Hi Gleb,
You could try changing the permissions of the shared directory on the
agents. Take away OSSEC's ability to write to the directory.

On Tue, Feb 15, 2011 at 5:29 PM, Gleb Paharenko <[email protected]> wrote:
> Hi!
>
> Is there any way to disable remote control of agents from the server? My
> clients do not won't to be compromised through the agents in case of
> compromise of OSSEC servers. As server can update agents configs it is
> theoretically possible to read sensitive information by specifying which
> file to read.
>
> I see workaround now - to change rights on ossec config file to read-only
> for ossec system user. Is there some other options to make the agent that is
> not managed from the server?
>
>
>
> --
> Best regards.
> Gleb Pakharenko.
> http://gpaharenko.livejournal.com
> http://www.linkedin.com/in/gpaharenko
> +380503116172
> skype: gpaharenko
>
>

Reply via email to