• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 04:53
CEST 10:53
KST 17:53
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
BGE Stara Zagora 2025: Info & Preview11Code S RO12 Preview: GuMiho, Bunny, SHIN, ByuN3The Memories We Share - Facing the Final(?) GSL44Code S RO12 Preview: Cure, Zoun, Solar, Creator4[ASL19] Finals Preview: Daunting Task30
Community News
GSL Ro4 and Finals moved to Sunday June 15th8Weekly Cups (May 27-June 1): ByuN goes back-to-back0EWC 2025 Regional Qualifier Results26Code S RO12 Results + RO8 Groups (2025 Season 2)3Weekly Cups (May 19-25): Hindsight is 20/20?0
StarCraft 2
General
Jim claims he and Firefly were involved in match-fixing GSL Ro4 and Finals moved to Sunday June 15th Serious Question: Mech BGE Stara Zagora 2025: Info & Preview I made a 5.0.12/5.0.13 replay fix
Tourneys
Bellum Gens Elite: Stara Zagora 2025 SOOP Starcraft Global #21 $5,100+ SEL Season 2 Championship (SC: Evo) WardiTV Mondays Master Swan Open (Global Bronze-Master 2)
Strategy
[G] Darkgrid Layout Simple Questions Simple Answers [G] PvT Cheese: 13 Gate Proxy Robo
Custom Maps
[UMS] Zillion Zerglings
External Content
Mutation # 476 Charnel House Mutation # 475 Hard Target Mutation # 474 Futile Resistance Mutation # 473 Cold is the Void
Brood War
General
Will foreigners ever be able to challenge Koreans? BW General Discussion FlaSh Witnesses SCV Pull Off the Impossible vs Shu BGH auto balance -> http://bghmmr.eu/ Battle.net is not working
Tourneys
[ASL19] Grand Finals Small VOD Thread 2.0 [BSL20] GosuLeague RO16 - Tue & Wed 20:00+CET [Megathread] Daily Proleagues
Strategy
I am doing this better than progamers do. [G] How to get started on ladder as a new Z player
Other Games
General Games
Monster Hunter Wilds Stormgate/Frost Giant Megathread Nintendo Switch Thread Path of Exile Mechabellum
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
LiquidLegends to reintegrate into TL.net
Heroes of the Storm
Simple Questions, Simple Answers
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
Vanilla Mini Mafia TL Mafia Community Thread TL Mafia Plays: Diplomacy TL Mafia: Generative Agents Showdown Survivor II: The Amazon
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine European Politico-economics QA Mega-thread Canadian Politics Mega-thread
Fan Clubs
Maru Fan Club Serral Fan Club
Media & Entertainment
Korean Music Discussion [Manga] One Piece
Sports
2024 - 2025 Football Thread Formula 1 Discussion NHL Playoffs 2024 NBA General Discussion
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread Cleaning My Mechanical Keyboard
TL Community
The Automated Ban List
Blogs
Heero Yuy & the Tax…
KrillinFromwales
Research study on team perfo…
TrAiDoS
I was completely wrong ab…
jameswatts
Need Your Help/Advice
Glider
Trip to the Zoo
micronesia
Poker
Nebuchad
Info SLEgma_12
SLEgma_12
Customize Sidebar...

Website Feedback

Closed Threads



Active: 17936 users

BWUSA.org = Hacked . - Page 2

Blogs > Xeris
Post a Reply
Prev 1 2 3 Next All
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:05 GMT
#21
ya I know... he's investigating it, we'll find out who did it soon. vengeance shall be had.
twitter.com/xerislight -- follow me~~
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:27 GMT
#22
the site looks fine to me, what exactly is wrong with it?

Also sorry to hear it Xeris. I wonder who did it?
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:31 GMT
#23
also will this delay tomorrow YL? I'm playing in it and if you reschedule i might not be able to play since i could be working.
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:32 GMT
#24
yes, tomorrow it will continue as planned.

it was fixed, just all the forum data was lost...
twitter.com/xerislight -- follow me~~
Centric
Profile Blog Joined March 2008
United States1989 Posts
June 05 2008 02:44 GMT
#25
That really sucks man...hope you can get it all together quickly. Also hope you find the bastard.
Super serious.
FragKrag
Profile Blog Joined September 2007
United States11549 Posts
June 05 2008 02:44 GMT
#26
Why is this in a blog? It should definitely be a post in the BW forum.
*TL CJ Entusman #40* "like scissors does anything to paper except MAKE IT MORE NUMEROUS" -paper
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 03:56 GMT
#27
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site
twitter.com/xerislight -- follow me~~
Skew
Profile Blog Joined October 2006
United States1019 Posts
June 05 2008 05:23 GMT
#28
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 05:55 GMT
#29
ya , we're going to start doing daily backups
twitter.com/xerislight -- follow me~~
Xeln4g4
Profile Joined January 2005
Italy1209 Posts
June 05 2008 08:15 GMT
#30
retarded idiots are everywhere ...
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:08 GMT
#31
You should be taking daily dumps of your database. I don't see it as being so big that it would matter. Just add it as a shell command to your crontab, one line to save the days dump as some date-valued file, another to delete backups older than say a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:16 GMT
#32
On June 05 2008 14:23 Skew wrote:
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.


Logs?

Check your db logs - if they are set up right they should have a record of the statement that caused the wipe.

Also. you should be logging any input that is not standard, or since its a small site, just log all input and clean your logs once they are older than a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
Jank
Profile Blog Joined March 2008
United States308 Posts
June 05 2008 10:24 GMT
#33
Probably the result of sql injection. Make sure you patch the hole and not just restore everything and pretend it never happened. Go through all your code making sure all the input is properly sanitized.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
QuanticHawk
Profile Blog Joined May 2007
United States32044 Posts
June 05 2008 12:26 GMT
#34
If I remember, steve said it was an sql, cuz the smi site got hacked yesterday too.
PROFESSIONAL GAMER - SEND ME OFFERS TO JOIN YOUR TEAM - USA USA USA
MasterOfChaos
Profile Blog Joined April 2007
Germany2896 Posts
June 05 2008 14:16 GMT
#35
If the attacker was not entirely supid(which is well possible, 1337 scriptkiddies often are) then your IP will be a random TOR exitnode, or an open wlan.
Did you already find out how he killed your db?
LiquipediaOne eye to kill. Two eyes to live.
Flaccid
Profile Blog Joined August 2006
8835 Posts
June 05 2008 17:45 GMT
#36
Not much detail is given in this blog post, so here is a link to what happened:

Description of hack

To quote this guy's post:

This is a Windows vulnerability. What the hacker did was attempt to run around the code and gain access to the asp.net Windows Media Player library via our /images/ folder. They found an image they liked, They ran a some kind of script, and gained access to run a sql instertion script that the application itself did not allow.

Sneaky fucker.

Apparently, this a vulnerability that Microsoft put out a patch to, and our hosting provider didn’t run it against our VPS yet.

So to protect your server against this hack, have your hosting provider run the latest updates for the vulnerability.


So it's really not a matter of basic SQL-injection. That stuff is protected against in the code in several different ways. It's a server-side vulnerability that is exploited and something most people have no control over. The only sites at risk are those running on a Windows server. Just do a google search and you'll see the hundreds of thousands of sites that have been hit in this way.

Point being we have to go a roundabout way to prevent this from happening again, and again, and again... and again.....

That's the internet for you.
I'd rather have a bottle in front of me than a frontal lobotomy
Jonoman92
Profile Blog Joined September 2006
United States9103 Posts
June 05 2008 18:29 GMT
#37
I wondered what was going on. I was looking for the thread with the info about my challenge and I realized the most recent threads were from a while ago.
Goosey
Profile Blog Joined September 2005
United States695 Posts
Last Edited: 2008-06-05 18:37:28
June 05 2008 18:36 GMT
#38
That sucks. :| I am surprised your host doesn't do regular backups

edit: oh and they run Windows Server? Unless you are reliant on that software stack I would recommend switching hosts for sure. Daily backup is pretty much standard.
#1 Shuttle Fan.
nofAcedAgent
Profile Blog Joined July 2007
United States952 Posts
Last Edited: 2008-06-05 19:27:47
June 05 2008 19:27 GMT
#39
On June 05 2008 12:56 Xeris wrote:
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site



Chill yo~ I think he just meant it would get noticed by more people in the brood war section, hes not the one that hacked you, control your rage (;p) (not that I know the benefit of having more viewers)

Anyway, hope the bastard gets caught man, sorry to hear it
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 22:00 GMT
#40
Apparently whoever did it tried to do it again last night and today -___________- !!

Woo I hope whoever hacked my site shows up to a LAN.
twitter.com/xerislight -- follow me~~
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
Next event in 2h 7m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
EnDerr 84
StarCraft: Brood War
Sea 3529
Bisu 662
EffOrt 359
Nal_rA 238
hero 145
Killer 145
Dewaltoss 80
ggaemo 60
Leta 55
Shine 51
[ Show more ]
Sharp 46
Rush 26
NotJumperer 16
sSak 12
JulyZerg 7
Dota 2
XcaliburYe648
BananaSlamJamma246
PGG 162
Fuzer 51
Counter-Strike
shoxiejesuss733
allub139
Super Smash Bros
Mew2King169
Other Games
ceh9593
Happy491
Pyrionflax96
Has11
Organizations
Dota 2
PGL Dota 2 - Main Stream2104
Other Games
gamesdonequick707
StarCraft: Brood War
UltimateBattle 57
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 12 non-featured ]
StarCraft 2
• LUISG 40
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Stunt521
Upcoming Events
WardiTV Qualifier
2h 7m
Bellum Gens Elite
3h 7m
OSC
7h 7m
The PondCast
1d 1h
Bellum Gens Elite
1d 2h
WardiTV Invitational
1d 2h
Replay Cast
1d 15h
OSC
1d 15h
Bellum Gens Elite
2 days
WardiTV Invitational
2 days
[ Show More ]
Replay Cast
2 days
CranKy Ducklings
3 days
SC Evo League
3 days
Bellum Gens Elite
3 days
Fire Grow Cup
3 days
CSO Contender
3 days
Replay Cast
3 days
SOOP
4 days
SHIN vs GuMiho
Sparkling Tuna Cup
4 days
AllThingsProtoss
4 days
Fire Grow Cup
4 days
Replay Cast
4 days
Replay Cast
5 days
Replay Cast
6 days
WardiTV Invitational
6 days
Liquipedia Results

Completed

CSL Season 17: Qualifier 1
DreamHack Dallas 2025
Heroes 10 EU

Ongoing

JPL Season 2
BSL 2v2 Season 3
BSL Season 20
KCM Race Survival 2025 Season 2
NPSL S3
Rose Open S1
CSL Season 17: Qualifier 2
2025 GSL S2
Bellum Gens Elite Stara Zagora 2025
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
ECL Season 49: Europe
BLAST Rivals Spring 2025
MESA Nomadic Masters
CCT Season 2 Global Finals
IEM Melbourne 2025
YaLLa Compass Qatar 2025
PGL Bucharest 2025
BLAST Open Spring 2025

Upcoming

CSL 17: 2025 SUMMER
Copa Latinoamericana 4
CSLPRO Last Chance 2025
CSLAN 2025
K-Championship
SEL Season 2 Championship
Esports World Cup 2025
HSC XXVII
Championship of Russia 2025
Murky Cup #2
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.