Problems with MainWP. Base64-encoded POST Variable
-
Hi,
I am using MainWP for remotely managing the sites of my subscribed clients. Some functionality is blocked by NF interpreting it as an intrusion.
’24/Jul/18 02:29:28 #2957922 CRITICAL – 46.252.27.245 POST /index.php – BASE64-encoded injection – [POST:settings = YTo2MTp7czoxNzoiY2hpbGRfcGx1Z2luX25hbWUiO3M6MDoiIjtzOjE3OiJjaGlsZF9wbHVnaW5fZGVzYyI7czowOiIiO3M6MTk6ImNoaWxkX3BsdWdpbl9hdXRob3IiO3M6MDoiIjtzOjIzOiJjaGlsZF9wbHVnaW5fYXV0aG9yX3VyaSI7czow…]’
’24/Jul/18 02:29:28 #8884613 CRITICAL – 46.252.27.245 POST /wp-admin/admin-ajax.php – BASE64-encoded injection – [POST:settings = YTo2MTp7czoxNzoiY2hpbGRfcGx1Z2luX25hbWUiO3M6MDoiIjtzOjE3OiJjaGlsZF9wbHVnaW5fZGVzYyI7czowOiIiO3M6MTk6ImNoaWxkX3BsdWdpbl9hdXRob3IiO3M6MDoiIjtzOjIzOiJjaGlsZF9wbHVnaW5fYXV0aG9yX3VyaSI7czow…]’I really don’t want to disable that policy. So I tried to whitelist my servers IP via .htninja but that doesn’t work. The only way of not giving up on any of these softwares would be to disable that. Or would there be any safe way around this?
Second question. When testing I noticed one client site letting those requests through despite having this option enabled as well as “Block any access to the REST API” enabled. NF is running in FAW mode. Would that mean the firewall is broken on that site?
Btw. sorry for asking so much. But I have a lot of clients and pitching a new software to them I need to be really certain that everything works together nicely.
Thank you for your time!
- The topic ‘Problems with MainWP. Base64-encoded POST Variable’ is closed to new replies.