| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 996a5de commit 6bf88e9
11 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -59,7 +59,6 @@ | |||
| 59 | 59 | <param-name>hstsIncludeSubDomains</param-name> | |
| 60 | 60 | <param-value>true</param-value> | |
| 61 | 61 | </init-param> | |
| 62 | - <async-supported>true</async-supported> | ||
| 63 | 62 | </filter> | |
| 64 | 63 | <filter-mapping> | |
| 65 | 64 | <filter-name>httpHeaderSecurity</filter-name> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -18,7 +18,6 @@ | |||
| 18 | 18 | */ | |
| 19 | 19 | ||
| 20 | 20 | import java.io.IOException; | |
| 21 | - import java.sql.SQLException; | ||
| 22 | 21 | ||
| 23 | 22 | import javax.servlet.Filter; | |
| 24 | 23 | import javax.servlet.FilterChain; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -59,8 +59,8 @@ | |||
| 59 | 59 | import org.owasp.benchmark.score.parsers.BurpReader; | |
| 60 | 60 | import org.owasp.benchmark.score.parsers.CASTAIPReader; | |
| 61 | 61 | import org.owasp.benchmark.score.parsers.CheckmarxESReader; | |
| 62 | - import org.owasp.benchmark.score.parsers.CheckmarxReader; | ||
| 63 | 62 | import org.owasp.benchmark.score.parsers.CheckmarxIASTReader; | |
| 63 | + import org.owasp.benchmark.score.parsers.CheckmarxReader; | ||
| 64 | 64 | import org.owasp.benchmark.score.parsers.ContrastReader; | |
| 65 | 65 | import org.owasp.benchmark.score.parsers.Counter; | |
| 66 | 66 | import org.owasp.benchmark.score.parsers.CoverityReader; | |
@@ -715,28 +715,29 @@ else if ( filename.endsWith( ".xml" ) ) { | |||
| 715 | 715 | ||
| 716 | 716 | String line1 = getLine( fileToParse, 0 ); | |
| 717 | 717 | String line2 = getLine( fileToParse, 1 ); | |
| 718 | + String line4; | ||
| 718 | 719 | ||
| 719 | - if ( line2.startsWith( " <ProjectName>" )) { | ||
| 720 | + if ( line2 != null && line2.startsWith( " <ProjectName>" )) { | ||
| 720 | 721 | tr = new ThunderScanReader().parse(fileToParse); | |
| 721 | 722 | } | |
| 722 | 723 | ||
| 723 | - else if ( line2.startsWith( "<pmd" )) { | ||
| 724 | + else if ( line2 != null && line2.startsWith( "<pmd" )) { | ||
| 724 | 725 | tr = new PMDReader().parse( fileToParse ); | |
| 725 | 726 | } | |
| 726 | 727 | ||
| 727 | - else if ( line2.toLowerCase().startsWith( "<castaip" ) ) { | ||
| 728 | + else if ( line2 != null && line2.toLowerCase().startsWith( "<castaip" ) ) { | ||
| 728 | 729 | tr = new CASTAIPReader().parse( fileToParse ); | |
| 729 | 730 | } | |
| 730 | 731 | ||
| 731 | - else if ( line2.startsWith( "<FusionLiteInsight" )) { | ||
| 732 | + else if ( line2 != null && line2.startsWith( "<FusionLiteInsight" )) { | ||
| 732 | 733 | tr = new FusionLiteInsightReader().parse( fileToParse ); | |
| 733 | 734 | } | |
| 734 | 735 | ||
| 735 | - else if ( line2.startsWith( "<XanitizerFindingsList" )) { | ||
| 736 | + else if ( line2 != null && line2.startsWith( "<XanitizerFindingsList" )) { | ||
| 736 | 737 | tr = new XanitizerReader().parse( fileToParse ); | |
| 737 | 738 | } | |
| 738 | 739 | ||
| 739 | - else if ( line2.startsWith( "<BugCollection" )) { | ||
| 740 | + else if ( line2 != null && line2.startsWith( "<BugCollection" )) { | ||
| 740 | 741 | tr = new FindbugsReader().parse( fileToParse ); | |
| 741 | 742 | ||
| 742 | 743 | // change the name of the tool if the filename contains findsecbugs | |
@@ -749,39 +750,41 @@ else if ( line2.startsWith( "<BugCollection" )) { | |||
| 749 | 750 | } | |
| 750 | 751 | } | |
| 751 | 752 | ||
| 752 | - else if ( line2.startsWith( "<ResultsSession" )) { | ||
| 753 | + else if ( line2 != null && line2.startsWith( "<ResultsSession" )) { | ||
| 753 | 754 | tr = new ParasoftReader().parse( fileToParse ); | |
| 754 | 755 | } | |
| 755 | 756 | ||
| 756 | - else if ( line2.startsWith( "<detailedreport" )) { | ||
| 757 | + else if ( line2 != null && line2.startsWith( "<detailedreport" )) { | ||
| 757 | 758 | tr = new VeracodeReader().parse( fileToParse ); | |
| 758 | 759 | } | |
| 759 | 760 | ||
| 760 | - else if ( line1.startsWith( "<total" )) { | ||
| 761 | + else if ( line1.startsWith( "<total" ) || line1.startsWith( "<p>" )) { | ||
| 761 | 762 | tr = new SonarQubeReader().parse( fileToParse ); | |
| 762 | 763 | } | |
| 763 | 764 | ||
| 764 | - else if ( line1.contains( "<OWASPZAPReport" ) || line2.contains( "<OWASPZAPReport" )) { | ||
| 765 | + else if ( line1.contains( "<OWASPZAPReport" ) || | ||
| 766 | + ( line2 != null && line2.contains( "<OWASPZAPReport" )) ) { | ||
| 765 | 767 | tr = new ZapReader().parse( fileToParse ); | |
| 766 | 768 | } | |
| 767 | 769 | ||
| 768 | - else if ( line2.startsWith( "<CxXMLResults" )) { | ||
| 770 | + else if ( line2 != null && line2.startsWith( "<CxXMLResults" )) { | ||
| 769 | 771 | tr = new CheckmarxReader().parse( fileToParse ); | |
| 770 | 772 | } | |
| 771 | 773 | ||
| 772 | - else if ( line2.contains( "Arachni" )) { | ||
| 774 | + else if ( line2 != null && line2.contains( "Arachni" )) { | ||
| 773 | 775 | tr = new ArachniReader().parse( fileToParse ); | |
| 774 | 776 | } | |
| 775 | 777 | ||
| 776 | - else if ( line2.startsWith( "<analysisResult") || line2.startsWith( "<analysisReportResult")) { | ||
| 778 | + else if ( line2 != null && (line2.startsWith( "<analysisResult") || | ||
| 779 | + line2.startsWith( "<analysisReportResult"))) { | ||
| 777 | 780 | tr = new JuliaReader().parse( fileToParse ); | |
| 778 | 781 | } | |
| 779 | 782 | ||
| 780 | - else if (line2.startsWith("<CodeIssueCollection")) { | ||
| 783 | + else if ( line2 != null && line2.startsWith("<CodeIssueCollection")) { | ||
| 781 | 784 | tr = new VisualCodeGrepperReader().parse(fileToParse); | |
| 782 | 785 | } | |
| 783 | 786 | ||
| 784 | - else if ( getLine( fileToParse, 4 ).contains( "Wapiti" )) { | ||
| 787 | + else if ( (line4 = getLine( fileToParse, 4 )) != null && line4.contains( "Wapiti" )) { | ||
| 785 | 788 | tr = new WapitiReader().parse( fileToParse ); | |
| 786 | 789 | } | |
| 787 | 790 | ||
@@ -910,50 +913,46 @@ else if ( filename.endsWith( ".sl" ) ) { | |||
| 910 | 913 | ||
| 911 | 914 | else System.out.println("Error: No matching parser found for file: " + filename); | |
| 912 | 915 | ||
| 913 | - // If the version # of the tool is specified in the results file name, extract it, and set it. | ||
| 914 | - // For example: Benchmark-1.1-Coverity-results-v1.3.2661-6720.json (the version # is 1.3.2661 in this example). | ||
| 915 | - // This code should also handle: Benchmark-1.1-Coverity-results-v1.3.2661.xml (where the compute time '-6720' isn't specified) | ||
| 916 | - int indexOfVersionMarker = filename.lastIndexOf("-v"); | ||
| 917 | - if ( indexOfVersionMarker != -1) { | ||
| 918 | - String restOfFileName = filename.substring(indexOfVersionMarker+2); | ||
| 919 | - int endIndex = restOfFileName.lastIndexOf('-'); | ||
| 920 | - if (endIndex == -1) endIndex = restOfFileName.lastIndexOf('.'); | ||
| 921 | - String version = restOfFileName.substring(0, endIndex); | ||
| 922 | - tr.setToolVersion(version); | ||
| 916 | + // If we have results, see if the version # is in the results file name. | ||
| 917 | + if (tr != null) { | ||
| 918 | + // If version # specified in the results file name, extract it, and set it. | ||
| 919 | + // For example: Benchmark-1.1-Coverity-results-v1.3.2661-6720.json (the version # is 1.3.2661 in this example). | ||
| 920 | + // This code should also handle: Benchmark-1.1-Coverity-results-v1.3.2661.xml (where the compute time '-6720' isn't specified) | ||
| 921 | + int indexOfVersionMarker = filename.lastIndexOf("-v"); | ||
| 922 | + if ( indexOfVersionMarker != -1) { | ||
| 923 | + String restOfFileName = filename.substring(indexOfVersionMarker+2); | ||
| 924 | + int endIndex = restOfFileName.lastIndexOf('-'); | ||
| 925 | + if (endIndex == -1) endIndex = restOfFileName.lastIndexOf('.'); | ||
| 926 | + String version = restOfFileName.substring(0, endIndex); | ||
| 927 | + tr.setToolVersion(version); | ||
| 928 | + } | ||
| 923 | 929 | } | |
| 924 | 930 | ||
| 925 | 931 | return tr; | |
| 926 | 932 | } | |
| 927 | 933 | ||
| 928 | 934 | /** | |
| 929 | - * Read the 2nd line of the provided file. If its blank, skip all blank lines until a non-blank line | ||
| 930 | - * is found and return that. Return "" if no none blank line is found from the second line on. | ||
| 931 | - * @return The first non-blank line in the file starting with the 2nd line. | ||
| 935 | + * Read the specified line of the provided file. If its blank, skip all blank lines until a non-blank | ||
| 936 | + * line is found and return that. Return "" if no non-blank line is found from the specified line on. | ||
| 937 | + * @return The first non-blank line in the file starting with the specified line. null if there aren't | ||
| 938 | + * that many lines in the file. | ||
| 932 | 939 | */ | |
| 933 | - private static String getLine(File actual, int line) { | ||
| 934 | - BufferedReader br = null; | ||
| 935 | - try { | ||
| 936 | - br = new BufferedReader( new FileReader( actual ) ); | ||
| 937 | - for ( int i=0; i<line; i++ ) { | ||
| 938 | - br.readLine(); // Skip line 1 | ||
| 939 | - } | ||
| 940 | - String line2 = ""; | ||
| 941 | - while ( line2.equals( "" ) ) { | ||
| 942 | - line2 = br.readLine(); | ||
| 943 | - } | ||
| 944 | - return line2; | ||
| 945 | - } catch( Exception e ) { | ||
| 946 | - return ""; | ||
| 947 | - } finally { | ||
| 948 | - try { | ||
| 949 | - if (br != null) br.close(); | ||
| 950 | - } catch (IOException e) { | ||
| 951 | - System.out.println("Can't close filereader for file: " + actual.getAbsolutePath() + | ||
| 952 | - " for some reason."); | ||
| 953 | - e.toString(); | ||
| 954 | - } | ||
| 955 | - } | ||
| 956 | - } | ||
| 940 | + private static String getLine(File actual, int lineNum) { | ||
| 941 | + | ||
| 942 | + try (BufferedReader br = new BufferedReader( new FileReader( actual )) ) { | ||
| 943 | + // Skip all the lines before the line # requested | ||
| 944 | + String line = null; | ||
| 945 | + for ( int i=0; i<=lineNum; i++ ) { | ||
| 946 | + line = br.readLine(); | ||
| 947 | + } | ||
| 948 | + while ( "".equals( line )) { | ||
| 949 | + line = br.readLine(); | ||
| 950 | + } | ||
| 951 | + return line; | ||
| 952 | + } catch( IOException e ) { | ||
| 953 | + return ""; | ||
| 954 | + } | ||
| 955 | + } | ||
| 957 | 956 | ||
| 958 | 957 | // Go through each expected result, and figure out if this tool actually passed or not. | |
| 959 | 958 | // This updates the expected results to reflect what passed/failed. | |
@@ -1267,6 +1266,7 @@ else if (scatter.getCommercialHigh() >= 50) | |||
| 1267 | 1266 | + new DecimalFormat("0.0").format((float) commercialHighTotal/(float) numberOfVulnCategories) + "</td>"); | |
| 1268 | 1267 | htmlForCommercialAverages.append("<td></td>"); | |
| 1269 | 1268 | htmlForCommercialAverages.append("</tr>\n"); | |
| 1269 | + htmlForCommercialAverages.append("</table>\n"); | ||
| 1270 | 1270 | ||
| 1271 | 1271 | try { | |
| 1272 | 1272 | ||
@@ -1340,7 +1340,6 @@ else if (r.truePositiveRate > .7 && r.falsePositiveRate < .3) | |||
| 1340 | 1340 | } | |
| 1341 | 1341 | } | |
| 1342 | 1342 | ||
| 1343 | - sb.append("</tr>\n"); | ||
| 1344 | 1343 | sb.append("</table>"); | |
| 1345 | 1344 | return sb.toString(); | |
| 1346 | 1345 | } | |
@@ -1384,7 +1383,6 @@ else if (or.getTruePositiveRate() > .7 && or.getFalsePositiveRate() < .3) | |||
| 1384 | 1383 | } | |
| 1385 | 1384 | } | |
| 1386 | 1385 | ||
| 1387 | - sb.append("</tr>\n"); | ||
| 1388 | 1386 | sb.append("</table>"); | |
| 1389 | 1387 | sb.append("<p>*-Please refer to each tool's scorecard for the data used to calculate these values."); | |
| 1390 | 1388 | ||
@@ -1401,14 +1399,14 @@ private static void updateMenus(Set<Report> toolResults, Set<String> catSet ) { | |||
| 1401 | 1399 | // Create tool menu | |
| 1402 | 1400 | StringBuffer sb = new StringBuffer(); | |
| 1403 | 1401 | for ( Report toolReport : toolResults ) { | |
| 1404 | - if (!(showAveOnlyMode && toolReport.isCommercial())) { | ||
| 1405 | - sb.append("<li><a href=\""); | ||
| 1406 | - sb.append(toolReport.getFilename()); | ||
| 1407 | - sb.append(".html\">"); | ||
| 1408 | - sb.append(toolReport.getToolNameAndVersion()); | ||
| 1409 | - sb.append("</a></li>"); | ||
| 1410 | - sb.append(System.lineSeparator()); | ||
| 1411 | - } | ||
| 1402 | + if (!(showAveOnlyMode && toolReport.isCommercial())) { | ||
| 1403 | + sb.append("<li><a href=\""); | ||
| 1404 | + sb.append(toolReport.getFilename()); | ||
| 1405 | + sb.append(".html\">"); | ||
| 1406 | + sb.append(toolReport.getToolNameAndVersion()); | ||
| 1407 | + sb.append("</a></li>"); | ||
| 1408 | + sb.append(System.lineSeparator()); | ||
| 1409 | + } | ||
| 1412 | 1410 | } | |
| 1413 | 1411 | ||
| 1414 | 1412 | // Before finishing, check to see if there is a commercial average scorecard file, and if so | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,7 +3,7 @@ | |||
| 3 | 3 | * | |
| 4 | 4 | * This file is part of the Open Web Application Security Project (OWASP) | |
| 5 | 5 | * Benchmark Project For details, please see | |
| 6 | - * <a href="https://www.owasp.org/index.php/Benchmark">https://www.owasp.org/index.php/Benchmark</a>. | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | 7 | * | |
| 8 | 8 | * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | |
| 9 | 9 | * of the GNU General Public License as published by the Free Software Foundation, version 2. | |
@@ -12,7 +12,7 @@ | |||
| 12 | 12 | * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
| 13 | 13 | * GNU General Public License for more details | |
| 14 | 14 | * | |
| 15 | - * @author Dave Wichers <a href="https://www.aspectsecurity.com">Aspect Security</a> | ||
| 15 | + * @author Dave Wichers | ||
| 16 | 16 | * @created 2015 | |
| 17 | 17 | */ | |
| 18 | 18 | ||
@@ -210,7 +210,7 @@ else if (r.truePositiveRate > .7 && r.falsePositiveRate < .3) | |||
| 210 | 210 | if (!Double.isNaN(r.score)) | |
| 211 | 211 | totalScore += r.score; | |
| 212 | 212 | } | |
| 213 | - sb.append("<th>Totals*</th><th/>"); | ||
| 213 | + sb.append("<tr><th>Totals*</th><th/>"); | ||
| 214 | 214 | sb.append("<th>" + totals.tp + "</th>"); | |
| 215 | 215 | sb.append("<th>" + totals.fn + "</th>"); | |
| 216 | 216 | sb.append("<th>" + totals.tn + "</th>"); | |
@@ -219,7 +219,7 @@ else if (r.truePositiveRate > .7 && r.falsePositiveRate < .3) | |||
| 219 | 219 | sb.append("<th>" + total + "</th>"); | |
| 220 | 220 | sb.append("<th/><th/><th/></tr>\n"); | |
| 221 | 221 | ||
| 222 | - sb.append("<th>Overall Results*</th><th/><th/><th/><th/><th/><th/>"); | ||
| 222 | + sb.append("<tr><th>Overall Results*</th><th/><th/><th/><th/><th/><th/>"); | ||
| 223 | 223 | double tpr = (totalTPR / scores.size()); | |
| 224 | 224 | sb.append("<th>" + new DecimalFormat("#0.00%").format(tpr) + "</th>"); | |
| 225 | 225 | double fpr = (totalFPR / scores.size()); | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -31,7 +31,6 @@ | |||
| 31 | 31 | import java.util.Set; | |
| 32 | 32 | ||
| 33 | 33 | import org.jfree.chart.ChartFactory; | |
| 34 | - import org.jfree.chart.ChartPanel; | ||
| 35 | 34 | import org.jfree.chart.JFreeChart; | |
| 36 | 35 | import org.jfree.chart.annotations.XYLineAnnotation; | |
| 37 | 36 | import org.jfree.chart.annotations.XYTextAnnotation; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -22,7 +22,6 @@ | |||
| 22 | 22 | import java.io.IOException; | |
| 23 | 23 | ||
| 24 | 24 | import org.jfree.chart.ChartFactory; | |
| 25 | - import org.jfree.chart.ChartPanel; | ||
| 26 | 25 | import org.jfree.chart.JFreeChart; | |
| 27 | 26 | import org.jfree.chart.plot.PlotOrientation; | |
| 28 | 27 | import org.jfree.chart.plot.XYPlot; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -28,7 +28,6 @@ | |||
| 28 | 28 | import java.util.Map.Entry; | |
| 29 | 29 | ||
| 30 | 30 | import org.jfree.chart.ChartFactory; | |
| 31 | - import org.jfree.chart.ChartPanel; | ||
| 32 | 31 | import org.jfree.chart.JFreeChart; | |
| 33 | 32 | import org.jfree.chart.annotations.XYTextAnnotation; | |
| 34 | 33 | import org.jfree.chart.plot.PlotOrientation; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -31,7 +31,6 @@ | |||
| 31 | 31 | import java.util.Set; | |
| 32 | 32 | ||
| 33 | 33 | import org.jfree.chart.ChartFactory; | |
| 34 | - import org.jfree.chart.ChartPanel; | ||
| 35 | 34 | import org.jfree.chart.JFreeChart; | |
| 36 | 35 | import org.jfree.chart.annotations.XYLineAnnotation; | |
| 37 | 36 | import org.jfree.chart.annotations.XYTextAnnotation; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -72,14 +72,14 @@ <h3>OWASP Benchmark Scorecard for Commercial Tools</h3> | |||
| 72 | 72 | ||
| 73 | 73 | <p>For more information, please visit the <a href="https://www.owasp.org/index.php/Benchmark">OWASP Benchmark Project Site</a>. | |
| 74 | 74 | ||
| 75 | - <p> | ||
| 76 | - <p> | ||
| 75 | + <p/> | ||
| 76 | + <p/> | ||
| 77 | 77 | ||
| 78 | 78 | <h2>Average Scores Per Vulnerability for Commercial Tools</h2> | |
| 79 | 79 | ${table} | |
| 80 | 80 | ||
| 81 | - <p> | ||
| 82 | - <p> | ||
| 81 | + <p/> | ||
| 82 | + <p/> | ||
| 83 | 83 | ||
| 84 | 84 | <h2>Key</h2> | |
| 85 | 85 | <table class="table"> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -83,20 +83,22 @@ <h2>Statistics</h2> | |||
| 83 | 83 | <th>Tool overall score (0-100)</th> | |
| 84 | 84 | <td>${score}</td> | |
| 85 | 85 | </tr> | |
| 86 | + <tr> | ||
| 86 | 87 | <th>Total test cases</th> | |
| 87 | 88 | <td>${tests}</td> | |
| 89 | + </tr> | ||
| 88 | 90 | <tr> | |
| 89 | 91 | <th>Download raw results</th> | |
| 90 | - <td><a href="${actualResultsFile}" download>Actual Results</a></td> | ||
| 92 | + <td><a href="${actualResultsFile}" >Actual Results</a></td> | ||
| 91 | 93 | </tr> | |
| 92 | 94 | </table> | |
| 93 | 95 | ||
| 94 | - <p> | ||
| 95 | - <p> | ||
| 96 | + <p/> | ||
| 97 | + <p/> | ||
| 96 | 98 | ||
| 97 | 99 | <h2>Detailed Results</h2> | |
| 98 | 100 | ${table} | |
| 99 | - <p> | ||
| 101 | + <p/> | ||
| 100 | 102 | ||
| 101 | 103 | ||
| 102 | 104 | <h2>Key</h2> | |
| Back | FazBrowse Home | New Git URL |
0 commit comments