Hi Gleb, You could try changing the permissions of the shared directory on the agents. Take away OSSEC's ability to write to the directory.
On Tue, Feb 15, 2011 at 5:29 PM, Gleb Paharenko <[email protected]> wrote: > Hi! > > Is there any way to disable remote control of agents from the server? My > clients do not won't to be compromised through the agents in case of > compromise of OSSEC servers. As server can update agents configs it is > theoretically possible to read sensitive information by specifying which > file to read. > > I see workaround now - to change rights on ossec config file to read-only > for ossec system user. Is there some other options to make the agent that is > not managed from the server? > > > > -- > Best regards. > Gleb Pakharenko. > http://gpaharenko.livejournal.com > http://www.linkedin.com/in/gpaharenko > +380503116172 > skype: gpaharenko > >
