Verified:

Vic Game profile

Member
6543

Apr 14th 2013, 22:11:43

Warning: mysql_connect() [function.mysql-connect]: User 'boxcardb' has exceeded the 'max_user_connections' resource (current value: 10) in /home/pangaea/boxcar/classes/security.php on line 15

En4cer85

Member
411

Apr 14th 2013, 22:16:42

Did it to me too

discharged Game profile

Member
45

Apr 14th 2013, 22:18:59

Warning: mysql_query() [function.mysql-query]: Access denied for user 'www-data'@'localhost' (using password: NO) in /home/pangaea/boxcar/portal/lib/db_fns.php on line 11

So the www-data user is denied to access the mySQL database? That is a bit suspicious, who is hosting this? it seems like someone wants boxcar to be down, is it someone from pdm or LaF that is hosting?

SAM_DANGER Game profile

Member
1236

Apr 14th 2013, 22:20:32

PDM BROKE BOXCAR. THEY HAVE FSED US ALL!

Xinhuan Game profile

Member
3728

Apr 14th 2013, 22:21:18

Actually, qzjul (Evo) hosts boxcar.

Nekked Game profile

Member
885

Apr 14th 2013, 22:23:22

kill joy Xin!

Marshal Game profile

Member
32,589

Apr 14th 2013, 22:31:46

yea bc is on qz's server due what tc did. no1 else is that trustworthy.

looks fixed.
Patience: Yep, I'm with ELK and Marshal.

ELKronos: Patty is more hairy.

Gallery: K at least I am to my expectations now.

LadyGrizz boobies is fine

NOW3P: Morwen is a much harsher mistress than boredom....

Dibs Ludicrous Game profile

Member
6702

Apr 14th 2013, 22:34:54

same MySQL server as EE?
There are no messages in your Inbox.
Elvis has left the building.

Stevano Game profile

Member
209

Apr 14th 2013, 22:52:40

still exploded.

Mr. Copper

Member
112

Apr 14th 2013, 22:58:14

wow Pang. Your coding is just epic...

www-data with blank password for your DB calls huh? That's really smart.

Can you point me in the direction of your phpmyadmin login so I can view all of boxcar and possibly more?

Qzjul, get pang to fix this crap before your whole server gets compromised.

Mr. Copper

Member
112

Apr 14th 2013, 22:59:02

PS it appears pang learned nothing about security from the TC/hanlong stuff...

LittleItaly Game profile

Game Moderator
Alliance, FFA, & Cooperation
2194

Apr 14th 2013, 23:00:57

www-data'@'localhost is denied because it is trying to get in without a password that is required.
LittleItaly
SOL Vet
-Discord: LittleItaly#2905
-IRC: irc.scourge.se #sol
-Apply today @ http://sol.ghqnet.com for Alliance

Dibs Ludicrous Game profile

Member
6702

Apr 14th 2013, 23:13:31

wonder if this has anything to do with me deciding to watch Battlestar Galactica today? somebody decided to call in the Cylons? mmmm, boobies.
There are no messages in your Inbox.
Elvis has left the building.

Mr. Copper

Member
112

Apr 14th 2013, 23:14:40

that can also happen if the DB is down LI. But yes I spoke to QZ and apparently pang's code makes random calls to this user but there is no www-data in the database.

Dibs Ludicrous Game profile

Member
6702

Apr 14th 2013, 23:16:28

QZ needs to get faster hamsters to run in the wheel. or maybe they just need some steroids.
There are no messages in your Inbox.
Elvis has left the building.

iolair Game profile

Member
151

Apr 14th 2013, 23:20:08

yea front end blames back-end and versa vice
nothing to see here ... move along

qzjul Game profile

Administrator
Game Development
10,263

Apr 15th 2013, 1:12:13

i'm going to put boxcar in a VM at some point here

just learning about how to set up & administer VM's this weekend heh
Finally did the signature thing.

Goofy Game profile

Member
415

Apr 15th 2013, 1:29:49

Think it just went down again.

Revelix Game profile

New Member
4

Apr 15th 2013, 1:29:49

Fix the database config, give it more connections...

General Earl Game profile

Member
896

Apr 15th 2013, 1:34:55

then you run into problems with the game getting cut off. The problem is being worked on. Be patient while they work on it.
General Earl
----
Every time I read AT: http://i.imgur.com/jeryjn8.gif
︻╦╤─✮ ┄ ┄ RatttaTaatataatat!

Devestation Game profile

Member
812

Apr 15th 2013, 5:29:52

still up for me

qzjul Game profile

Administrator
Game Development
10,263

Apr 16th 2013, 0:38:17

the main problem is the half-minute queries that can cause it to pile up on itself

but i've looked at fixing them, and there's no quick way for me to do it, i'm not familiar enough with its db
Finally did the signature thing.

Sov Game profile

Member
2500

Apr 16th 2013, 0:47:06

Qz, as we discussed over lunch last year... You should just open up a new hosting site based on Evo's template ;)

qzjul Game profile

Administrator
Game Development
10,263

Apr 16th 2013, 0:49:53

yes! i should!

man i need more time though =(
Finally did the signature thing.

Pang Game profile

Administrator
Game Development
5731

Apr 16th 2013, 1:22:16

not to complain to qz in public, but i'd have fixed all the glaring problems in the first place if I had root access to the game server to make some changes to the apache config.

the boxcar codebase is garbage and I'd like to just shut it down if there was a public, viable alternative hosted... but it really just needs a few apache rules tweaked to work right (non-absolute paths, case insentive queries and probably a few more I'm forgetting about, but if Xin just gave me a braindump of all the issues he flagged earlier in private, it would likely encapsulate all of them). I'm in the same boat as qz -- no time. And with the time I have, ee isn't really on my priority list any more other than coming here once in a while when someone messages me about the most recent outlandish thing to happen. And then I read a few threads, remember why EE's not on my priority list and I go back to other stuff :-(

PS. Mr Copper is just crying wolf; there is no database/security problem in any way shape or form unless someone inserted code without my knowledge prior to the migration to the EE environment.

Edited By: Pang on Apr 16th 2013, 1:28:41
See Original Post
-=Pang=-
Earth Empires Staff
pangaea [at] earthempires [dot] com

Boxcar - Earth Empires Clan & Alliance Hosting
http://www.boxcarhosting.com

Requiem Game profile

Member
EE Patron
9092

Apr 16th 2013, 1:44:15

<3 Pang

Mr. Copper

Member
112

Apr 16th 2013, 2:22:01

lol yep crying wolf. Mysql generates errors about www-data getting access denied when it gets in the mood right?

Pang if you'll sign a hold-harmless I'll show you EVERYTHING wrong with boxcar.

Put up or shutup.

Pang Game profile

Administrator
Game Development
5731

Apr 16th 2013, 3:22:14

www-data is not the user that Boxcar uses to access the database.

just shut up.
-=Pang=-
Earth Empires Staff
pangaea [at] earthempires [dot] com

Boxcar - Earth Empires Clan & Alliance Hosting
http://www.boxcarhosting.com

mdevol Game profile

Member
3229

Apr 16th 2013, 5:31:30

Boxcar crashing just as LaF goes to war? color me shocked....
Surely what a man does when he is caught off his guard is the best evidence as to what sort of man he is. - C.S. Lewis

Mr. Copper

Member
112

Apr 16th 2013, 11:09:27

[quote poster=discharged; 24089; 446111]Warning: mysql_query() [function.mysql-query]: Access denied for user 'www-data'@'localhost' (using password: NO) in /home/pangaea/boxcar/portal/lib/db_fns.php on line 11

[/quote]

As I said, mysql is known for making up fake authentication attempts. That's what I hear at atleast...

I can't believe you do this for a living, no wonder my job security is through the roof ha


PS pang, in case you were wondering the call to www-data@localhost is in the db_fns.php file on line 11...

No, you shutup ;)


PPS Hey Pang since you locked this so you wouldn't look bad I'll write here. I never stated that this was your user, I stated there was a call to this user in your code on line 11. McDonald's actually has quite a good information security department but I don't work there, sorry but good try ;). Your code is likely full of plenty of fun easter eggs like the one found above. That's probably why you don't want it tested...

Edited By: Mr. Copper on Apr 16th 2013, 15:28:26. Reason: Mod abuse
See Original Post

Pang Game profile

Administrator
Game Development
5731

Apr 16th 2013, 13:05:18

I can't believe you're so full of yourself. you're wrong and you don't seem to understand it. i'm not telling you more because THAT would be a security risk, but i do not connect to the database with the www-data user -- regardless of what you think you're seeing, that is not the db connection Boxcar uses.

if your theory about your job security is like your ego, it's likely quite overblown. don't burn bridges at McDonalds, eh?

i don't care to continue having you make such incorrect accusations, so thread closed.

Edited By: Pang on Apr 16th 2013, 13:09:23
See Original Post
-=Pang=-
Earth Empires Staff
pangaea [at] earthempires [dot] com

Boxcar - Earth Empires Clan & Alliance Hosting
http://www.boxcarhosting.com