| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
1 parent 6bf88e9 commit ea01466
8 files changed
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -831,7 +831,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 831 | 831 | <dependency> | |
| 832 | 832 | <groupId>org.apache.httpcomponents</groupId> | |
| 833 | 833 | <artifactId>httpcore</artifactId> | |
| 834 | - <version>4.4.13</version> | ||
| 834 | + <version>4.4.14</version> | ||
| 835 | 835 | </dependency> | |
| 836 | 836 | ||
| 837 | 837 | <dependency> | |
@@ -912,7 +912,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 912 | 912 | <dependency> | |
| 913 | 913 | <groupId>org.json</groupId> | |
| 914 | 914 | <artifactId>json</artifactId> | |
| 915 | - <version>20200518</version> | ||
| 915 | + <version>20201115</version> | ||
| 916 | 916 | </dependency> | |
| 917 | 917 | ||
| 918 | 918 | <dependency> | |
@@ -924,7 +924,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 924 | 924 | <dependency> | |
| 925 | 925 | <groupId>org.owasp.esapi</groupId> | |
| 926 | 926 | <artifactId>esapi</artifactId> | |
| 927 | - <version>2.2.1.0</version> | ||
| 927 | + <version>2.2.2.0</version> | ||
| 928 | 928 | </dependency> | |
| 929 | 929 | ||
| 930 | 930 | <dependency> | |
@@ -1087,7 +1087,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 1087 | 1087 | <plugin> | |
| 1088 | 1088 | <groupId>org.apache.maven.plugins</groupId> | |
| 1089 | 1089 | <artifactId>maven-pmd-plugin</artifactId> | |
| 1090 | - <version>3.13.0</version> | ||
| 1090 | + <version>3.14.0</version> | ||
| 1091 | 1091 | <configuration> | |
| 1092 | 1092 | <linkXref>true</linkXref> | |
| 1093 | 1093 | <targetJdk>1.7</targetJdk> | |
@@ -1097,13 +1097,13 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 1097 | 1097 | <plugin> | |
| 1098 | 1098 | <groupId>org.apache.maven.plugins</groupId> | |
| 1099 | 1099 | <artifactId>maven-project-info-reports-plugin</artifactId> | |
| 1100 | - <version>3.1.0</version> | ||
| 1100 | + <version>3.1.1</version> | ||
| 1101 | 1101 | </plugin> | |
| 1102 | 1102 | ||
| 1103 | 1103 | <plugin> | |
| 1104 | 1104 | <groupId>org.apache.maven.plugins</groupId> | |
| 1105 | 1105 | <artifactId>maven-resources-plugin</artifactId> | |
| 1106 | - <version>3.1.0</version> | ||
| 1106 | + <version>3.2.0</version> | ||
| 1107 | 1107 | </plugin> | |
| 1108 | 1108 | ||
| 1109 | 1109 | <plugin> | |
@@ -1130,13 +1130,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 1130 | 1130 | <plugin> | |
| 1131 | 1131 | <groupId>org.codehaus.cargo</groupId> | |
| 1132 | 1132 | <artifactId>cargo-maven2-plugin</artifactId> | |
| 1133 | - <version>1.7.13</version> | ||
| 1134 | - </plugin> | ||
| 1135 | - | ||
| 1136 | - <plugin> | ||
| 1137 | - <groupId>org.codehaus.mojo</groupId> | ||
| 1138 | - <artifactId>sonar-maven-plugin</artifactId> | ||
| 1139 | - <version>3.7.1.1746</version> | ||
| 1133 | + <version>1.8.2</version> | ||
| 1140 | 1134 | </plugin> | |
| 1141 | 1135 | ||
| 1142 | 1136 | <!-- SpotBugs Static Analysis - the successor to FindBugs --> | |
@@ -1149,6 +1143,15 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 1149 | 1143 | <threshold>Low</threshold> | |
| 1150 | 1144 | <failOnError>true</failOnError> | |
| 1151 | 1145 | </configuration> | |
| 1146 | + <dependencies> | ||
| 1147 | + <!-- Overwrite dependency on SpotBugs if you want to specify the version of SpotBugs. | ||
| 1148 | + SpotBugs itself is frequently several versions ahead of the spotbugs-maven-plugin --> | ||
| 1149 | + <dependency> | ||
| 1150 | + <groupId>com.github.spotbugs</groupId> | ||
| 1151 | + <artifactId>spotbugs</artifactId> | ||
| 1152 | + <version>${version.spotbugs}</version> | ||
| 1153 | + </dependency> | ||
| 1154 | + </dependencies> | ||
| 1152 | 1155 | </plugin> | |
| 1153 | 1156 | ||
| 1154 | 1157 | <plugin> | |
@@ -1220,6 +1223,7 @@ But it might be needed for Java 10, because I get this error, that I don't get w | |||
| 1220 | 1223 | <version.jersey>1.19.4</version.jersey> | |
| 1221 | 1224 | <version.slf4j>1.7.30</version.slf4j> | |
| 1222 | 1225 | <version.spotbugs.maven>4.1.4</version.spotbugs.maven> | |
| 1226 | + <version.spotbugs>4.2.0</version.spotbugs> | ||
| 1223 | 1227 | <version.springframework>4.3.29.RELEASE</version.springframework> | |
| 1224 | 1228 | <!-- tomcat 8.5 is last version to support Java 7. Tomcat 9+ requires Java 8. --> | |
| 1225 | 1229 | <tomcat.major.version>8</tomcat.major.version> | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,3 +1,21 @@ | |||
| 1 | + /** | ||
| 2 | + * OWASP Benchmark Project | ||
| 3 | + * | ||
| 4 | + * This file is part of the Open Web Application Security Project (OWASP) | ||
| 5 | + * Benchmark Project For details, please see | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | + * | ||
| 8 | + * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | ||
| 9 | + * of the GNU General Public License as published by the Free Software Foundation, version 2. | ||
| 10 | + * | ||
| 11 | + * The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without | ||
| 12 | + * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| 13 | + * GNU General Public License for more details | ||
| 14 | + * | ||
| 15 | + * @author Juan GaMa | ||
| 16 | + * @created 2015 | ||
| 17 | + */ | ||
| 18 | + | ||
| 1 | 19 | package org.owasp.benchmark.helpers; | |
| 2 | 20 | ||
| 3 | 21 | import java.io.File; | |
@@ -15,7 +33,6 @@ | |||
| 15 | 33 | import org.apache.directory.server.ldap.LdapServer; | |
| 16 | 34 | import org.apache.directory.server.protocol.shared.transport.TcpTransport; | |
| 17 | 35 | import org.apache.directory.server.xdbm.Index; | |
| 18 | - import org.apache.directory.shared.ldap.entry.Entry; | ||
| 19 | 36 | import org.apache.directory.shared.ldap.entry.ServerEntry; | |
| 20 | 37 | import org.apache.directory.shared.ldap.name.DN; | |
| 21 | 38 | import org.apache.directory.shared.ldap.schema.SchemaManager; | |
@@ -45,9 +62,10 @@ public LDAPServer() { | |||
| 45 | 62 | } | |
| 46 | 63 | ||
| 47 | 64 | // Read an entry | |
| 48 | - Entry result = null; | ||
| 65 | + //Entry result = null; | ||
| 49 | 66 | try { | |
| 50 | - result = service.getAdminSession().lookup(new DN("dc=apache,dc=org")); | ||
| 67 | + //result = | ||
| 68 | + service.getAdminSession().lookup(new DN("dc=apache,dc=org")); | ||
| 51 | 69 | } catch (Exception e) { | |
| 52 | 70 | System.out.println("Error creating LDAP Server: " + e.getMessage()); | |
| 53 | 71 | } | |
@@ -100,6 +118,7 @@ private void initDirectoryService(File workDir){ | |||
| 100 | 118 | service = new DefaultDirectoryService(); | |
| 101 | 119 | } catch (Exception e1) { | |
| 102 | 120 | System.out.println("Error creating DefaultDirectoryService. " + e1.getMessage()); | |
| 121 | + e1.printStackTrace(); | ||
| 103 | 122 | } | |
| 104 | 123 | service.setWorkingDirectory(workDir); | |
| 105 | 124 | ||
@@ -113,6 +132,7 @@ private void initDirectoryService(File workDir){ | |||
| 113 | 132 | systemPartition = addPartition("system", ServerDNConstants.SYSTEM_DN); | |
| 114 | 133 | } catch (Exception e1) { | |
| 115 | 134 | System.out.println("Error addPartition system. " + e1.getMessage()); | |
| 135 | + e1.printStackTrace(); | ||
| 116 | 136 | } | |
| 117 | 137 | service.setSystemPartition(systemPartition); | |
| 118 | 138 | ||
@@ -127,18 +147,23 @@ private void initDirectoryService(File workDir){ | |||
| 127 | 147 | fooPartition = addPartition("foo", "dc=foo,dc=com"); | |
| 128 | 148 | } catch (Exception e1) { | |
| 129 | 149 | System.out.println("Error addPartition foo. " + e1.getMessage()); | |
| 150 | + e1.printStackTrace(); | ||
| 130 | 151 | } | |
| 152 | + | ||
| 131 | 153 | Partition barPartition = null; | |
| 132 | 154 | try { | |
| 133 | 155 | barPartition = addPartition("bar", "dc=bar,dc=com"); | |
| 134 | 156 | } catch (Exception e1) { | |
| 135 | 157 | System.out.println("Error addPartition bar. " + e1.getMessage()); | |
| 158 | + e1.printStackTrace(); | ||
| 136 | 159 | } | |
| 160 | + | ||
| 137 | 161 | Partition apachePartition = null; | |
| 138 | 162 | try { | |
| 139 | 163 | apachePartition = addPartition("apache", "dc=apache,dc=org"); | |
| 140 | 164 | } catch (Exception e1) { | |
| 141 | 165 | System.out.println("Error addPartition apache. " + e1.getMessage()); | |
| 166 | + e1.printStackTrace(); | ||
| 142 | 167 | } | |
| 143 | 168 | ||
| 144 | 169 | // Index some attributes on the apache partition | |
@@ -148,7 +173,9 @@ private void initDirectoryService(File workDir){ | |||
| 148 | 173 | service.startup(); | |
| 149 | 174 | } catch (Exception e) { | |
| 150 | 175 | System.out.println("Error at LDAP startup: " + e.getMessage()); | |
| 176 | + e.printStackTrace(); | ||
| 151 | 177 | } | |
| 178 | + | ||
| 152 | 179 | // Inject the foo root entry if it does not already exist | |
| 153 | 180 | try { | |
| 154 | 181 | service.getAdminSession().lookup(fooPartition.getSuffixDn()); | |
@@ -161,6 +188,7 @@ private void initDirectoryService(File workDir){ | |||
| 161 | 188 | service.getAdminSession().add(entryFoo); | |
| 162 | 189 | } catch (Exception e) { | |
| 163 | 190 | System.out.println("Error creating new DN."); | |
| 191 | + e.printStackTrace(); | ||
| 164 | 192 | } | |
| 165 | 193 | } | |
| 166 | 194 | ||
@@ -176,6 +204,7 @@ private void initDirectoryService(File workDir){ | |||
| 176 | 204 | service.getAdminSession().add(entryBar); | |
| 177 | 205 | } catch (Exception e) { | |
| 178 | 206 | System.out.println("Error creating new DN."); | |
| 207 | + e.printStackTrace(); | ||
| 179 | 208 | } | |
| 180 | 209 | } | |
| 181 | 210 | ||
@@ -190,12 +219,13 @@ private void initDirectoryService(File workDir){ | |||
| 190 | 219 | service.getAdminSession().add(entryApache); | |
| 191 | 220 | } catch (Exception e) { | |
| 192 | 221 | System.out.println("Error creating new DN."); | |
| 222 | + e.printStackTrace(); | ||
| 193 | 223 | } | |
| 194 | 224 | } | |
| 195 | 225 | } catch (Exception e) { | |
| 196 | 226 | System.out.println("Error when checking if partition exists."); | |
| 227 | + e.printStackTrace(); | ||
| 197 | 228 | } | |
| 198 | - | ||
| 199 | 229 | } | |
| 200 | 230 | ||
| 201 | 231 | /** | |
@@ -221,6 +251,8 @@ private void initSchemaPartition() { | |||
| 221 | 251 | extractor.extractOrCopy( true ); | |
| 222 | 252 | //System.out.println("is Extracted: " + extractor.isExtracted()); | |
| 223 | 253 | } catch (Exception e) { | |
| 254 | + System.out.println("ERROR: parsing LDAP schema"); | ||
| 255 | + e.printStackTrace(); | ||
| 224 | 256 | } | |
| 225 | 257 | ||
| 226 | 258 | schemaPartition.setWrappedPartition(ldifPartition); | |
@@ -233,7 +265,6 @@ private void initSchemaPartition() { | |||
| 233 | 265 | // to initialize the Partitions, as we won't be able to parse | |
| 234 | 266 | // and normalize their suffix DN | |
| 235 | 267 | schemaManager.loadAllEnabled(); | |
| 236 | - | ||
| 237 | 268 | schemaPartition.setSchemaManager(schemaManager); | |
| 238 | 269 | ||
| 239 | 270 | List<Throwable> errors = schemaManager.getErrors(); | |
@@ -242,6 +273,8 @@ private void initSchemaPartition() { | |||
| 242 | 273 | throw new Exception("Schema load failed : " + errors); | |
| 243 | 274 | } | |
| 244 | 275 | } catch (Exception e) { | |
| 276 | + System.out.println("ERROR: loading LDAP schema"); | ||
| 277 | + e.printStackTrace(); | ||
| 245 | 278 | } | |
| 246 | 279 | } | |
| 247 | 280 | ||
@@ -296,7 +329,6 @@ public void startServer() throws Exception { | |||
| 296 | 329 | int serverPort = 10389; | |
| 297 | 330 | server.setTransports(new TcpTransport(serverPort)); | |
| 298 | 331 | server.setDirectoryService(service); | |
| 299 | - | ||
| 300 | 332 | server.start(); | |
| 301 | 333 | } | |
| 302 | 334 | ||
@@ -312,12 +344,12 @@ public void stopServer() throws Exception { | |||
| 312 | 344 | /** | |
| 313 | 345 | * Main class. | |
| 314 | 346 | * | |
| 315 | - * @param args | ||
| 316 | - * Not used. | ||
| 347 | + * @param args Not used. | ||
| 317 | 348 | * @throws Exception | |
| 318 | 349 | */ | |
| 319 | 350 | public static void main(String[] args) throws Exception { | |
| 320 | - LDAPServer ldap = new LDAPServer(); | ||
| 351 | + //LDAPServer ldap = | ||
| 352 | + new LDAPServer(); | ||
| 321 | 353 | //ldap.stopServer(); | |
| 322 | 354 | } | |
| 323 | 355 | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -3,7 +3,7 @@ | |||
| 3 | 3 | * | |
| 4 | 4 | * This file is part of the Open Web Application Security Project (OWASP) | |
| 5 | 5 | * Benchmark Project For details, please see | |
| 6 | - * <a href="https://www.owasp.org/index.php/Benchmark">https://www.owasp.org/index.php/Benchmark</a>. | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | 7 | * | |
| 8 | 8 | * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | |
| 9 | 9 | * of the GNU General Public License as published by the Free Software Foundation, version 2. | |
@@ -12,7 +12,7 @@ | |||
| 12 | 12 | * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | |
| 13 | 13 | * GNU General Public License for more details | |
| 14 | 14 | * | |
| 15 | - * @author Dave Wichers <a href="https://www.aspectsecurity.com">Aspect Security</a> | ||
| 15 | + * @author Dave Wichers | ||
| 16 | 16 | * @created 2015 | |
| 17 | 17 | */ | |
| 18 | 18 | ||
@@ -46,6 +46,7 @@ public static enum ToolType { | |||
| 46 | 46 | private static int nextCommercialSAST_ToolNumber = 1; | |
| 47 | 47 | private static int nextCommercialDAST_ToolNumber = 1; | |
| 48 | 48 | private static int nextCommercialIAST_ToolNumber = 1; | |
| 49 | + private static int nextCommercialHybrid_ToolNumber = 1; | ||
| 49 | 50 | ||
| 50 | 51 | // The version of the Benchmark these test results are for | |
| 51 | 52 | private String benchmarkVersion = "notSet"; | |
@@ -121,6 +122,10 @@ public String getToolNameAndVersion() { | |||
| 121 | 122 | return this.toolName; | |
| 122 | 123 | } | |
| 123 | 124 | ||
| 125 | + /** | ||
| 126 | + * Get the version of the tool these results are from. | ||
| 127 | + * @return Version of the tool if determined. Null otherwise. | ||
| 128 | + */ | ||
| 124 | 129 | public String getToolVersion() { | |
| 125 | 130 | return toolVersion; | |
| 126 | 131 | } | |
@@ -151,13 +156,19 @@ public void setAnonymous() { | |||
| 151 | 156 | case DAST : { | |
| 152 | 157 | if (nextCommercialDAST_ToolNumber < 10) { | |
| 153 | 158 | this.setTool("DAST-0" + nextCommercialDAST_ToolNumber++); | |
| 154 | - } else this.setTool("DAST-" + nextCommercialDAST_ToolNumber++); | ||
| 159 | + } else this.setTool("DAST-" + nextCommercialDAST_ToolNumber++); | ||
| 155 | 160 | break; | |
| 156 | 161 | } | |
| 157 | 162 | case IAST : { | |
| 158 | 163 | if (nextCommercialIAST_ToolNumber < 10) { | |
| 159 | 164 | this.setTool("IAST-0" + nextCommercialIAST_ToolNumber++); | |
| 160 | - } else this.setTool("IAST-" + nextCommercialIAST_ToolNumber++); | ||
| 165 | + } else this.setTool("IAST-" + nextCommercialIAST_ToolNumber++); | ||
| 166 | + break; | ||
| 167 | + } | ||
| 168 | + case Hybrid : { | ||
| 169 | + if (nextCommercialHybrid_ToolNumber < 10) { | ||
| 170 | + this.setTool("HYBR-0" + nextCommercialHybrid_ToolNumber++); | ||
| 171 | + } else this.setTool("HYBR-" + nextCommercialHybrid_ToolNumber++); | ||
| 161 | 172 | } | |
| 162 | 173 | } | |
| 163 | 174 | } | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,3 +1,21 @@ | |||
| 1 | + /** | ||
| 2 | + * OWASP Benchmark Project | ||
| 3 | + * | ||
| 4 | + * This file is part of the Open Web Application Security Project (OWASP) | ||
| 5 | + * Benchmark Project For details, please see | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | + * | ||
| 8 | + * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | ||
| 9 | + * of the GNU General Public License as published by the Free Software Foundation, version 2. | ||
| 10 | + * | ||
| 11 | + * The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without | ||
| 12 | + * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| 13 | + * GNU General Public License for more details | ||
| 14 | + * | ||
| 15 | + * @author Juan Gama | ||
| 16 | + * @created 2017 | ||
| 17 | + */ | ||
| 18 | + | ||
| 1 | 19 | package org.owasp.benchmark.tools; | |
| 2 | 20 | ||
| 3 | 21 | import java.util.List; | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,3 +1,21 @@ | |||
| 1 | + /** | ||
| 2 | + * OWASP Benchmark Project | ||
| 3 | + * | ||
| 4 | + * This file is part of the Open Web Application Security Project (OWASP) | ||
| 5 | + * Benchmark Project For details, please see | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | + * | ||
| 8 | + * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | ||
| 9 | + * of the GNU General Public License as published by the Free Software Foundation, version 2. | ||
| 10 | + * | ||
| 11 | + * The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without | ||
| 12 | + * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| 13 | + * GNU General Public License for more details | ||
| 14 | + * | ||
| 15 | + * @author Juan Gama | ||
| 16 | + * @created 2017 | ||
| 17 | + */ | ||
| 18 | + | ||
| 1 | 19 | package org.owasp.benchmark.tools; | |
| 2 | 20 | ||
| 3 | 21 | import java.io.File; | |
@@ -156,4 +174,5 @@ public HttpRequestBase getRequestBase() { | |||
| 156 | 174 | public void setRequestBase(HttpRequestBase requestBase) { | |
| 157 | 175 | this.requestBase = requestBase; | |
| 158 | 176 | } | |
| 159 | - } | ||
| 177 | + } | ||
| 178 | + | ||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
@@ -1,3 +1,21 @@ | |||
| 1 | + /** | ||
| 2 | + * OWASP Benchmark Project | ||
| 3 | + * | ||
| 4 | + * This file is part of the Open Web Application Security Project (OWASP) | ||
| 5 | + * Benchmark Project For details, please see | ||
| 6 | + * <a href="https://owasp.org/www-project-benchmark/">https://owasp.org/www-project-benchmark/</a>. | ||
| 7 | + * | ||
| 8 | + * The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms | ||
| 9 | + * of the GNU General Public License as published by the Free Software Foundation, version 2. | ||
| 10 | + * | ||
| 11 | + * The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without | ||
| 12 | + * even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the | ||
| 13 | + * GNU General Public License for more details | ||
| 14 | + * | ||
| 15 | + * @author Juan Gama | ||
| 16 | + * @created 2017 | ||
| 17 | + */ | ||
| 18 | + | ||
| 1 | 19 | package org.owasp.benchmark.tools; | |
| 2 | 20 | ||
| 3 | 21 | import java.io.File; | |
| Back | FazBrowse Home | New Git URL |
0 commit comments