Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

POLYTOPIA WORLD CHAMPIONSHIP 2025 BREAKS RECORD PARTICIPATION AS FINALS DRAW CLOSER

Published

on

Reading Time: 2 minutes

Celebrated strategy game The Battle of Polytopia confirms its first ever World Championships has exceeded expectations with over 10,000 sign-ups in its qualifying rounds. While no stranger to tournaments, previously hosting smaller scale, local tournaments called ‘Polysseums’, developer Midjiwan’s first step into global esports has been met with extreme success. The inclusive esports event has a $10,000 prize pool and will conclude on 6 December 2025, 14:00-21:00.

The finals will take place in front of a live-studio audience, with expert commentary and a chance to peek behind the scenes at Midjiwan itself. First place will receive $4,000, the runner-up will take away $2,000, the third and fourth place finishers will get $1,500, and the fifth and sixth place $500.

The Polytopia World Championship 2025 is being hosted by eSports platform, Challengermode, who Midjiwan has relied on for its monthly local tournaments since 2022. Midjiwan also partnered with Black Molly Entertainment to help organise and manage the event. Black Molly Entertainment have years of experience managing eSports tournaments, with notable events including the Geoguesser World Cup and CS:GO Pinnacle Cup Championship.

Midjiwan has worked closely with its community to ensure engagement is high with each round, building a bespoke ‘Spectator Mode’ into the game so fans can watch each game live through the game itself. In the spectator mode the viewer has visibility of all players simultaneously, with stats on how many cities, technologies, kills and more available for quick access.

Christian Lovstedt, CEO of Midjiwan commented:
“Polytopia has always been about welcoming all kinds of players into the world of 4X strategy. That’s why our championship is open to everyone – not just pros with sponsors. We’ve been thrilled at the amount of interest this tournament received from our community, reaching participation numbers way beyond our expectations. We’re excited to bring the finalists to Stockholm and can’t wait to see the strategies that emerge.”

The Polytopia World Championship 2025 kicked off in September, with its ‘Battle of the Tribes’ qualifying round – weekly battles where players competed to be the best in each of the game’s 12 tribes. After an exciting six weeks, the top player from each tribe faced-off, reducing the qualifiers to six finalists. These six winners are listed down below.

Tribe

Qualifying Player

IMPERIUS

ArthurL248

BARDUR

slimmingboy

OUMAJI

Dreamlander3000

HOODRICK

Theetat

XIN-Xi

LeLiberateur

LUXIDOOR

Meisterlampe

 

Recaps of each round of the tournament prior to the finals can be watched on the official Battle of Polytopia YouTube channel.

 

  • Part 1: Polytopia World Championship 1st Qualifiers Wrap-Up – BARDUR, IMPERIUS, KICKOO, ZEBASI

  • Part 2: Qualifiers Wrap-Up – Oumaji Hoodrick Yadakk & Quetzali – World Champoinship 2025

  • Part 3: Final Qualifiers Wrap-Up – Xin-Xi, Luxidoor, Ai-Mo & Vengir – World Championship 2025

  • Face-off stream: https://youtube.com/live/GnU6mWPoJiY?feature=share

To watch the finals live on December 6,visit here: https://polytopia.io/stream/

To stay up to date on the Polytopia World Championship 2025, or purchase one of the limited tickets for the live event, visit the official website or join the Official Polytopia Discord.

The post POLYTOPIA WORLD CHAMPIONSHIP 2025 BREAKS RECORD PARTICIPATION AS FINALS DRAW CLOSER appeared first on European Gaming Industry News.

Continue Reading

Latest News

Second Prize Drop of N1 Puzzle Promo: Top Affiliates Score Porsche, Cartier, Leica & Apple for Driving High-Quality Traffic

Published

on

N1 Partners is wrapping up the second lottery of the N1 Puzzle Promo! From September 1 to November 30, partners were actively collecting puzzle pieces for FTDs and climbing the rankings to secure their place among the winners.

A notable trend this season: the Top-5 leaders by traffic and collected puzzles differ from the main leaderboard. This means some partners slowed down, while others pushed harder — and now have every chance to boost their position in the overall standings by the end of the promo.

Five luxury prizes will be awarded to partners with consistently strong performance who entered the Top-5 by puzzle count during the second mini-lottery period.

Which prizes did the leaders receive?

1st place — MacBook Pro

C*** *****h

2nd place — Porsche eBike Sport

A***********t

3rd place — Cartier Santos Medium watch

T****** ****d

4th place — Leica Q2 camera

P******k

5th place — Apple Vision Pro

S** ****s

The promo is entering its final stretch — a crucial checkpoint for the entire N1 Puzzle Promo, where the fate of the leaderboard may be decided,” notes Alexa Bond, Head of Affiliates at N1 Partners. “With one month left until the end, even those who joined later still have a chance to make a breakthrough, while the leaders can strengthen their positions and widen the gap. N1 Puzzle Promo isn’t about luck — it’s about consistent work and mutual trust between partners and the affiliate program.”

The Grand Finale in Barcelona Is Getting Closer

The race continues: the more puzzle pieces collected throughout the promo, the higher the ranking — and the greater the chance to fly out of Barcelona in your very own helicopter!

On January 20, 2026, in Barcelona, during iGB Affiliate and ICE, N1 Partners will host the final N1 Puzzle Promo party, where winners will receive exclusive gifts — and the grand prize: a Robinson R22 Beta II helicopter.

Guests of the event can also expect:

  • Exclusive prize ceremony;
  • Live performance by top artists and the evening’s headliner (announcement coming soon)!
  • Activities and surprises from the N1 Partners team;

Still Not Too Late to Join

N1 Puzzle Promo runs until December 31, 2025, and partners still have time to collect puzzle pieces, climb the leaderboard, and compete for the grand prize and additional rewards. Traffic from Tier-1 GEOs counts toward the ranking, and only registered N1 Partners partners can participate.

All details and registration are available at: https://n1.partners/puzzle_promo

There’s still time! Collect your puzzle pieces, level up in the leaderboard — and your team might be the one taking home the Robinson R22 Beta II right off the stage in Barcelona!

Continue Reading

Latest News

bet365 PARTNERS WITH INSPIRED ENTERTAINMENT TO LAUNCH A BESPOKE GAME: SPIN O’REELY GRAND CHANCE

Published

on

Reading Time: < 1 minute

Inspired Entertainment, Inc., a leading B2B provider of gaming content, systems, and solutions, is thrilled to announce the exclusive launch of its brand-new, bespoke slot game, Spin O’Reely Grand Chance, in collaboration with long time partners bet365.

Expanding bet365’s popular exclusive Irish-themed Spin O’Reely game series, the game will initially be available to players in the UK, Ontario, and New Jersey, with more markets to follow soon. The game can also be accessed via the bet365.com domain.

Spin O’Reely Grand Chance builds on Inspired’s successful Golden Winner slot, combining its fan-favourite mechanics with new features. This 5×3 slot includes a Free Spins bonus round with multipliers and the potential for additional Free Spins. Players will also discover dynamic reel upgrades, bell announcements, prize pots, a progressive bonus feature and the Golden Grand Chance Cherry feature.

Claire Osborne, VP of Interactive at Inspired Entertainment, said: “We’re thrilled to expand our long-standing partnership with bet365 through the launch of Spin O’Reely Grand Chance. By combining the proven mechanics of one of our top-performing titles with the lively charm of a bet365 Irish-themed classic, we’ve created a game that’s built for success. We can’t wait to see players enjoy it and look forward to building on this momentum together.”

A bet365 spokesperson said: “We are delighted to launch Spin O’Reely Grand Chance in collaboration with Inspired. This game combines enjoyable mechanics with innovative features that will provide our players entertaining gaming experience. We are confident that Spin O’Reely Grand Chance will be a popular addition to our portfolio of cutting-edge content.”

Experience the exciting new collaboration between bet365 and Inspired Entertainment with Spin O’Reely Grand Chance, available now exclusively at bet365.

The post bet365 PARTNERS WITH INSPIRED ENTERTAINMENT TO LAUNCH A BESPOKE GAME: SPIN O’REELY GRAND CHANCE appeared first on European Gaming Industry News.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.