Jump to content
The Dark Mod Forums

TTLG - anyone having trouble geting in ?


esme

Recommended Posts

Just tried looking at TTLG & got the following error

Database Error: SQLSTATE[HY000] [1862] Your password has expired. To log in you must change it using a client that supports expired passwords.

I get this on 2 different browsers

 

Removed all saved passwords and cookies & still get it

 

Anyone else having an issue or is it just me ?

Link to comment
Share on other sites

are you using google based browsers, they've introduced a system where if a site isn't protected by certain expensive SSL certificates they are going to block access to password protected areas on those sites.

 

I accessed it with Google Chrome just fine. Was able to login too.

Link to comment
Share on other sites

I think it was a database connectionerror on ttlg-forum's side.

 

The password it mentioned, is NOT about your password, but the account what the webserver uses to connect to ttlg mysql database, esme. (error 1862)

Edited by freyk

Info: My portfolio and darkmod graphical installer
Amnesty for Bikerdude!

Link to comment
Share on other sites

Lately there's been a lot of exposure about the vulnerabilities in google chrome over http. Now it's public it means stuff has to be done about it.

 

Can see instantly that TTLG is http only (you'll notice in chrome that there is a broken padlock in the URL bar).

What Stumpy is saying is right (it's a conspiracy!), and Freyk's also correct that it is a server-side error thanks to google's security updates.

Probably TTLG will need to update some php or mysql as it appears as if you're getting the error because mysql is restricting you to sandbox mode or the client (your chrome browser) is connecting to the server via scripts.

It's pretty old, by the looks of things...


80/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP) <---win server 2008 / microsoft iis7.0

Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Since it's a win home server and on http, it's potentially a very soft target.
Uses ascii string for passwords and html encoding for special characters in that field. Usernames are on the forum...

Probably TTLG could fix the issue by changing password expiration.


SET GLOBAL default_password_lifetime = 0;

So that all user's passwords do not expire, whether they connect via scripts or not.

Or the admin could migrate everything to something such as freeBDS, but they've always been windows server forever - also there's a loootttt of data over the past 21 years at that place.

Best course of action would be to use a different browser (eg firefox) and mail the admin with the issue so that it can be resolved, I'd guess.
http://www.ttlg.com/forums/sendmessage.php


I'd recommend migration, as the server has no SSL cypher mapping, however the f= parameter means it is an unlikely target for sql injection "practice".
But it is a windows server and it's vbulliten 4.2.3.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recent Status Updates

    • OrbWeaver

      Does anyone actually use the Normalise button in the Surface inspector? Even after looking at the code I'm not quite sure what it's for.
      · 6 replies
    • Ansome

      Turns out my 15th anniversary mission idea has already been done once or twice before! I've been beaten to the punch once again, but I suppose that's to be expected when there's over 170 FMs out there, eh? I'm not complaining though, I love learning new tricks and taking inspiration from past FMs. Best of luck on your own fan missions!
      · 4 replies
    • The Black Arrow

      I wanna play Doom 3, but fhDoom has much better features than dhewm3, yet fhDoom is old, outdated and probably not supported. Damn!
      Makes me think that TDM engine for Doom 3 itself would actually be perfect.
      · 6 replies
    • Petike the Taffer

      Maybe a bit of advice ? In the FM series I'm preparing, the two main characters have the given names Toby and Agnes (it's the protagonist and deuteragonist, respectively), I've been toying with the idea of giving them family names as well, since many of the FM series have named protagonists who have surnames. Toby's from a family who were usually farriers, though he eventually wound up working as a cobbler (this serves as a daylight "front" for his night time thieving). Would it make sense if the man's popularly accepted family name was Farrier ? It's an existing, though less common English surname, and it directly refers to the profession practiced by his relatives. Your suggestions ?
      · 9 replies
    • nbohr1more

      Looks like the "Reverse April Fools" releases were too well hidden. Darkfate still hasn't acknowledge all the new releases. Did you play any of the new April Fools missions?
      · 5 replies
×
×
  • Create New...