• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 04:04
CET 09:04
KST 17:04
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
ByuL: The Forgotten Master of ZvT29Behind the Blue - Team Liquid History Book19Clem wins HomeStory Cup 289HomeStory Cup 28 - Info & Preview13Rongyi Cup S3 - Preview & Info8
Community News
Blizzard Classic Cup - Tastosis announced as captains3Weekly Cups (March 2-8): ByuN overcomes PvT block2GSL CK - New online series13BSL Season 224Vitality ends partnership with ONSYDE20
StarCraft 2
General
Blizzard Classic Cup - Tastosis announced as captains Weekly Cups (March 2-8): ByuN overcomes PvT block GSL CK - New online series Weekly Cups (Feb 23-Mar 1): herO doubles, 2v2 bonanza Vitality ends partnership with ONSYDE
Tourneys
Master Swan Open (Global Bronze-Master 2) RSL Season 4 announced for March-April Sparkling Tuna Cup - Weekly Open Tournament PIG STY FESTIVAL 7.0! (19 Feb - 1 Mar) $5,000 WardiTV Winter Championship 2026
Strategy
Custom Maps
Publishing has been re-enabled! [Feb 24th 2026] Map Editor closed ?
External Content
The PondCast: SC2 News & Results Mutation # 516 Specter of Death Mutation # 515 Together Forever Mutation # 514 Ulnar New Year
Brood War
General
Recent recommended BW games ASL21 General Discussion BSL 22 Map Contest — Submissions OPEN to March 10 BGH Auto Balance -> http://bghmmr.eu/ BSL Season 22
Tourneys
ASL Season 21 Qualifiers March 7-8 [Megathread] Daily Proleagues BWCL Season 64 Announcement [BSL22] Open Qualifier #1 - Sunday 21:00 CET
Strategy
Soma's 9 hatch build from ASL Game 2 Fighting Spirit mining rates Simple Questions, Simple Answers Zealot bombing is no longer popular?
Other Games
General Games
Nintendo Switch Thread PC Games Sales Thread Path of Exile No Man's Sky (PS4 and PC) Stormgate/Frost Giant Megathread
Dota 2
Official 'what is Dota anymore' discussion The Story of Wings Gaming
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Deck construction bug Heroes of StarCraft mini-set
TL Mafia
Mafia Game Mode Feedback/Ideas Vanilla Mini Mafia TL Mafia Community Thread
Community
General
US Politics Mega-thread Mexico's Drug War Things Aren’t Peaceful in Palestine Russo-Ukrainian War Thread YouTube Thread
Fan Clubs
The IdrA Fan Club
Media & Entertainment
[Req][Books] Good Fantasy/SciFi books [Manga] One Piece
Sports
Formula 1 Discussion 2024 - 2026 Football Thread General nutrition recommendations Cricket [SPORT] TL MMA Pick'em Pool 2013
World Cup 2022
Tech Support
Laptop capable of using Photoshop Lightroom?
TL Community
The Automated Ban List
Blogs
Iranian anarchists: organize…
XenOsky
FS++
Kraekkling
Shocked by a laser…
Spydermine0240
Gaming-Related Deaths
TrAiDoS
Unintentional protectionism…
Uldridge
ASL S21 English Commentary…
namkraft
Customize Sidebar...

Website Feedback

Closed Threads



Active: 1863 users

ScForAll unsafe... - Page 5

Forum Index > BW General
Post a Reply
Prev 1 2 3 4 5 All
ceaRshaf
Profile Joined August 2009
Romania4926 Posts
September 30 2009 14:27 GMT
#81
Well, i can't acces it no more. Maybe it's just me.
Mess with the best, die like the rest.
aKshun
Profile Joined March 2009
Australia18 Posts
October 01 2009 08:17 GMT
#82
On September 30 2009 22:34 StorrZerg wrote:
Show nested quote +
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol


Not sure what my word is worth. But the website is clean on a cookies-disabled browser.

It also no longer has the offending code at the bottom of its page source. Was hit with neither False-Flash request or notification from my AV
When you do something right, people wont notice youve done anything at all.
nicoaldo
Profile Joined March 2009
Argentina939 Posts
October 01 2009 17:54 GMT
#83
Google is not blocking it anymore, it looks like. I entered the page with cookies and auto downloads disabled and didn´t have any problem. It didn´t ask me to download stuff or anything suspicious.
PokePill
Profile Blog Joined March 2009
United States1048 Posts
Last Edited: 2009-10-01 18:08:07
October 01 2009 18:06 GMT
#84
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
October 01 2009 18:14 GMT
#85
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


It was done from an add/message created by a third party on the website using javascript.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Deleriux
Profile Joined September 2009
10 Posts
Last Edited: 2009-10-01 21:42:17
October 01 2009 21:39 GMT
#86
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


Its much simpler than that - the code is appended to the end of the main files. The attacker has write access to them.

Normally thats due to stolen FTP credentials. How that happens - well - generally keyloggers on machines that have access to FTP on scforall.com. Most of the places one gets these keyloggers added to your system is through sites of a less than dignified nature .

These type of attacks are sourced from botnets (keylogger sends FTP details to a botnet, a few hours later the botnet logs in to add its malware to the site). In most cases what happens is the botnet keeps resubmitting its hacks to the site to reverse the affect where a webmaster has removed the bad lines of code from the website.

I see this all the time in my line of work. I emailed the site maintainers with curative/preventative measures to help stop this - I gather that Artosis is not responsible for this - it appears he merely updates the site content via the in built control panels for the website.

Needless to say if they dont clear out the malware on systems that have FTP access to this site the site will continue to get infected - regardless of how often they change the FTP password.

So - be warned - the site might be OK now but infected again tomorrow. We'll just have to wait and get a reliable confirmation that the system that has caused all these problems is cleared and the problem is rectified.

I'm not familiar with Korean ISPs but if they tend to hand out static IP addresses it makes it far simpler to just firewall off FTP access to scforall.com to only a list of authorized IPs.
Eukarya
Profile Joined April 2009
United States29 Posts
October 01 2009 21:58 GMT
#87
I get the same message popup from GosuGamers too. I just clicked "Don't Install" every time it came up and could navigate the site just fine.

Is this coming up on any other SC sites?
Flaccid
Profile Blog Joined August 2006
8887 Posts
Last Edited: 2009-10-06 16:30:26
October 06 2009 16:21 GMT
#88
Site is still pooched. Which is awesome because Artosis keeps posting that it's fixed and "not to worry". By not worrying you'll be downloading some nice malware to your pc simply by loading the site in your browser.

Don't be a faggot Artosis. Take your site down and stop spamming links until you get this fixed. I'd rather get fucking Rick-Rolled.

edit: here is what scforall installs on your computer and how to get rid of it
I'd rather have a bottle in front of me than a frontal lobotomy
Prev 1 2 3 4 5 All
Please log in or register to reply.
Live Events Refresh
Next event in 1h 56m
[ Submit Event ]
Live Streams
Refresh
StarCraft: Brood War
BeSt 535
Shuttle 348
actioN 272
Leta 260
EffOrt 127
Dewaltoss 124
Bale 60
Nal_rA 38
NotJumperer 23
NaDa 19
[ Show more ]
sSak 19
ToSsGirL 19
Sharp 11
Dota 2
febbydoto24
Counter-Strike
Stewie2K803
m0e_tv693
Super Smash Bros
Mew2King121
Other Games
ceh9318
Tasteless186
Happy184
crisheroes53
Organizations
Dota 2
PGL Dota 2 - Main Stream2705
Other Games
gamesdonequick1100
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 15 non-featured ]
StarCraft 2
• Berry_CruncH227
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
• Migwel
• sooper7s
StarCraft: Brood War
• iopq 1
• BSLYoutube
• STPLYoutube
• ZZZeroYoutube
League of Legends
• Lourlo1555
• Stunt645
• HappyZerGling100
Upcoming Events
GSL
1h 56m
WardiTV Team League
3h 56m
The PondCast
1d 1h
WardiTV Team League
1d 3h
Replay Cast
1d 15h
Replay Cast
2 days
CranKy Ducklings
3 days
RSL Revival
3 days
WardiTV Team League
3 days
uThermal 2v2 Circuit
3 days
[ Show More ]
BSL
3 days
Sparkling Tuna Cup
4 days
RSL Revival
4 days
WardiTV Team League
4 days
BSL
4 days
Replay Cast
4 days
Replay Cast
5 days
Wardi Open
5 days
Monday Night Weeklies
5 days
WardiTV Team League
6 days
Liquipedia Results

Completed

Spring Cup 2026
WardiTV Winter 2026
Underdog Cup #3

Ongoing

KCM Race Survival 2026 Season 1
Jeongseon Sooper Cup
BSL Season 22
RSL Revival: Season 4
Nations Cup 2026
ESL Pro League S23 Stage 1&2
PGL Cluj-Napoca 2026
IEM Kraków 2026
BLAST Bounty Winter 2026
BLAST Bounty Winter Qual

Upcoming

CSL Elite League 2026
ASL Season 21
Acropolis #4 - TS6
Acropolis #4
IPSL Spring 2026
CSLAN 4
HSC XXIX
uThermal 2v2 2026 Main Event
Bellum Gens Elite Stara Zagora 2026
NationLESS Cup
CS Asia Championships 2026
Asian Champions League 2026
IEM Atlanta 2026
PGL Astana 2026
BLAST Rivals Spring 2026
CCT Season 3 Global Finals
IEM Rio 2026
PGL Bucharest 2026
Stake Ranked Episode 1
BLAST Open Spring 2026
ESL Pro League S23 Finals
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2026 TLnet. All Rights Reserved.