Contrast Community Edition (CE), which is free, subject to the terms of its use. If you don't have a commercial license for Contrast, you must use Contrast CE on Benchmark. See: https://www.contrastsecurity.com/community-edition-lp for more information.
66

7-
Contrast has released Contrast Community Edition (CE), which is free, subject to the terms of its use. If you don't have a commercial license for Contrast, it is likely you can use Contrast CE on Benchmark. See: https://www.contrastsecurity.com/community-edition-lp for more information.
7+
See the Tool Scanning Tips page at OWASP (https://owasp.org/www-project-benchmark/#div-scanning_tips) for the latest instructions on how to scan the Benchmark with any vulnerability detection tool, including Contrast.

0 commit comments

Comments
 (0)