Connect with us

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub

Published

on

FairPlay’s betting technology and AI-powered predictive content drive deeper fan engagement and deliver media opportunities and revenue

FOX Sports Digital and FairPlay Sports Media, the fan-focused and AI-powered global sports media network, have announced a strategic betting tech, affiliate and sports media agreement.

Under the multi-year agreement, FairPlay will serve as the exclusive sports betting affiliate technology provider of FOX Sports Digital, deploying its market-leading odds components, advanced AI-powered predictive data and analytics, and cutting-edge technology solutions on FOXSports.com and the FOX Sports mobile application.

The new relationship powers the newly released FOX Sports Betting Hub which integrates FairPlay’s innovative sports betting-related content enhanced with bespoke, value-added experiences derived from FairPlay’s deep relationships with global sportsbook operators.

“FOX Sports is one of the largest sports rights holders in the world, with incredible access to live games and global events,” said Stuart Simms, Group CEO of FairPlay Sports Media. “FairPlay is excited to work with the FOX Sports Digital team, and we’re honored to serve their millions of users with more engaging, insightful sports media experiences that have proven to drive loyalty, engagement and deliver on brand differentiation.”

FairPlay’s advanced AI technology and robust odds components are already delivering real-time, data-driven insights to help FOX Sports fans and bettors, while monetization frameworks being deployed create revenue opportunities for operators, sportsbooks and digital media buyers.

The agreement enhances and elevates fan engagement by bringing FairPlay’s betting information technology and AI-powered tools to FOX Sports’ digital platforms. FairPlay’s approach enables FOX Sports digital users and fans to access personalized, data-driven betting analytics that deepen their connection and engagement with sports content. As the sports media and betting landscapes continue to evolve, the FOX Sports and FairPlay agreement delivers pioneering, scalable digital experiences for fans and operators alike.

 

The post FairPlay Sports Media and FOX Sports Digital Launch New Betting Hub appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering

Published

on

Checkd Dev, part of the award-winning Checkd Group and a leading iGaming technology provider, has signed a multi-year agreement to supply its Automated Betting System (ABS) to UK bookmaker Betfred, introducing new levels of efficiency and engagement to pre-match football accumulator betting.

Through the partnership, Betfred has launched a suite of pre-configured, one-click accumulator bets, powered by Checkd Dev’s ABS technology and seamlessly integrated with Betfred’s proprietary pricing.

The solution enhances the customer betting journey while equipping Betfred’s trading team with a robust backend platform to streamline bet creation, management, and settlement. Customers benefit from football bets that are dynamically assigned probabilities based on historic form, providing greater insight and confidence in their selections.

The launch of ABS reinforces Betfred’s reputation as an industry innovator, offering customers smarter, faster, and more engaging betting experiences.

Checkd Dev has refined its ABS user interface through deployments with multiple tier-one operators. Betfred has further strengthened the proposition by integrating its competitive Acca Flex bonus offer, available from launch. Customers can access additional bonuses if their bet wins, while also benefiting from a money-back guarantee if a single leg loses.

Since its introduction two years ago, Checkd Dev’s ABS has evolved from a statistics-driven tool to increase operator conversion rates into a comprehensive system designed to meet the growing demand for automated, pre-configured betting products, powered by the company’s proprietary BRUNO platform.

This agreement extends Checkd Dev’s recent growth trajectory, following high-profile partnerships with William Hill on a fully automated, stats-powered Bet Builder, and a three-year deal with OpenBet to launch a new Trending BetBuilder to market.

Andrew Grimshaw, Commercial Director at Checkd Dev, commented: “We are delighted to be working with fellow Mancunians Betfred on our Trending Bets product. More and more major bookmakers are recognising the tangible value of our automated betting solutions, and it is especially gratifying to collaborate with a local partner on this launch.”

Mark Hartley, Head of Product at Betfred, added: “Since moving onto our propriety platform, we’ve been able to bring new ideas to market much faster. This partnership with Checkd Dev is a great example, helping us solve a simple problem for football fans: researching and building an accumulator can sometimes feel like hard work!

“With one-click, data-driven selections we’ve made the process quicker and easier, while still giving customers the choice and depth they want. Accas are already one of our most compelling propositions, thanks to our popular promotion Acca Flex, and this launch makes them even more engaging. We’re also looking forward to exploring further opportunities to work with Checkd Dev in the future.”

 

The post Betfred Launches Checkd Dev’s Automated Betting System to Strengthen Football Betting Offering appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Latest News

Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features

Published

on

Legendary Title Reborn for a New Generation of Fortune Seekers with Freebies and Bonuses until December 28th

Slotland Entertainment has ceremoniously relaunched its legendary title, Gods of Egypt, across its casinos Slotland, Winaday and now including CryptoSlots and CryptoWins. This revered 5×4, 30-payline slot invites players into a grand temple of mythic wealth.

Wager $1.50 to $30 to awaken divine features: Ra’s Sticky Expanding Wilds, Bastet’s gem-triggered Free Spins, and a Pick Me Bonus with layered treasures. For those betting $15 or more, five Pharaoh symbols unlock the progressive jackpot.

Gods of Egypt has always been a crown jewel in our collection,” said Michael Hilary, Manager at Slotland. “This relaunch across our entire empire allows a new generation of players to experience its timeless magic and seek its legendary rewards.”

Framed by the regal visages of Anubis and a jeweled queen, the game creates a ceremonial atmosphere of arcade spectacle. It is a call to modern seekers: enter and claim your ancient riches.

WINADAY CASINO: Available December 19 – 28, 2025

Up to $111 FREEBIE chip

  • For platinum VIPs, $88 for Gold VIPs, $55 for Silver VIPs, $44 for Bronze VIPs, $20 for ALL
  • Redeem: 1x, wager: 29x, max cashout 5x, depositing players only
  • Bonus Code: FREEBIE2025

Up to 155% NEW GAME BONUS

  • For VIPs, 100% for ALL
  • On deposits on $10 – $250
  • Redeem: 2x per day, wager: 29x, valid: Gods of Egypt
  • Bonus code: NEWSLOT

 

CRYPTOSLOTS: Available December 17 – 25, 2025

123% VIP TREASURE MATCH

  • On deposits $50-500
  • Redeem: 1x per day, wager: 35x, valid: Gods of Egypt
  • Bonus code: VIPNEW

77$ DESERT GOLD MATCH

  • On deposits 200 – $400, 65% on $100 – $199, 50% on $10 – $99
  • Redeem: 2x per day, wager: 35x, valid: Gods of Egypt
  • Bonus code: NEWIN

 

The post Slotland’s Crown Jewel, Gods of Egypt, Resurrects with Enhanced Features appeared first on Gaming and Gambling Industry Newsroom.

Continue Reading

Trending

EEGaming.org is part of HIPTHER, parent brand of various prominent news outlets and international conferences. These platforms and events span a wide range of industries, including Entertainment, Technology, Gaming and Gambling, Blockchain, Artificial Intelligence, Fintech, Quantum Technology, Legal Cannabis, Health and Lifestyle, VR/AR, eSports, and several others. This indicates that EEGaming.org is part of a larger network that focuses on a diverse array of sectors, particularly those related to cutting-edge technology and modern lifestyle trends.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025 HIPTHER. All Rights Reserved. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.