Hi! Is there any way to disable remote control of agents from the server? My clients do not won't to be compromised through the agents in case of compromise of OSSEC servers. As server can update agents configs it is theoretically possible to read sensitive information by specifying which file to read.
I see workaround now - to change rights on ossec config file to read-only for ossec system user. Is there some other options to make the agent that is not managed from the server? -- Best regards. Gleb Pakharenko. http://gpaharenko.livejournal.com http://www.linkedin.com/in/gpaharenko +380503116172 skype: gpaharenko
