• Ciao evilsocket!

    I’m in trouble with the combination of wp-sentinel and the russian language I must use in my site. Maybe because the utf-8 characters, and when creating/editing a post, I think that it occurs when WordPress auto-saves a draft, Your plugin receives a odd string of characteres that interprets as “Script or html injection”.

    Details follows:

    timestamp ??? 03 ??? 2011 06:44:40
    address 99.99.999.999 (The I.P. address of the editor)
    location
    user-agent Mozilla/5.0 (Windows NT 6.1; WOW64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
    referer https://born-2-be-free.com/wp-admin/post.php?post=81&action=edit&message=1
    wp username
    scope POST
    variable content
    content <!–:ru–>D?D?D·??D°D?……… (and so on till more that 65000 characters)
    message script or html injection
    rule <[^>]*(script|object|iframe|applet|m

    may you help me with this?
    Maybe a “Whitelist” of IP Adresses?

    Thanks in advance for your interest and thanks a lot for your good job with this pluggin, that I like a lot but must have de-activated in this site.

    Manu

  • The topic ‘[Plugin: WP-Sentinel] Plugin – message script or html injection’ is closed to new replies.