• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 04:45
CEST 10:45
KST 17:45
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
Classic Games #3: Rogue vs Serral at BlizzCon8[ASL20] Ro16 Preview Pt1: Ascent10Maestros of the Game: Week 1/Play-in Preview12[ASL20] Ro24 Preview Pt2: Take-Off7[ASL20] Ro24 Preview Pt1: Runway13
Community News
SC4ALL $6,000 Open LAN in Philadelphia7Weekly Cups (Sept 1-7): MaxPax rebounds & Clem saga continues23LiuLi Cup - September 2025 Tournaments3Weekly Cups (August 25-31): Clem's Last Straw?39Weekly Cups (Aug 18-24): herO dethrones MaxPax6
StarCraft 2
General
Team Liquid Map Contest #21 - Presented by Monster Energy #1: Maru - Greatest Players of All Time What happened to Singapore/Brazil servers? SC4ALL: A North American StarCraft LAN Classic Games #3: Rogue vs Serral at BlizzCon
Tourneys
SC4ALL $6,000 Open LAN in Philadelphia RSL: Revival, a new crowdfunded tournament series LANified! 37: Groundswell, BYOC LAN, Nov 28-30 2025 LiuLi Cup - September 2025 Tournaments Maestros of The Game—$20k event w/ live finals in Paris
Strategy
Custom Maps
External Content
Mutation # 490 Masters of Midnight Mutation # 489 Bannable Offense Mutation # 488 What Goes Around Mutation # 487 Think Fast
Brood War
General
ASL20 General Discussion BGH Auto Balance -> http://bghmmr.eu/ alas... i aint gon' lie to u bruh... BW General Discussion [ASL20] Ro16 Preview Pt1: Ascent
Tourneys
[ASL20] Ro16 Group B Small VOD Thread 2.0 [ASL20] Ro16 Group A [Megathread] Daily Proleagues
Strategy
Simple Questions, Simple Answers Muta micro map competition Fighting Spirit mining rates [G] Mineral Boosting
Other Games
General Games
Stormgate/Frost Giant Megathread Borderlands 3 The PlayStation 5 General RTS Discussion Thread Iron Harvest: 1920+
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread
Community
General
US Politics Mega-thread Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread The Games Industry And ATVI UK Politics Mega-thread
Fan Clubs
The Happy Fan Club!
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread
Sports
2024 - 2026 Football Thread Formula 1 Discussion MLB/Baseball 2023 TeamLiquid Health and Fitness Initiative For 2023
World Cup 2022
Tech Support
Linksys AE2500 USB WIFI keeps disconnecting Computer Build, Upgrade & Buying Resource Thread High temperatures on bridge(s)
TL Community
BarCraft in Tokyo Japan for ASL Season5 Final The Automated Ban List
Blogs
The Personality of a Spender…
TrAiDoS
A very expensive lesson on ma…
Garnet
hello world
radishsoup
Lemme tell you a thing o…
JoinTheRain
RTS Design in Hypercoven
a11
Evil Gacha Games and the…
ffswowsucks
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1748 users

ScForAll unsafe... - Page 5

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 All
ceaRshaf
Profile Joined August 2009
Romania4926 Posts
September 30 2009 14:27 GMT
#81
Well, i can't acces it no more. Maybe it's just me.
Mess with the best, die like the rest.
aKshun
Profile Joined March 2009
Australia18 Posts
October 01 2009 08:17 GMT
#82
On September 30 2009 22:34 StorrZerg wrote:
Show nested quote +
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol


Not sure what my word is worth. But the website is clean on a cookies-disabled browser.

It also no longer has the offending code at the bottom of its page source. Was hit with neither False-Flash request or notification from my AV
When you do something right, people wont notice youve done anything at all.
nicoaldo
Profile Joined March 2009
Argentina939 Posts
October 01 2009 17:54 GMT
#83
Google is not blocking it anymore, it looks like. I entered the page with cookies and auto downloads disabled and didn´t have any problem. It didn´t ask me to download stuff or anything suspicious.
PokePill
Profile Blog Joined March 2009
United States1048 Posts
Last Edited: 2009-10-01 18:08:07
October 01 2009 18:06 GMT
#84
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
October 01 2009 18:14 GMT
#85
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


It was done from an add/message created by a third party on the website using javascript.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Deleriux
Profile Joined September 2009
10 Posts
Last Edited: 2009-10-01 21:42:17
October 01 2009 21:39 GMT
#86
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


Its much simpler than that - the code is appended to the end of the main files. The attacker has write access to them.

Normally thats due to stolen FTP credentials. How that happens - well - generally keyloggers on machines that have access to FTP on scforall.com. Most of the places one gets these keyloggers added to your system is through sites of a less than dignified nature .

These type of attacks are sourced from botnets (keylogger sends FTP details to a botnet, a few hours later the botnet logs in to add its malware to the site). In most cases what happens is the botnet keeps resubmitting its hacks to the site to reverse the affect where a webmaster has removed the bad lines of code from the website.

I see this all the time in my line of work. I emailed the site maintainers with curative/preventative measures to help stop this - I gather that Artosis is not responsible for this - it appears he merely updates the site content via the in built control panels for the website.

Needless to say if they dont clear out the malware on systems that have FTP access to this site the site will continue to get infected - regardless of how often they change the FTP password.

So - be warned - the site might be OK now but infected again tomorrow. We'll just have to wait and get a reliable confirmation that the system that has caused all these problems is cleared and the problem is rectified.

I'm not familiar with Korean ISPs but if they tend to hand out static IP addresses it makes it far simpler to just firewall off FTP access to scforall.com to only a list of authorized IPs.
Eukarya
Profile Joined April 2009
United States29 Posts
October 01 2009 21:58 GMT
#87
I get the same message popup from GosuGamers too. I just clicked "Don't Install" every time it came up and could navigate the site just fine.

Is this coming up on any other SC sites?
Flaccid
Profile Blog Joined August 2006
8843 Posts
Last Edited: 2009-10-06 16:30:26
October 06 2009 16:21 GMT
#88
Site is still pooched. Which is awesome because Artosis keeps posting that it's fixed and "not to worry". By not worrying you'll be downloading some nice malware to your pc simply by loading the site in your browser.

Don't be a faggot Artosis. Take your site down and stop spamming links until you get this fixed. I'd rather get fucking Rick-Rolled.

edit: here is what scforall installs on your computer and how to get rid of it
I'd rather have a bottle in front of me than a frontal lobotomy
Prev 1 2 3 4 5 All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 15m
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
Nina 158
OGKoka 123
StarCraft: Brood War
zelot 104
sSak 96
Noble 88
Dewaltoss 74
ToSsGirL 70
Sharp 51
Movie 39
Hyuk 36
Bale 33
Rush 19
[ Show more ]
Purpose 14
Dota 2
The International71657
Gorgc4732
League of Legends
JimRising 518
Counter-Strike
olofmeister661
Stewie2K659
Foxcn476
shoxiejesuss235
allub114
Other Games
ceh9341
hungrybox206
crisheroes167
XaKoH 160
Happy117
NeuroSwarm26
Organizations
Other Games
gamesdonequick1029
StarCraft: Brood War
UltimateBattle 68
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 12 non-featured ]
StarCraft 2
• LUISG 27
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• iopq 2
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
Upcoming Events
RSL Revival
1h 15m
Classic vs TriGGeR
ByuN vs Maru
Online Event
3h 15m
Kung Fu Cup
3h 15m
BSL Team Wars
10h 15m
RSL Revival
1d 1h
Maestros of the Game
1d 5h
ShoWTimE vs Classic
Clem vs herO
Serral vs Bunny
Reynor vs Zoun
Cosmonarchy
1d 7h
Bonyth vs Dewalt
[BSL 2025] Weekly
1d 9h
RSL Revival
2 days
Maestros of the Game
2 days
[ Show More ]
BSL Team Wars
2 days
Afreeca Starleague
3 days
Snow vs Sharp
Jaedong vs Mini
Wardi Open
3 days
Sparkling Tuna Cup
4 days
Afreeca Starleague
4 days
Light vs Speed
Larva vs Soma
LiuLi Cup
5 days
The PondCast
6 days
Liquipedia Results

Completed

Copa Latinoamericana 4
SEL Season 2 Championship
HCC Europe

Ongoing

BSL 20 Team Wars
KCM Race Survival 2025 Season 3
BSL 21 Points
ASL Season 20
CSL 2025 AUTUMN (S18)
LASL Season 20
RSL Revival: Season 2
Maestros of the Game
Chzzk MurlocKing SC1 vs SC2 Cup #2
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1

Upcoming

2025 Chongqing Offline CUP
BSL Polish World Championship 2025
BSL Season 21
BSL 21 Team A
EC S1
SL Budapest Major 2025
BLAST Rivals Fall 2025
IEM Chengdu 2025
PGL Masters Bucharest 2025
Thunderpick World Champ.
MESA Nomadic Masters Fall
CS Asia Championships 2025
ESL Pro League S22
StarSeries Fall 2025
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.