Penetration Testing mailing list archives
Re: OSSIM Fedback
From: Stefano Zanero <zanero () elet polimi it>
Date: Mon, 12 Jun 2006 23:06:24 +0200
Koolk3 wrote:
I am looking for some feedback on the usefulness and practicaility (interms or maintenance and configuration) of this software. I am mainly interested in OSSIM as a corelation tool / log analysis for now.
We studied OSSIM in order to use it as a framework for implementing our own correlation algorithms. My experience is partially negative, in particular for the lack of documentation on installation and software internals. Additionally, the source code is intentionally complex and undocumented, to avoid forking or reuse... which is quite curious for a GPL software.
Has anyone tried the latest version of the product (0.9.9)?
No, we didn't, we tested earlier versions.
Any feedback on installation and usability would be great.
Installation is quite difficult unless you use the provided debian packages. Installing it clean on a Gentoo or name-your-distro box is (used to be, at least) a mess. ONCE INSTALLED, the software is very good, not to say excellent, with good look and feel and usability. I like it a lot. But a software I cannot expand, extend or troubleshoot easily is very much the contrary of what I look for in a GPL software. Stefano ------------------------------------------------------------------------------ This List Sponsored by: Cenzic Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details. ------------------------------------------------------------------------------
Current thread:
- OSSIM Fedback Koolk3 (Jun 12)
- Re: OSSIM Fedback Stefano Zanero (Jun 12)
- Re: OSSIM Fedback Dominique Karg (Jun 13)
- RE: OSSIM Fedback Strand, John (Mission Systems) (Jun 13)
- Re: OSSIM Fedback Stefano Zanero (Jun 15)
- Re: OSSIM Fedback Dominique Karg (Jun 13)
- RE: OSSIM Fedback Mark Lists (Jun 13)
- Re: OSSIM Fedback Stefano Zanero (Jun 12)