• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EST 16:42
CET 22:42
KST 06:42
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
TL.net Map Contest #21: Winners11Intel X Team Liquid Seoul event: Showmatches and Meet the Pros10[ASL20] Finals Preview: Arrival13TL.net Map Contest #21: Voting12[ASL20] Ro4 Preview: Descent11
Community News
[TLMC] Fall/Winter 2025 Ladder Map Rotation7Weekly Cups (Nov 3-9): Clem Conquers in Canada4SC: Evo Complete - Ranked Ladder OPEN ALPHA8StarCraft, SC2, HotS, WC3, Returning to Blizzcon!45$5,000+ WardiTV 2025 Championship7
StarCraft 2
General
[TLMC] Fall/Winter 2025 Ladder Map Rotation Mech is the composition that needs teleportation t Weekly Cups (Nov 3-9): Clem Conquers in Canada Craziest Micro Moments Of All Time? SC: Evo Complete - Ranked Ladder OPEN ALPHA
Tourneys
RSL S3 Round of 16 Master Swan Open (Global Bronze-Master 2) Constellation Cup - Main Event - Stellar Fest Tenacious Turtle Tussle Sparkling Tuna Cup - Weekly Open Tournament
Strategy
Custom Maps
Map Editor closed ?
External Content
Mutation # 499 Chilling Adaptation Mutation # 498 Wheel of Misfortune|Cradle of Death Mutation # 497 Battle Haredened Mutation # 496 Endless Infection
Brood War
General
BW General Discussion FlaSh on: Biggest Problem With SnOw's Playstyle Terran 1:35 12 Gas Optimization BGH Auto Balance -> http://bghmmr.eu/ [ASL20] Ask the mapmakers — Drop your questions
Tourneys
[Megathread] Daily Proleagues [BSL21] RO32 Group D - Sunday 21:00 CET [BSL21] RO32 Group C - Saturday 21:00 CET [ASL20] Grand Finals
Strategy
Current Meta PvZ map balance How to stay on top of macro? Soma's 9 hatch build from ASL Game 2
Other Games
General Games
Stormgate/Frost Giant Megathread Nintendo Switch Thread EVE Corporation Should offensive tower rushing be viable in RTS games? Path of Exile
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread SPIRED by.ASL Mafia {211640}
Community
General
Things Aren’t Peaceful in Palestine US Politics Mega-thread Russo-Ukrainian War Thread Canadian Politics Mega-thread The Games Industry And ATVI
Fan Clubs
White-Ra Fan Club The herO Fan Club!
Media & Entertainment
[Manga] One Piece Anime Discussion Thread Movie Discussion! Korean Music Discussion Series you have seen recently...
Sports
2024 - 2026 Football Thread Formula 1 Discussion NBA General Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
SC2 Client Relocalization [Change SC2 Language] Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Dyadica Gospel – a Pulp No…
Hildegard
Coffee x Performance in Espo…
TrAiDoS
Saturation point
Uldridge
DnB/metal remix FFO Mick Go…
ImbaTosS
Reality "theory" prov…
perfectspheres
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1819 users

ScForAll unsafe... - Page 5

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 All
ceaRshaf
Profile Joined August 2009
Romania4926 Posts
September 30 2009 14:27 GMT
#81
Well, i can't acces it no more. Maybe it's just me.
Mess with the best, die like the rest.
aKshun
Profile Joined March 2009
Australia18 Posts
October 01 2009 08:17 GMT
#82
On September 30 2009 22:34 StorrZerg wrote:
Show nested quote +
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol


Not sure what my word is worth. But the website is clean on a cookies-disabled browser.

It also no longer has the offending code at the bottom of its page source. Was hit with neither False-Flash request or notification from my AV
When you do something right, people wont notice youve done anything at all.
nicoaldo
Profile Joined March 2009
Argentina939 Posts
October 01 2009 17:54 GMT
#83
Google is not blocking it anymore, it looks like. I entered the page with cookies and auto downloads disabled and didn´t have any problem. It didn´t ask me to download stuff or anything suspicious.
PokePill
Profile Blog Joined March 2009
United States1048 Posts
Last Edited: 2009-10-01 18:08:07
October 01 2009 18:06 GMT
#84
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
October 01 2009 18:14 GMT
#85
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


It was done from an add/message created by a third party on the website using javascript.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Deleriux
Profile Joined September 2009
10 Posts
Last Edited: 2009-10-01 21:42:17
October 01 2009 21:39 GMT
#86
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


Its much simpler than that - the code is appended to the end of the main files. The attacker has write access to them.

Normally thats due to stolen FTP credentials. How that happens - well - generally keyloggers on machines that have access to FTP on scforall.com. Most of the places one gets these keyloggers added to your system is through sites of a less than dignified nature .

These type of attacks are sourced from botnets (keylogger sends FTP details to a botnet, a few hours later the botnet logs in to add its malware to the site). In most cases what happens is the botnet keeps resubmitting its hacks to the site to reverse the affect where a webmaster has removed the bad lines of code from the website.

I see this all the time in my line of work. I emailed the site maintainers with curative/preventative measures to help stop this - I gather that Artosis is not responsible for this - it appears he merely updates the site content via the in built control panels for the website.

Needless to say if they dont clear out the malware on systems that have FTP access to this site the site will continue to get infected - regardless of how often they change the FTP password.

So - be warned - the site might be OK now but infected again tomorrow. We'll just have to wait and get a reliable confirmation that the system that has caused all these problems is cleared and the problem is rectified.

I'm not familiar with Korean ISPs but if they tend to hand out static IP addresses it makes it far simpler to just firewall off FTP access to scforall.com to only a list of authorized IPs.
Eukarya
Profile Joined April 2009
United States29 Posts
October 01 2009 21:58 GMT
#87
I get the same message popup from GosuGamers too. I just clicked "Don't Install" every time it came up and could navigate the site just fine.

Is this coming up on any other SC sites?
Flaccid
Profile Blog Joined August 2006
8850 Posts
Last Edited: 2009-10-06 16:30:26
October 06 2009 16:21 GMT
#88
Site is still pooched. Which is awesome because Artosis keeps posting that it's fixed and "not to worry". By not worrying you'll be downloading some nice malware to your pc simply by loading the site in your browser.

Don't be a faggot Artosis. Take your site down and stop spamming links until you get this fixed. I'd rather get fucking Rick-Rolled.

edit: here is what scforall installs on your computer and how to get rid of it
I'd rather have a bottle in front of me than a frontal lobotomy
Prev 1 2 3 4 5 All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 19m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
White-Ra 286
UpATreeSC 209
PiGStarcraft143
Livibee 99
ZombieGrub71
JuggernautJason64
ProTech24
ForJumy 1
StarCraft: Brood War
Calm 2139
Shuttle 463
sas.Sziky 66
Rock 34
ivOry 14
NaDa 13
Sexy 13
Dota 2
Dendi1074
syndereN217
LuMiX1
Counter-Strike
Foxcn486
Super Smash Bros
Mew2King85
Heroes of the Storm
Liquid`Hasu495
Other Games
Grubby4910
C9.Mang074
Trikslyr46
Maynarde6
Nathanias3
Organizations
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 20 non-featured ]
StarCraft 2
• Hupsaiya 20
• Adnapsc2 6
• Dystopia_ 1
• intothetv
• Kozan
• sooper7s
• Migwel
• LaughNgamezSOOP
• AfreecaTV YouTube
• IndyKCrew
StarCraft: Brood War
• 80smullet 17
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota2673
• WagamamaTV426
• lizZardDota250
League of Legends
• imaqtpie3231
• TFBlade1244
Other Games
• Shiphtur268
Upcoming Events
Tenacious Turtle Tussle
1h 19m
The PondCast
12h 19m
RSL Revival
12h 19m
Solar vs Zoun
MaxPax vs Bunny
Kung Fu Cup
14h 19m
ByuN vs ShoWTimE
Classic vs Cure
Reynor vs TBD
WardiTV Korean Royale
14h 19m
PiGosaur Monday
1d 3h
RSL Revival
1d 12h
Classic vs Creator
Cure vs TriGGeR
Kung Fu Cup
1d 14h
herO vs TBD
CranKy Ducklings
2 days
RSL Revival
2 days
herO vs Gerald
ByuN vs SHIN
[ Show More ]
Kung Fu Cup
2 days
IPSL
2 days
ZZZero vs rasowy
Napoleon vs KameZerg
BSL 21
2 days
Tarson vs Julia
Doodle vs OldBoy
eOnzErG vs WolFix
StRyKeR vs Aeternum
Sparkling Tuna Cup
3 days
RSL Revival
3 days
Reynor vs sOs
Maru vs Ryung
Kung Fu Cup
3 days
WardiTV Korean Royale
3 days
BSL 21
3 days
JDConan vs Semih
Dragon vs Dienmax
Tech vs NewOcean
TerrOr vs Artosis
IPSL
3 days
Dewalt vs WolFix
eOnzErG vs Bonyth
Replay Cast
4 days
Wardi Open
4 days
Monday Night Weeklies
4 days
WardiTV Korean Royale
5 days
The PondCast
6 days
Liquipedia Results

Completed

Proleague 2025-11-07
Stellar Fest: Constellation Cup
Eternal Conflict S1

Ongoing

C-Race Season 1
IPSL Winter 2025-26
KCM Race Survival 2025 Season 4
SOOP Univ League 2025
YSL S2
BSL Season 21
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual

Upcoming

SLON Tour Season 2
BSL 21 Non-Korean Championship
Acropolis #4
IPSL Spring 2026
HSC XXVIII
RSL Offline Finals
WardiTV 2025
RSL Revival: Season 3
META Madness #9
BLAST Bounty Winter 2026
BLAST Bounty Winter 2026: Closed Qualifier
eXTREMESLAND 2025
ESL Impact League Season 8
SL Budapest Major 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.