• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 23:13
CET 05:13
KST 13:13
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting10[ASL20] Ro4 Preview: Descent11Team TLMC #5: Winners Announced!3
Community News
[BSL21] RO32 Group Stage0Weekly Cups (Oct 26-Nov 2): Liquid, Clem, Solar win; LAN in Philly2Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win62025 RSL Offline Finals Dates + Ticket Sales!10BSL21 Open Qualifiers Week & CONFIRM PARTICIPATION3
StarCraft 2
General
RotterdaM "Serral is the GOAT, and it's not close" Weekly Cups (Oct 26-Nov 2): Liquid, Clem, Solar win; LAN in Philly Intel X Team Liquid Seoul event: Showmatches and Meet the Pros Weekly Cups (Oct 20-26): MaxPax, Clem, Creator win Weekly Cups (Oct 13-19): Clem Goes for Four
Tourneys
Monday Nights Weeklies SC4ALL $6,000 Open LAN in Philadelphia $3,500 WardiTV Korean Royale S4 Crank Gathers Season 2: SC II Pro Teams Merivale 8 Open - LAN - Stellar Fest
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection Mutation # 495 Rest In Peace
Brood War
General
SnOw on 'Experimental' Nonstandard Maps in ASL [BSL21] RO32 Group Stage [ASL20] Ask the mapmakers — Drop your questions Ladder Map Matchup Stats SnOw's ASL S20 Finals Review
Tourneys
BSL21 Open Qualifiers Week & CONFIRM PARTICIPATION [ASL20] Grand Finals Small VOD Thread 2.0 The Casual Games of the Week Thread
Strategy
How to stay on top of macro? Current Meta PvZ map balance Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Dawn of War IV Nintendo Switch Thread Stormgate/Frost Giant Megathread ZeroSpace Megathread General RTS Discussion Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Dating: How's your luck? Russo-Ukrainian War Thread Canadian Politics Mega-thread
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread Movie Discussion! Korean Music Discussion Series you have seen recently...
Sports
MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion 2024 - 2026 Football Thread NBA General Discussion
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List Recent Gifted Posts
Blogs
The Big Reveal
Peanutsc
Challenge: Maths isn't all…
Hildegard
Career Paths and Skills for …
TrAiDoS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1782 users

BWUSA.org = Hacked . - Page 2

Blogs > Xeris
Post a Reply
Prev 1 2 3 Next All
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:05 GMT
#21
ya I know... he's investigating it, we'll find out who did it soon. vengeance shall be had.
twitter.com/xerislight -- follow me~~
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:27 GMT
#22
the site looks fine to me, what exactly is wrong with it?

Also sorry to hear it Xeris. I wonder who did it?
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:31 GMT
#23
also will this delay tomorrow YL? I'm playing in it and if you reschedule i might not be able to play since i could be working.
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:32 GMT
#24
yes, tomorrow it will continue as planned.

it was fixed, just all the forum data was lost...
twitter.com/xerislight -- follow me~~
Centric
Profile Blog Joined March 2008
United States1989 Posts
June 05 2008 02:44 GMT
#25
That really sucks man...hope you can get it all together quickly. Also hope you find the bastard.
Super serious.
FragKrag
Profile Blog Joined September 2007
United States11552 Posts
June 05 2008 02:44 GMT
#26
Why is this in a blog? It should definitely be a post in the BW forum.
*TL CJ Entusman #40* "like scissors does anything to paper except MAKE IT MORE NUMEROUS" -paper
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 03:56 GMT
#27
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site
twitter.com/xerislight -- follow me~~
Skew
Profile Blog Joined October 2006
United States1019 Posts
June 05 2008 05:23 GMT
#28
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 05:55 GMT
#29
ya , we're going to start doing daily backups
twitter.com/xerislight -- follow me~~
Xeln4g4
Profile Joined January 2005
Italy1209 Posts
June 05 2008 08:15 GMT
#30
retarded idiots are everywhere ...
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:08 GMT
#31
You should be taking daily dumps of your database. I don't see it as being so big that it would matter. Just add it as a shell command to your crontab, one line to save the days dump as some date-valued file, another to delete backups older than say a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:16 GMT
#32
On June 05 2008 14:23 Skew wrote:
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.


Logs?

Check your db logs - if they are set up right they should have a record of the statement that caused the wipe.

Also. you should be logging any input that is not standard, or since its a small site, just log all input and clean your logs once they are older than a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
Jank
Profile Blog Joined March 2008
United States308 Posts
June 05 2008 10:24 GMT
#33
Probably the result of sql injection. Make sure you patch the hole and not just restore everything and pretend it never happened. Go through all your code making sure all the input is properly sanitized.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
QuanticHawk
Profile Blog Joined May 2007
United States32083 Posts
June 05 2008 12:26 GMT
#34
If I remember, steve said it was an sql, cuz the smi site got hacked yesterday too.
PROFESSIONAL GAMER - SEND ME OFFERS TO JOIN YOUR TEAM - USA USA USA
MasterOfChaos
Profile Blog Joined April 2007
Germany2896 Posts
June 05 2008 14:16 GMT
#35
If the attacker was not entirely supid(which is well possible, 1337 scriptkiddies often are) then your IP will be a random TOR exitnode, or an open wlan.
Did you already find out how he killed your db?
LiquipediaOne eye to kill. Two eyes to live.
Flaccid
Profile Blog Joined August 2006
8848 Posts
June 05 2008 17:45 GMT
#36
Not much detail is given in this blog post, so here is a link to what happened:

Description of hack

To quote this guy's post:

This is a Windows vulnerability. What the hacker did was attempt to run around the code and gain access to the asp.net Windows Media Player library via our /images/ folder. They found an image they liked, They ran a some kind of script, and gained access to run a sql instertion script that the application itself did not allow.

Sneaky fucker.

Apparently, this a vulnerability that Microsoft put out a patch to, and our hosting provider didn’t run it against our VPS yet.

So to protect your server against this hack, have your hosting provider run the latest updates for the vulnerability.


So it's really not a matter of basic SQL-injection. That stuff is protected against in the code in several different ways. It's a server-side vulnerability that is exploited and something most people have no control over. The only sites at risk are those running on a Windows server. Just do a google search and you'll see the hundreds of thousands of sites that have been hit in this way.

Point being we have to go a roundabout way to prevent this from happening again, and again, and again... and again.....

That's the internet for you.
I'd rather have a bottle in front of me than a frontal lobotomy
Jonoman92
Profile Blog Joined September 2006
United States9104 Posts
June 05 2008 18:29 GMT
#37
I wondered what was going on. I was looking for the thread with the info about my challenge and I realized the most recent threads were from a while ago.
Goosey
Profile Blog Joined September 2005
United States695 Posts
Last Edited: 2008-06-05 18:37:28
June 05 2008 18:36 GMT
#38
That sucks. :| I am surprised your host doesn't do regular backups

edit: oh and they run Windows Server? Unless you are reliant on that software stack I would recommend switching hosts for sure. Daily backup is pretty much standard.
#1 Shuttle Fan.
nofAcedAgent
Profile Blog Joined July 2007
United States952 Posts
Last Edited: 2008-06-05 19:27:47
June 05 2008 19:27 GMT
#39
On June 05 2008 12:56 Xeris wrote:
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site



Chill yo~ I think he just meant it would get noticed by more people in the brood war section, hes not the one that hacked you, control your rage (;p) (not that I know the benefit of having more viewers)

Anyway, hope the bastard gets caught man, sorry to hear it
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 22:00 GMT
#40
Apparently whoever did it tried to do it again last night and today -___________- !!

Woo I hope whoever hacked my site shows up to a LAN.
twitter.com/xerislight -- follow me~~
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
Replay Cast
23:00
WardiTV Mondays #57
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Nina 166
RuFF_SC2 160
Nathanias 104
StarCraft: Brood War
Horang2 9719
JimRising 661
Icarus 10
Dota 2
NeuroSwarm106
LuMiX1
League of Legends
Cuddl3bear3
Counter-Strike
fl0m1329
taco 176
PGG 133
Other Games
summit1g15633
shahzam803
C9.Mang0277
WinterStarcraft266
Maynarde103
Organizations
Other Games
gamesdonequick1159
BasetradeTV160
Counter-Strike
PGL130
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 13 non-featured ]
StarCraft 2
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Stunt404
• Lourlo189
Other Games
• Scarra578
Upcoming Events
Sparkling Tuna Cup
5h 47m
WardiTV Korean Royale
7h 47m
LAN Event
10h 47m
Replay Cast
1d 4h
WardiTV Korean Royale
1d 7h
LAN Event
1d 10h
OSC
1d 18h
The PondCast
2 days
LAN Event
2 days
Replay Cast
2 days
[ Show More ]
LAN Event
3 days
Korean StarCraft League
3 days
CranKy Ducklings
4 days
WardiTV Korean Royale
4 days
LAN Event
4 days
IPSL
4 days
dxtr13 vs OldBoy
Napoleon vs Doodle
Replay Cast
4 days
Sparkling Tuna Cup
5 days
WardiTV Korean Royale
5 days
LAN Event
5 days
IPSL
5 days
JDConan vs WIZARD
WolFix vs Cross
Replay Cast
6 days
Wardi Open
6 days
Liquipedia Results

Completed

BSL 21 Points
SC4ALL: StarCraft II
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025

Upcoming

BSL Season 21
SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
Stellar Fest
META Madness #9
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
BLAST Rivals Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.