<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: SSA Version 1.5.2 - OVAL Vulnerability Assessment Software</title>
	<atom:link href="http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<pubDate>Thu, 04 Dec 2008 19:04:49 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: dre</title>
		<link>http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-71604</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Wed, 31 Oct 2007 05:46:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-71604</guid>
		<description>There is a ton of information about OVAL on these &lt;a href="http://www.nabble.com/OVAL-f24857.html" rel="nofollow"&gt;forums&lt;/a&gt;.

I'm reconsidering what I said earlier about OVAL after looking at the MITRE integration overall.  I'm also reconsidering AVDL because it turns out that WebInspect hasn't even supported it themselves all year.

For example, check out &lt;a href="http://www.swqual.com/SQGNE/presentations/2006-07/Martin%20-%20May%20Joint%20Meeting%202007.pdf" rel="nofollow"&gt;this presentation&lt;/a&gt; by Bob Martin on CWE.   On slide 15 (second to last slide), he shows how XCCDF and OVAL can be used as knowledge repositories to bring data to/from operations security management processes.</description>
		<content:encoded><![CDATA[<p>There is a ton of information about OVAL on these <a href="http://www.nabble.com/OVAL-f24857.html" rel="nofollow">forums</a>.</p>
<p>I&#8217;m reconsidering what I said earlier about OVAL after looking at the MITRE integration overall.  I&#8217;m also reconsidering AVDL because it turns out that WebInspect hasn&#8217;t even supported it themselves all year.</p>
<p>For example, check out <a href="http://www.swqual.com/SQGNE/presentations/2006-07/Martin%20-%20May%20Joint%20Meeting%202007.pdf" rel="nofollow">this presentation</a> by Bob Martin on CWE.   On slide 15 (second to last slide), he shows how XCCDF and OVAL can be used as knowledge repositories to bring data to/from operations security management processes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fazed</title>
		<link>http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-71574</link>
		<dc:creator>fazed</dc:creator>
		<pubDate>Tue, 30 Oct 2007 17:47:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-71574</guid>
		<description>I have to agree with dre..</description>
		<content:encoded><![CDATA[<p>I have to agree with dre..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dre</title>
		<link>http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-68799</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Thu, 25 Oct 2007 01:31:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/2007/10/ssa-version-152-oval-vulnerability-assessment-software/#comment-68799</guid>
		<description>qualys has integrated oval support into their product.

i find that the &lt;a href="http://www.avdl.org" rel="nofollow"&gt;avdl&lt;/a&gt; support in webinspect is much more mature, and i wish that other products would support this... although oval support isn't that bad of an idea either</description>
		<content:encoded><![CDATA[<p>qualys has integrated oval support into their product.</p>
<p>i find that the <a href="http://www.avdl.org" rel="nofollow">avdl</a> support in webinspect is much more mature, and i wish that other products would support this&#8230; although oval support isn&#8217;t that bad of an idea either</p>
]]></content:encoded>
	</item>
</channel>
</rss>
