Quote:
Are they validate somehow ?
The audit result must be valid XML.
Quote:
Will someone be able to make mess by sending corrupt/malicious xml to submit url?
They can certainly do that. Any changes to a device will be recorded in Open-AudIT though. So you'll see that a "bad" audit was submitted pretty quickly.
Quote:
If so - are there known ways to protect from it?
Blessed subnets are your answer.
Quote:
Can I modify blessed subnets to accept only from network only when it's is audited ?
I suppose we could look at something like that. Only accept data when a discovery run is occurring. I'll make a note to give that some thought but to be honest - if you have users in your organisation doing this you have more important issues to worry about!
_________________
Support and Development hours available from
Opmantek.
Please consider a purchase to help make Open-AudIT better for everyone.