• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 03:17
CEST 09:17
KST 16:17
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 1 - Final Week6[ASL19] Finals Recap: Standing Tall12HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16Code S RO4 & Finals Preview: herO, Rogue, Classic, GuMiho0
Community News
Team TLMC #5 - Submission extension1Firefly given lifetime ban by ESIC following match-fixing investigation17$25,000 Streamerzone StarCraft Pro Series announced7Weekly Cups (June 30 - July 6): Classic Doubles7[BSL20] Non-Korean Championship 4x BSL + 4x China11
StarCraft 2
General
TL Team Map Contest #5: Presented by Monster Energy Team TLMC #5 - Submission extension RSL Revival patreon money discussion thread The GOAT ranking of GOAT rankings Weekly Cups (June 30 - July 6): Classic Doubles
Tourneys
RSL: Revival, a new crowdfunded tournament series $5,100+ SEL Season 2 Championship (SC: Evo) WardiTV Mondays Sparkling Tuna Cup - Weekly Open Tournament FEL Cracov 2025 (July 27) - $8000 live event
Strategy
How did i lose this ZvP, whats the proper response Simple Questions Simple Answers
Custom Maps
External Content
Mutation # 482 Wheel of Misfortune Mutation # 481 Fear and Lava Mutation # 480 Moths to the Flame Mutation # 479 Worn Out Welcome
Brood War
General
A cwal.gg Extension - Easily keep track of anyone Flash Announces Hiatus From ASL [Guide] MyStarcraft BW General Discussion [ASL19] Finals Recap: Standing Tall
Tourneys
[BSL20] Non-Korean Championship 4x BSL + 4x China [Megathread] Daily Proleagues 2025 ACS Season 2 Qualifier Small VOD Thread 2.0
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Nintendo Switch Thread Stormgate/Frost Giant Megathread Path of Exile CCLP - Command & Conquer League Project The PlayStation 5
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
Russo-Ukrainian War Thread US Politics Mega-thread Summer Games Done Quick 2025! Things Aren’t Peaceful in Palestine The Accidental Video Game Porn Archive
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread [\m/] Heavy Metal Thread
Sports
2024 - 2025 Football Thread Formula 1 Discussion NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023 NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Men Take Risks, Women Win Ga…
TrAiDoS
momentary artworks from des…
tankgirl
from making sc maps to makin…
Husyelt
StarCraft improvement
iopq
Trip to the Zoo
micronesia
Customize Sidebar...

Website Feedback

Closed Threads



Active: 527 users

ScForAll unsafe... - Page 5

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 All
ceaRshaf
Profile Joined August 2009
Romania4926 Posts
September 30 2009 14:27 GMT
#81
Well, i can't acces it no more. Maybe it's just me.
Mess with the best, die like the rest.
aKshun
Profile Joined March 2009
Australia18 Posts
October 01 2009 08:17 GMT
#82
On September 30 2009 22:34 StorrZerg wrote:
Show nested quote +
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol


Not sure what my word is worth. But the website is clean on a cookies-disabled browser.

It also no longer has the offending code at the bottom of its page source. Was hit with neither False-Flash request or notification from my AV
When you do something right, people wont notice youve done anything at all.
nicoaldo
Profile Joined March 2009
Argentina939 Posts
October 01 2009 17:54 GMT
#83
Google is not blocking it anymore, it looks like. I entered the page with cookies and auto downloads disabled and didn´t have any problem. It didn´t ask me to download stuff or anything suspicious.
PokePill
Profile Blog Joined March 2009
United States1048 Posts
Last Edited: 2009-10-01 18:08:07
October 01 2009 18:06 GMT
#84
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
October 01 2009 18:14 GMT
#85
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


It was done from an add/message created by a third party on the website using javascript.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Deleriux
Profile Joined September 2009
10 Posts
Last Edited: 2009-10-01 21:42:17
October 01 2009 21:39 GMT
#86
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


Its much simpler than that - the code is appended to the end of the main files. The attacker has write access to them.

Normally thats due to stolen FTP credentials. How that happens - well - generally keyloggers on machines that have access to FTP on scforall.com. Most of the places one gets these keyloggers added to your system is through sites of a less than dignified nature .

These type of attacks are sourced from botnets (keylogger sends FTP details to a botnet, a few hours later the botnet logs in to add its malware to the site). In most cases what happens is the botnet keeps resubmitting its hacks to the site to reverse the affect where a webmaster has removed the bad lines of code from the website.

I see this all the time in my line of work. I emailed the site maintainers with curative/preventative measures to help stop this - I gather that Artosis is not responsible for this - it appears he merely updates the site content via the in built control panels for the website.

Needless to say if they dont clear out the malware on systems that have FTP access to this site the site will continue to get infected - regardless of how often they change the FTP password.

So - be warned - the site might be OK now but infected again tomorrow. We'll just have to wait and get a reliable confirmation that the system that has caused all these problems is cleared and the problem is rectified.

I'm not familiar with Korean ISPs but if they tend to hand out static IP addresses it makes it far simpler to just firewall off FTP access to scforall.com to only a list of authorized IPs.
Eukarya
Profile Joined April 2009
United States29 Posts
October 01 2009 21:58 GMT
#87
I get the same message popup from GosuGamers too. I just clicked "Don't Install" every time it came up and could navigate the site just fine.

Is this coming up on any other SC sites?
Flaccid
Profile Blog Joined August 2006
8835 Posts
Last Edited: 2009-10-06 16:30:26
October 06 2009 16:21 GMT
#88
Site is still pooched. Which is awesome because Artosis keeps posting that it's fixed and "not to worry". By not worrying you'll be downloading some nice malware to your pc simply by loading the site in your browser.

Don't be a faggot Artosis. Take your site down and stop spamming links until you get this fixed. I'd rather get fucking Rick-Rolled.

edit: here is what scforall installs on your computer and how to get rid of it
I'd rather have a bottle in front of me than a frontal lobotomy
Prev 1 2 3 4 5 All
Please log in or register to reply.
Live Events Refresh
Next event in 3h 43m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Nina 263
StarCraft: Brood War
PianO 536
Free 536
Leta 154
Dewaltoss 101
Noble 18
Shine 16
Bale 10
Dota 2
monkeys_forever596
XcaliburYe167
ODPixel27
League of Legends
JimRising 691
Counter-Strike
Stewie2K328
Super Smash Bros
Mew2King227
Westballz38
Heroes of the Storm
Khaldor98
Other Games
summit1g11763
ViBE230
NeuroSwarm71
SortOf68
Fuzer 1
Organizations
Other Games
gamesdonequick5311
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 14 non-featured ]
StarCraft 2
• Berry_CruncH383
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Dota 2
• lizZardDota2147
League of Legends
• Rush2764
• HappyZerGling75
Upcoming Events
Wardi Open
3h 43m
Replay Cast
1d 2h
WardiTV European League
1d 8h
ShoWTimE vs sebesdes
Percival vs NightPhoenix
Shameless vs Nicoract
Krystianer vs Scarlett
ByuN vs uThermal
Harstem vs HeRoMaRinE
PiGosaur Monday
1d 16h
uThermal 2v2 Circuit
2 days
Replay Cast
2 days
The PondCast
3 days
Replay Cast
3 days
Epic.LAN
4 days
CranKy Ducklings
5 days
[ Show More ]
Epic.LAN
5 days
BSL20 Non-Korean Champi…
5 days
Bonyth vs Sziky
Dewalt vs Hawk
Hawk vs QiaoGege
Sziky vs Dewalt
Mihu vs Bonyth
Zhanhun vs QiaoGege
QiaoGege vs Fengzi
Sparkling Tuna Cup
6 days
Online Event
6 days
BSL20 Non-Korean Champi…
6 days
Bonyth vs Zhanhun
Dewalt vs Mihu
Hawk vs Sziky
Sziky vs QiaoGege
Mihu vs Hawk
Zhanhun vs Dewalt
Fengzi vs Bonyth
Liquipedia Results

Completed

2025 ACS Season 2: Qualifier
RSL Revival: Season 1
Murky Cup #2

Ongoing

JPL Season 2
BSL 2v2 Season 3
Copa Latinoamericana 4
Jiahua Invitational
BSL20 Non-Korean Championship
Championship of Russia 2025
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters

Upcoming

CSL Xiamen Invitational
CSL Xiamen Invitational: ShowMatche
2025 ACS Season 2
CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
BSL Season 21
K-Championship
RSL Revival: Season 2
SEL Season 2 Championship
uThermal 2v2 Main Event
FEL Cracov 2025
Esports World Cup 2025
Underdog Cup #2
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.