• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 09:12
CEST 15:12
KST 22:12
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
[ASL20] Ro24 Preview Pt1: Runway132v2 & SC: Evo Complete: Weekend Double Feature4Team Liquid Map Contest #21 - Presented by Monster Energy9uThermal's 2v2 Tour: $15,000 Main Event18Serral wins EWC 202549
Community News
Maestros of The Game—$20k event w/ live finals in Paris23Weekly Cups (Aug 11-17): MaxPax triples again!13Weekly Cups (Aug 4-10): MaxPax wins a triple6SC2's Safe House 2 - October 18 & 195Weekly Cups (Jul 28-Aug 3): herO doubles up6
StarCraft 2
General
What mix of new and old maps do you want in the next 1v1 ladder pool? (SC2) : 2v2 & SC: Evo Complete: Weekend Double Feature Geoff 'iNcontroL' Robinson has passed away The GOAT ranking of GOAT rankings RSL Revival patreon money discussion thread
Tourneys
RSL: Revival, a new crowdfunded tournament series Maestros of The Game—$20k event w/ live finals in Paris Sparkling Tuna Cup - Weekly Open Tournament Monday Nights Weeklies Master Swan Open (Global Bronze-Master 2)
Strategy
Custom Maps
External Content
Mutation # 487 Think Fast Mutation # 486 Watch the Skies Mutation # 485 Death from Below Mutation # 484 Magnetic Pull
Brood War
General
Flash On His 2010 "God" Form, Mind Games, vs JD BGH Auto Balance -> http://bghmmr.eu/ Joined effort New season has just come in ladder BW General Discussion
Tourneys
[ASL20] Ro24 Group B [ASL20] Ro24 Group C BWCL Season 63 Announcement [CSLPRO] It's CSLAN Season! - Last Chance
Strategy
Simple Questions, Simple Answers Fighting Spirit mining rates [G] Mineral Boosting Muta micro map competition
Other Games
General Games
Nintendo Switch Thread General RTS Discussion Thread Dawn of War IV Path of Exile Stormgate/Frost Giant Megathread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Russo-Ukrainian War Thread The year 2050 Things Aren’t Peaceful in Palestine European Politico-economics QA Mega-thread
Fan Clubs
INnoVation Fan Club SKT1 Classic Fan Club!
Media & Entertainment
Anime Discussion Thread Movie Discussion! [Manga] One Piece [\m/] Heavy Metal Thread
Sports
2024 - 2026 Football Thread TeamLiquid Health and Fitness Initiative For 2023 Formula 1 Discussion
World Cup 2022
Tech Support
High temperatures on bridge(s) Gtx660 graphics card replacement Installation of Windows 10 suck at "just a moment"
TL Community
The Automated Ban List TeamLiquid Team Shirt On Sale
Blogs
Evil Gacha Games and the…
ffswowsucks
Breaking the Meta: Non-Stand…
TrAiDoS
INDEPENDIENTE LA CTM
XenOsky
[Girl blog} My fema…
artosisisthebest
Sharpening the Filtration…
frozenclaw
ASL S20 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 2080 users

BWUSA.org = Hacked . - Page 2

Blogs > Xeris
Post a Reply
Prev 1 2 3 Next All
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:05 GMT
#21
ya I know... he's investigating it, we'll find out who did it soon. vengeance shall be had.
twitter.com/xerislight -- follow me~~
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:27 GMT
#22
the site looks fine to me, what exactly is wrong with it?

Also sorry to hear it Xeris. I wonder who did it?
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
MoNKeYSpanKeR
Profile Blog Joined May 2007
United States2869 Posts
June 05 2008 02:31 GMT
#23
also will this delay tomorrow YL? I'm playing in it and if you reschedule i might not be able to play since i could be working.
<3's Mani and Seraphim, thx for the second chance. TSL Name: TSL-mSLeGenD
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 02:32 GMT
#24
yes, tomorrow it will continue as planned.

it was fixed, just all the forum data was lost...
twitter.com/xerislight -- follow me~~
Centric
Profile Blog Joined March 2008
United States1989 Posts
June 05 2008 02:44 GMT
#25
That really sucks man...hope you can get it all together quickly. Also hope you find the bastard.
Super serious.
FragKrag
Profile Blog Joined September 2007
United States11552 Posts
June 05 2008 02:44 GMT
#26
Why is this in a blog? It should definitely be a post in the BW forum.
*TL CJ Entusman #40* "like scissors does anything to paper except MAKE IT MORE NUMEROUS" -paper
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 03:56 GMT
#27
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site
twitter.com/xerislight -- follow me~~
Skew
Profile Blog Joined October 2006
United States1019 Posts
June 05 2008 05:23 GMT
#28
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 05:55 GMT
#29
ya , we're going to start doing daily backups
twitter.com/xerislight -- follow me~~
Xeln4g4
Profile Joined January 2005
Italy1209 Posts
June 05 2008 08:15 GMT
#30
retarded idiots are everywhere ...
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:08 GMT
#31
You should be taking daily dumps of your database. I don't see it as being so big that it would matter. Just add it as a shell command to your crontab, one line to save the days dump as some date-valued file, another to delete backups older than say a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
yenta
Profile Blog Joined April 2006
Poland1142 Posts
June 05 2008 09:16 GMT
#32
On June 05 2008 14:23 Skew wrote:
Sorry Xer.

I don't *think* you can track an XSS/SQL injection wipe on the DB as the content that caused it would also be wiped... someone correct me if I'm wrong, but good luck anyways. Daily DB backups next time around.


Logs?

Check your db logs - if they are set up right they should have a record of the statement that caused the wipe.

Also. you should be logging any input that is not standard, or since its a small site, just log all input and clean your logs once they are older than a week.
Trutacz Practice Discord - https://discord.gg/PWF7Pv
Jank
Profile Blog Joined March 2008
United States308 Posts
June 05 2008 10:24 GMT
#33
Probably the result of sql injection. Make sure you patch the hole and not just restore everything and pretend it never happened. Go through all your code making sure all the input is properly sanitized.
"You don't know you're wearing a leash if you sit by the peg all day." - Michael Parenti
QuanticHawk
Profile Blog Joined May 2007
United States32069 Posts
June 05 2008 12:26 GMT
#34
If I remember, steve said it was an sql, cuz the smi site got hacked yesterday too.
PROFESSIONAL GAMER - SEND ME OFFERS TO JOIN YOUR TEAM - USA USA USA
MasterOfChaos
Profile Blog Joined April 2007
Germany2896 Posts
June 05 2008 14:16 GMT
#35
If the attacker was not entirely supid(which is well possible, 1337 scriptkiddies often are) then your IP will be a random TOR exitnode, or an open wlan.
Did you already find out how he killed your db?
LiquipediaOne eye to kill. Two eyes to live.
Flaccid
Profile Blog Joined August 2006
8837 Posts
June 05 2008 17:45 GMT
#36
Not much detail is given in this blog post, so here is a link to what happened:

Description of hack

To quote this guy's post:

This is a Windows vulnerability. What the hacker did was attempt to run around the code and gain access to the asp.net Windows Media Player library via our /images/ folder. They found an image they liked, They ran a some kind of script, and gained access to run a sql instertion script that the application itself did not allow.

Sneaky fucker.

Apparently, this a vulnerability that Microsoft put out a patch to, and our hosting provider didn’t run it against our VPS yet.

So to protect your server against this hack, have your hosting provider run the latest updates for the vulnerability.


So it's really not a matter of basic SQL-injection. That stuff is protected against in the code in several different ways. It's a server-side vulnerability that is exploited and something most people have no control over. The only sites at risk are those running on a Windows server. Just do a google search and you'll see the hundreds of thousands of sites that have been hit in this way.

Point being we have to go a roundabout way to prevent this from happening again, and again, and again... and again.....

That's the internet for you.
I'd rather have a bottle in front of me than a frontal lobotomy
Jonoman92
Profile Blog Joined September 2006
United States9104 Posts
June 05 2008 18:29 GMT
#37
I wondered what was going on. I was looking for the thread with the info about my challenge and I realized the most recent threads were from a while ago.
Goosey
Profile Blog Joined September 2005
United States695 Posts
Last Edited: 2008-06-05 18:37:28
June 05 2008 18:36 GMT
#38
That sucks. :| I am surprised your host doesn't do regular backups

edit: oh and they run Windows Server? Unless you are reliant on that software stack I would recommend switching hosts for sure. Daily backup is pretty much standard.
#1 Shuttle Fan.
nofAcedAgent
Profile Blog Joined July 2007
United States952 Posts
Last Edited: 2008-06-05 19:27:47
June 05 2008 19:27 GMT
#39
On June 05 2008 12:56 Xeris wrote:
who the hell cares where it is -________-; blog is the same shit as a forum post anyways, it's the exact same format, it's just in a different subsection of the site



Chill yo~ I think he just meant it would get noticed by more people in the brood war section, hes not the one that hacked you, control your rage (;p) (not that I know the benefit of having more viewers)

Anyway, hope the bastard gets caught man, sorry to hear it
Xeris
Profile Blog Joined July 2005
Iran17695 Posts
June 05 2008 22:00 GMT
#40
Apparently whoever did it tried to do it again last night and today -___________- !!

Woo I hope whoever hacked my site shows up to a LAN.
twitter.com/xerislight -- follow me~~
Prev 1 2 3 Next All
Please log in or register to reply.
Live Events Refresh
SC Evo League
12:00
S2 Championship: Ro16 Day 2
IndyStarCraft 204
SteadfastSC86
EnkiAlexander 35
IntoTheiNu 13
Liquipedia
WardiTV Summer Champion…
11:00
Playoffs Day 1
ByuN vs herO
MaxPax vs Zoun
Clem vs NightMare
WardiTV1010
Liquipedia
Sparkling Tuna Cup
10:00
Weekly #103
Solar vs ShoWTimELIVE!
ByuN vs TBD
CranKy Ducklings341
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
IndyStarCraft 204
Rex 127
ProTech90
SteadfastSC 86
BRAT_OK 73
MindelVK 37
StarCraft: Brood War
Britney 41597
Larva 1103
Killer 494
Hyun 362
PianO 355
Pusan 331
Rush 326
Last 292
ggaemo 279
Mini 277
[ Show more ]
Hyuk 238
firebathero 215
Barracks 155
Mind 125
Sea.KH 46
soO 35
Free 32
ajuk12(nOOB) 24
HiyA 17
Noble 14
Sacsri 7
Dota 2
Gorgc9502
qojqva1409
XcaliburYe363
Pyrionflax206
Fuzer 158
League of Legends
Dendi847
Counter-Strike
summit1g8694
olofmeister1733
Super Smash Bros
Mew2King63
Heroes of the Storm
Khaldor210
Other Games
singsing2058
B2W.Neo1009
RotterdaM229
byalli203
rGuardiaN22
KnowMe9
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 15 non-featured ]
StarCraft 2
• Reevou 12
• intothetv
• AfreecaTV YouTube
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• C_a_k_e 2861
• WagamamaTV414
League of Legends
• Nemesis3152
• Jankos2457
Upcoming Events
Chat StarLeague
2h 48m
Razz vs Julia
StRyKeR vs ZZZero
Semih vs TBD
Replay Cast
10h 48m
Afreeca Starleague
20h 48m
Queen vs HyuN
EffOrt vs Calm
Wardi Open
21h 48m
RotterdaM Event
1d 1h
Replay Cast
1d 10h
Afreeca Starleague
1d 20h
Rush vs TBD
Jaedong vs Mong
WardiTV Summer Champion…
1d 21h
PiGosaur Monday
2 days
Afreeca Starleague
2 days
herO vs TBD
Royal vs Barracks
[ Show More ]
Replay Cast
3 days
The PondCast
3 days
WardiTV Summer Champion…
3 days
Replay Cast
4 days
LiuLi Cup
4 days
Cosmonarchy
5 days
OyAji vs Sziky
Sziky vs WolFix
WolFix vs OyAji
BSL Team Wars
5 days
Team Hawk vs Team Dewalt
BSL Team Wars
5 days
Team Hawk vs Team Bonyth
SC Evo League
5 days
[BSL 2025] Weekly
6 days
SC Evo League
6 days
Liquipedia Results

Completed

Jiahua Invitational
uThermal 2v2 Main Event
HCC Europe

Ongoing

Copa Latinoamericana 4
BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Qualifiers
ASL Season 20
CSL Season 18: Qualifier 1
Acropolis #4 - TS1
CSLAN 3
SEL Season 2 Championship
WardiTV Summer 2025
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
BLAST.tv Austin Major 2025

Upcoming

CSL Season 18: Qualifier 2
CSL 2025 AUTUMN (S18)
LASL Season 20
BSL Season 21
BSL 21 Team A
Chzzk MurlocKing SC1 vs SC2 Cup #2
RSL Revival: Season 2
Maestros of the Game
EC S1
Sisters' Call Cup
IEM Chengdu 2025
PGL Masters Bucharest 2025
MESA Nomadic Masters Fall
Thunderpick World Champ.
CS Asia Championships 2025
Roobet Cup 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.