Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

POKERSTARS GALACTIC SERIES PAYS OUT MORE THAN €8 MILLION TO FRENCH, SPANISH AND PORTUGUESE PLAYERS

Published

on

Reading Time: 2 minutes

Series and Main Event both exceed their guarantees

PokerStars’ has once again smashed expectations in Southern Europe, with the Galactic Series, one of its most popular series for players in France, Spain and Portugal, generating an €8 million prize pool, over €1 million above the guarantee. The prize pool was shared out across 261 events and more than 343,000 entries. The highlight of the series was the Main Event that paid out €365,025 to players across the three weeks.

GALACTIC STAR BATTLES FOR SILVER AND GOLD PRIZES

Throughout the series, players had the chance to get their hands on additional Silver and Gold Passes by opting-in to the Galactic Stars Battle. Players opted in for a PokerStars Ambassador, and all those who chose to support the leading Ambassador each week being entered into a freeroll to win a Silver Power Pass.

In Spain, captains ‘WilloelPillo’ and ‘and1ero’ saw a similar pattern. Willo was victorious in weeks one and three with 327,805 and 250,763 points respectively while Álex ‘and1ero’ Romero took the advantage in week two with 318,631 points and Esteban ‘estiwinho’ Pascual couldn’t reach the top spot in any week.

Silver and Gold Passes can be redeemed as entries to a range of PokerStars Live events throughout the year, including marquee stops at the European Poker Tour (EPT) and the PokerStars Open, which debuted this year and have provided players across Europe with world class poker at accessible price points with lively, grassroots-style atmosphere and entertainment. Closing out the season, EPT Prague starts December 3 and runs until December 14, and will be followed by PokerStars Open Cannes on December 16. Players with Gold or Silver Passes can redeem them for entries at both of these events.

“Once again, we’ve seen players from all over France, Spain and Portugal come together to enjoy the Galactic Series”, said Sandro Forleo, Head of Poker Operations for Southern Europe and Italy at PokerStars. “Our Mega Mystery events, where bounties can be won as soon as late reg closes, proved especially popular and continued to offer something new and enjoyable to players at all experience levels.”

 

The post POKERSTARS GALACTIC SERIES PAYS OUT MORE THAN €8 MILLION TO FRENCH, SPANISH AND PORTUGUESE PLAYERS appeared first on European Gaming Industry News.

Continue Reading

Latest News

The eSports World Tournament FIFAe World Cup 2025™ Kicks-Off in Riyadh, Saudi Arabia on December 10!

Published

on

Reading Time: 3 minutes

Commemorating the start of the tournament, a new in-game update arrives and fans can take part in a campaign launching today in eFootball

Konami Digital Entertainment B.V. (Konami) announces the FIFAe World Cup 2025 featuring eFootball. Kicking off on December 10th in Riyadh, Saudi Arabia, the official eSports tournament is hosted by FIFA® for a live audience and live streamed worldwide. This year marks the second edition of the tournament where a record of 90 countries and regions participated in the preliminaries totalling 16.51 million participants.

eFootball official website: konami.com/efootball…

FIFAe World Cup 2025 is an official eSports world championship co-hosted by Konami Digital Entertainment Co., Ltd. and the Fédération Internationale de Football Association (FIFA®). This year 12 national representatives emerged victorious from regional qualifiers and will now compete in the console and mobile divisions for the tournament’s highest honours and be crowned champions.

For the console division, it will be held in a 2v2 format with players participating in teams of three whereas the mobile division will be a 1v1 format. Both divisions will feature players from 12 different countries where they compete through a group stage and knockout stage before battling it out in the finals.

To celebrate the start of the tournament, users can participate in an eFootball campaign and can obtain free special items. Logging in during the campaign period rewards users with different items.

Additionally, users also receive one player item each day from a curated special player list. Users can also take on a Squad Challenge Event where clearing challenges with specific rules will reward them with various items. The campaign period is from December 4th – December 18th.

Coinciding with this campaign, a new game update has been implemented to adjust game balance and adds various features and gameplay elements to enhance the experience. A new particular feature analyses in-game player tendencies and adds an “Advice” feature where players and coaches provide feedback in real-time that could serve as a catalyst for improvements in tactics.

Another feature is the “Analysis” which aggregates and analyses the results of each user’s last 10 PvP matches and visualises their playstyle via comparison graphs and data against opposition from Division 1 – Division 4 users.

Also being introduced to this update is Ronald Koeman receiving the “Link-up Play” feature. Ronald Koeman possesses the “Aggressive Centring A” Link-Up where the “Centrepiece” is in possession of the ball, the “Key Man” will actively make runs towards goal from crosses. Activating this Link-Up increases the accuracy for high and low crosses as well as direct shots from those passes from the “Centrepiece” to the “Key Man”. Legendary player items such as “Epic: David Beckham” and “Epic: Jan Koller” meet the activation conditions and are now available in-game from December 4th – December 11th.

Other features and improvements include:

  • “Auto Control” which allows the AI to take control when the user is not actively playing. • Adjustments in speed and acceleration for defenders by reducing the extreme disparities against speedy players.
  • Acceleration during latter periods of a match with decreased stamina has also been fine tuned to allow players with decreased stamina to maintain their reaction speed even with a reduced stamina.
  • Alterations to the “Defensive Awareness” parameter where defenders with high “Defensive Awareness” can now keep up with opponents more effectively even if their acceleration stat is lower.

Access the viewing page from ‘eFootball’ and watch the broadcasts for the Console Division and Mobile Division to earn up to 2,500eFootball points.

Day 1-3

  • Console / Mobile
  • Viewing Reward: 500 eFootball Points

Day 4 Final

  • Console:
  • Viewing Reward: 1,000 eFootball Points
  • Mobile:
  • Viewing Reward: 1,000 eFootball Points

 

The post The eSports World Tournament FIFAe World Cup 2025™ Kicks-Off in Riyadh, Saudi Arabia on December 10! appeared first on European Gaming Industry News.

Continue Reading

Latest News

S8UL launches India’s first-ever FGC Talent Hunt Program to discover the next stars in Tekken 8 and Street Fighter 6

Published

on

Reading Time: 2 minutes

A total of six players will be selected for the six-month program, running from January to June 2026, following the finals of the talent hunt

Selected athletes will receive professional coaching, fully funded participation in Tier-1 international tournaments, complete travel support, a monthly stipend, and integration into S8UL’s content ecosystem

Mumbai, December 4, 2025: S8UL, a global powerhouse in esports and gaming content, has announced a landmark initiative for India’s fighting game community (FGC) with the launch of a first-of-its-kind Talent Hunt Program for Tekken 8 and Street Fighter 6. Running from January to June 2026, the six-month program aims to identify and develop India’s next breakthrough fighting-game athletes through a structured, high-performance ecosystem and position the country prominently on the global FGC map.

Unlike traditional talent hunts, S8UL’s initiative is designed as a development pipeline, focusing on long-term athlete growth rather than one-off competition. From a wide pool of participants across the nation, a total of six players, including two for Tekken 8 and four for Street Fighter 6, will be scouted and selected solely based on their performance in the nationwide qualifiers and finals.

Selected players will receive one of the most comprehensive support structures ever provided in India’s competitive FGC space, including:

  • A dedicated professional coach for each game throughout the six-month program
  • Fully-funded participation in a minimum of three international Tier-1 tournaments
  • Comprehensive travel support covering flights, accommodation, meals, local transport, and tournament registration
  • A monthly stipend to ensure athletes can focus entirely on training and performance
  • Integration into S8UL’s industry-leading content ecosystem, offering visibility, narrative-building, and community reach to both the players and the fighting game titles

Speaking about the program, Animesh Agarwal, Co-founder and CEO, S8UL Esports, said, “India’s fighting game community has shown tremendous potential but players have rarely had access to a structured environment that supports long-term growth. Through this Talent Hunt Program, we want to change that by giving selected athletes professional coaching, international tournament experience, and the day-to-day support they need to improve. This is not just a short-term project for us—it’s the beginning of a sustained effort to help build a strong foundation for fighting games in India and give our players a fair chance to compete on the world stage”

S8UL today stands as the only Indian esports organization competing across nine leading titles, and it has begun establishing a strong foothold in fighting games as well. After becoming the first Indian team selected for the Esports World Cup’s Club Partner Program, S8UL competed in qualifiers for titles such as Fatal Fury and Tekken 8, underscoring its long-term commitment to the FGC ecosystem.

S8UL’s state-of-the-art gaming house is one of India’s most advanced training and content facilities built to global esports standards. The setup includes structured training schedules, dedicated practice zones, content studios, analytics support, and a high-performance environment that drives discipline and growth. For the FGC Talent Hunt athletes, this access will be transformative. They will train like professional competitors while also learning to build their personal brands through content, storytelling, and community engagement, preparing them to become both top-tier players and future esports personalities.

With fighting games gaining momentum worldwide through major events such as EVO, the Esports World Cup, and the Asian Games, S8UL’s initiative arrives at a crucial moment for the Indian esports ecosystem. The Talent Hunt Program is poised to play an important role in positioning India as a rising force in the global FGC landscape.

Players interested in participating can register here – start.gg/tournament/s8ul-gauntlet/details?utm_source=ig&utm_medium=social&utm_content=link_in_bio&fbclid=PAdGRleAOeRm5leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAacpQXYhiJrLqlKmzwd17yHb8kmDHaXK8HAYTh5ltYtSyZqF5OSnaP6oHxgrtw_aem_ps-_uz-8aMSR5Nqa3IgPjA

The post S8UL launches India’s first-ever FGC Talent Hunt Program to discover the next stars in Tekken 8 and Street Fighter 6 appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.