is there a recent doc ( 2009 - 2010 ) about ossim installation
Aro RANAIVONDRAMBOLA <razuki <at> hotmail.fr>
2010-08-25 13:45:19 GMT
Hello,
My project at university is about compiling and running OSSIM. I must compile OSSIM source code on Debian lenny. But the doc version is old. the last update was in 2004 ... So many patch failed ( for example I cannot patch snort with ossim patch. It fails ).
is there a recent doc ( 2009 - 2010 ) about ossim installation.
Otherwise what can I do ? ( my teacher do not want I make "lazy install" ( using debian package provided by alienvault )
Thanks for your help
> From: os-sim-support-request <at> lists.sourceforge.net
> Subject: Os-sim-support Digest, Vol 35, Issue 1
> To: os-sim-support <at> lists.sourceforge.net
> Date: Wed, 28 Jul 2010 18:56:33 +0000
>
> Send Os-sim-support mailing list submissions to
> os-sim-support <at> lists.sourceforge.net
>
> To subscribe or unsubscribe via the World Wide Web, visit
> https://lists.sourceforge.net/lists/listinfo/os-sim-support
> or, via email, send a message with subject or body 'help' to
> os-sim-support-request <at> lists.sourceforge.net
>
> You can reach the person managing the list at
> os-sim-support-owner <at> lists.sourceforge.net
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Os-sim-support digest..."
>
>
> Today's Topics:
>
> 1. Problem with Cisco Pix (Houcem HACHICHA)
> 2. ossim agent does not receive traffic (Aro RANAIVONDRAMBOLA)
> 3. OSSIM Source Code / Web Site (Aro RANAIVONDRAMBOLA)
> 4. Re: OSSIM Source Code / Web Site (Ritter, Nicholas)
> 5. Re: OSSIM Source Code / Web Site (Pablo)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Wed, 23 Jun 2010 20:01:34 +0100
> From: Houcem HACHICHA <houcem.hachicha <at> gmail.com>
> Subject: [Os-sim-support] Problem with Cisco Pix
> To: os-sim-support <at> lists.sourceforge.net
> Message-ID:
> <AANLkTin2RITRTwOP0x78lBtlAtmOD2saMWobMAWCgZC3 <at> mail.gmail.com>
> Content-Type: text/plain; charset="iso-8859-1"
>
> Hi guys,
>
> I performed a OSSIM 2.2 fresh installation, with no cards at promisc mode. I
> needed to feed it with CISCO PIX logs.
> So I redirected those logs using syslog (UDP:514), to the ossim server I
> just installed. Running TCPdump on the server shows that those logs are
> indeed recieved by the OSSIM server. I activated cisco-pix pluguin using
> (only) ossim-setup on the server side.
>
> Back to the web frontend, events from CISCO-Pics are not pouring in :(
>
> Am I missing something here? Does the plugin need more configuration? Do I
> need to send the syslog traffic throught another port/protocol? Do I need to
> add the CISCO Pix to the assets list or something?
>
>
> Please help
> --
> Kind regards
>
> Houcem HACHICHA
> -------------- next part --------------
> An HTML attachment was scrubbed...
>
> ------------------------------
>
> Message: 2
> Date: Fri, 25 Jun 2010 10:51:40 +0200
> From: Aro RANAIVONDRAMBOLA <razuki <at> hotmail.fr>
> Subject: [Os-sim-support] ossim agent does not receive traffic
> To: <os-sim-support <at> lists.sourceforge.net>
> Message-ID: <BAY146-w59CE2DDBF51D3833E90E1CA4C70 <at> phx.gbl>
> Content-Type: text/plain; charset="iso-8859-1"
>
>
>
> Hi,
> I installed ossim-server and ossim-agent on a host A and I installed snare ( a sensor ) on a host B. A and B are linked by a SWITCH.
> the problem : the agent which is on A does not receive the traffic ( the events ) from host B.
> thanks for your help
>
>
> _________________________________________________________________
> Vous voulez regarder la TV directement depuis votre PC ? C'est tr?s simple avec Windows 7
> http://clk.atdmt.com/FRM/go/229960614/direct/01/
> -------------- next part --------------
> An HTML attachment was scrubbed...
>
> ------------------------------
>
> Message: 3
> Date: Wed, 28 Jul 2010 17:59:21 +0200
> From: Aro RANAIVONDRAMBOLA <razuki <at> hotmail.fr>
> Subject: [Os-sim-support] OSSIM Source Code / Web Site
> To: <os-sim-support <at> lists.sourceforge.net>
> Message-ID: <BAY146-w1236B881AFF55343A52448A4A80 <at> phx.gbl>
> Content-Type: text/plain; charset="iso-8859-1"
>
>
> Hello,
> - I would like to know if there is still a web site for OSSIM Project. When I go to www.ossim.net, I am rederected to Alienvault web site.
> - Where can I obtain OSSIM Source Code ?
>
> Regards,
>
> razuki.
>
> -------------- next part --------------
> An HTML attachment was scrubbed...
>
> ------------------------------
>
> Message: 4
> Date: Wed, 28 Jul 2010 11:12:44 -0500
> From: "Ritter, Nicholas" <Nicholas.Ritter <at> americantv.com>
> Subject: Re: [Os-sim-support] OSSIM Source Code / Web Site
> To: "Aro RANAIVONDRAMBOLA" <razuki <at> hotmail.fr>
> Cc: os-sim-support <at> lists.sourceforge.net
> Message-ID: <A31DBDD0D3C9454B8B14AE7DFD8A8EB606888EAB <at> mail3.ds.atv>
> Content-Type: text/plain; charset="us-ascii"
>
> OSSIM is made by AlienVault. The code is available, I think, try looking
> on the forums for info on how it is available. Try the following urls:
>
>
>
> For the Forums:
>
>
>
> https://www.alienvault.com/forum/
>
>
>
> or the source git repo:
>
>
>
> http://www.assembla.com/code/os-sim/git/nodes?rev=master
>
>
>
>
>
>
>
> From: Aro RANAIVONDRAMBOLA [mailto:razuki <at> hotmail.fr]
> Sent: Wednesday, July 28, 2010 10:59 AM
> To: os-sim-support <at> lists.sourceforge.net
> Subject: [Os-sim-support] OSSIM Source Code / Web Site
>
>
>
> Hello,
> - I would like to know if there is still a web site for OSSIM Project.
> When I go to www.ossim.net, I am rederected to Alienvault web site.
> - Where can I obtain OSSIM Source Code ?
>
> Regards,
>
> razuki.
>
> -------------- next part --------------
> An HTML attachment was scrubbed...
>
> ------------------------------
>
> Message: 5
> Date: Wed, 28 Jul 2010 20:56:03 +0200
> From: Pablo <pablo <at> ossim.net>
> Subject: Re: [Os-sim-support] OSSIM Source Code / Web Site
> To: "Ritter, Nicholas" <Nicholas.Ritter <at> americantv.com>
> Cc: Aro RANAIVONDRAMBOLA <razuki <at> hotmail.fr>,
> os-sim-support <at> lists.sourceforge.net
> Message-ID:
> <AANLkTi=zRSaUpZhc2BeWvEMyJDY_PYXhquHG=a1cE0-m <at> mail.gmail.com>
> Content-Type: text/plain; charset="iso-8859-1"
>
> Hi, now they have a git at assembla:
> http://www.assembla.com/code/os-sim/git/nodes?rev=master
>
> 2010/7/28 Ritter, Nicholas <Nicholas.Ritter <at> americantv.com>
>
> > OSSIM is made by AlienVault. The code is available, I think, try looking
> > on the forums for info on how it is available. Try the following urls:
> >
> >
> >
> > For the Forums:
> >
> >
> >
> > https://www.alienvault.com/forum/
> >
> >
> >
> > or the source git repo:
> >
> >
> >
> > http://www.assembla.com/code/os-sim/git/nodes?rev=master
> >
> >
> >
> >
> >
> >
> >
> > *From:* Aro RANAIVONDRAMBOLA [mailto:razuki <at> hotmail.fr]
> > *Sent:* Wednesday, July 28, 2010 10:59 AM
> > *To:* os-sim-support <at> lists.sourceforge.net
> > *Subject:* [Os-sim-support] OSSIM Source Code / Web Site
> >
> >
> >
> > Hello,
> > - I would like to know if there is still a web site for OSSIM Project. When
> > I go to www.ossim.net, I am rederected to Alienvault web site.
> > - Where can I obtain OSSIM Source Code ?
> >
> > Regards,
> >
> > razuki.
> >
> >
> > ------------------------------------------------------------------------------
> > The Palm PDK Hot Apps Program offers developers who use the
> > Plug-In Development Kit to bring their C/C++ apps to Palm for a share
> > of $1 Million in cash or HP Products. Visit us here for more details:
> > http://p.sf.net/sfu/dev2dev-palm
> > _______________________________________________
> > Os-sim-support mailing list
> > Os-sim-support <at> lists.sourceforge.net
> > https://lists.sourceforge.net/lists/listinfo/os-sim-support
> >
> >
>
>
> --
> Best regards,
> --
> Pablo Rinc?n Crespo
> Security researcher and developer
> Open Information Security Foundation (OISF)
> -------------- next part --------------
> An HTML attachment was scrubbed...
>
> ------------------------------
>
> ------------------------------------------------------------------------------
> The Palm PDK Hot Apps Program offers developers who use the
> Plug-In Development Kit to bring their C/C++ apps to Palm for a share
> of $1 Million in cash or HP Products. Visit us here for more details:
> http://p.sf.net/sfu/dev2dev-palm
>
> ------------------------------
>
> _______________________________________________
> Os-sim-support mailing list
> Os-sim-support <at> lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/os-sim-support
>
>
> End of Os-sim-support Digest, Vol 35, Issue 1
> *********************************************
------------------------------------------------------------------------------
Sell apps to millions through the Intel(R) Atom(Tm) Developer Program
Be part of this innovative community and reach millions of netbook users
worldwide. Take advantage of special opportunities to increase revenue and
speed time-to-market. Join now, and jumpstart your future.
http://p.sf.net/sfu/intel-atom-d2d
_______________________________________________
Os-sim-support mailing list
Os-sim-support <at> lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/os-sim-support