Skip to content

Conversation

@zirons1
Copy link

@zirons1 zirons1 commented Nov 24, 2020

Dave, is it possible to also edit the content under Contrast Assess on this page: https://owasp.org/www-project-benchmark/#div-scanning_tips. In order for the Contrast agent to work with the OWASP Benchmark, a user will need to set some environment variables that the agent can pick up.

@zirons1
Copy link
Author

zirons1 commented Nov 24, 2020

The first paragraph could be edited to look something like this.

To use Contrast Assess, we simply add the Java agent to the Benchmark environment and run the BenchmarkCrawler. You must also export the following configuration settings as environment variables. These values are displayed under User Settings -> Your Keys when logged into a Contrast TeamServer instance: CONTRAST__API__API_KEY, CONTRAST__API__SERVICE_KEY, and CONTRAST__API__URL.

keys

You also must set the username configuration setting as an environment variable: CONTRAST__API__USER_NAME. This is the username used to login to your TeamServer instance. The entire process should only take a few minutes. We provided a few scripts, which simply add the -javaagent:contrast.jar flag to the Benchmark launch configuration. We have tested on MacOS, Ubuntu, and Windows. Be sure your VM has at least 4M of memory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants