Connect with us
Prague Gaming & TECH Summit 2025 (25-26 March)
728x90 banner available here

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Stretch Network announces Black Friday Weekend Tournament

Published

on

Reading Time: < 1 minute

Black Friday Weekend is here! Stretch Network introduces another player-focused initiative – the Black Friday Weekend promotion. Running from November 29th to December 1st, this event offers up to 90% discounts on buy-ins for the World Poker League tournament series.

Here’s how it works:

  • Players register for special phase tournaments at a reduced cost.
  • These 2-minute events don’t require player actions and provide the same starting stack as the target tournament.
  • After the phase tournament ends, players are automatically registered for the main event.
  • Players already in the target tournament will have their stacks combined for added excitement.

Raise with us to go all-in on player satisfaction.

The post Stretch Network announces Black Friday Weekend Tournament appeared first on European Gaming Industry News.

Continue Reading

Latest News

SOFTSWISS Integrates Jackpot Aggregator with RedStar Casino

Published

on

Reading Time: 2 minutes

 

SOFTSWISS has announced the integration of its Jackpot Aggregator, a cutting-edge player engagement solution, with RedStar Casino, a secure and reliable gaming platform. This partnership demonstrates the seamless integration capabilities of SOFTSWISS products with third-party casino platforms, further solidifying the versatility of the Jackpot Aggregator.

Previously, the SOFTSWISS Jackpot Aggregator team primarily worked with clients using the SOFTSWISS Casino Platform and the SOFTSWISS Game Aggregator, delivering efficient and seamless engagement tools. The collaboration with RedStar Casino highlights the product’s ability to integrate effortlessly with external platforms, showcasing its adaptability beyond the SOFTSWISS ecosystem.

To support smooth onboarding, the SOFTSWISS team provides comprehensive API integration documentation and dedicated Technical Account Manager support, addressing any potential queries in real time.

Angelina Stasiuk, Head of Business Line at SOFTSWISS Jackpot Aggregator, shared: “The SOFTSWISS Jackpot Aggregator is constantly evolving. In addition to expanding engagement mechanics such as jackpots, drops, multi-prizes, and Prime Network Jackpot campaigns, we are also broadening our client base and market reach. Regardless of their casino platform, any client can integrate the SOFTSWISS Jackpot Aggregator and easily launch diverse engagement campaigns.”

RedStar Casino representatives added: “We appreciate the professionalism of the SOFTSWISS Jackpot Aggregator team and the simplicity of the product’s integration process. We have already launched a three-level progressive jackpot campaign and are thrilled to offer our players a diverse and engaging gaming experience.”

This successful integration marks a milestone in the SOFTSWISS Jackpot Aggregator’s mission to deliver innovative and adaptable engagement solutions, ensuring seamless functionality and exceptional value for operators and players alike.

Recently, the SOFTSWISS Jackpot Aggregator announced the improvement of its product by introducing a multi-prizes feature. This new functionality enables operators to split winnings among several players or groups, offering customisable distribution methods tailored to various engagement strategies.

 

About SOFTSWISS

SOFTSWISS is an international technology company with over 15 years of experience in developing innovative solutions for the iGaming industry. SOFTSWISS holds a number of gaming licences and provides comprehensive software for managing iGaming projects. The company’s product portfolio includes the Online Casino Platform, the Game Aggregator with over 23,500 casino games, the Affilka Affiliate Platform, the Sportsbook Software and the Jackpot Aggregator. In 2013, SOFTSWISS revolutionised the industry by introducing the world’s first Bitcoin-optimised online casino solution. The expert team, based in Malta, Poland, and Georgia, counts over 2,000 employees.

The post SOFTSWISS Integrates Jackpot Aggregator with RedStar Casino appeared first on European Gaming Industry News.

Continue Reading

Latest News

Starburst Galaxy Ushers in NetEnt’s New Era

Published

on

Reading Time: 2 minutes

 

Starburst Galaxy, a sequel to the iconic Starburst that reshaped the online slot market, is propelling veteran NetEnt to new heights. The game takes players on a cosmic journey and launches NetEnt into the next phase of its evolution.

As players blast off into a stellar adventure with this dazzling sequel, NetEnt enters a new era. The revolutionary developer’s Phase 1 brought online slots to desktops without cumbersome downloads and allowed players to trial games through free play. Phase 2 brought players’ favourite slots to their mobile screens so they could play anytime, anywhere. Now, Starburst Galaxy stands as a testament to NetEnt’s new Phase 3, where many new features and mechanics await players.

Starburst Galaxy builds on the success of its predecessor, embracing NetEnt’s signature Avalanche™ mechanic, where winning symbols vanish, allowing new ones to fall into place and creating opportunities for consecutive wins from a single spin. Adding to the excitement, the new Feature Generator lets each win contribute to unlocking five dynamic features: symbol destroy, random wilds, expanding wilds, line transform, and symbol upgrade.

The Galaxy Star feature introduces a thrilling twist with an expansive 7×7 grid and a dazzling 3×3 Starburst Wild that activates additional wilds and unique features. Landing three scatters fires up the Mega Star feature, summoning a 2×2 Starburst Wild and introducing powerful multipliers throughout the round, while a retrigger remains possible by refilling the Galaxy Metre with each win.

An exciting new addition introduced in Starburst Galaxy, the Elevate Feature will be rolled out across all NetEnt slots moving forward. Elevate gives players the power to customise their gameplay by activating various game features and add-ons directly from a list, using base bet multipliers to enhance the experience. (The availability of the Elevate Feature varies by region.)

The new era of NetEnt will also feature upgrades across its product offerings, including new robust multi-level jackpots and more big wins through the GigaMath Model. Classic games will receive visual and UX enhancements, and new Speed Spins and Super Speed Spins options will allow players to play at their own pace. Additionally, operators can customise their own Starburst slot with the introduction of Starburst Brandable.

Todd Haushalter, Chief Product Officer at Evolution, said: “This is a defining moment for NetEnt as we enter a new era with the launch of Starburst Galaxy. The game introduces innovative features, stunning visuals, and advanced technology while honouring the iconic classic that transformed the online video slot market. I’m incredibly proud of our team’s hard work—from the enhanced gameplay to the refreshed brand design, which marks another milestone and a new direction in NetEnt’s evolution. We’re excited for players to experience Starburst Galaxy, and this is only the beginning of what’s to come.”

The post Starburst Galaxy Ushers in NetEnt’s New Era appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 HIPTHER Agency. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.