Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Latest News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerabilityReading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source


Source: Latest News on European Gaming Media Network
This is a Syndicated News piece. Photo credits or photo sources can be found on the source article: MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

George Miller (Gyorgy Molnar) started his career in content marketing and has started working as an Editor/Content Manager for our company in 2016. George has acquired many experiences when it comes to interviews and newsworthy content becoming Head of Content in 2017. He is responsible for the news being shared on multiple websites that are part of the European Gaming Media Network.

Latest News

Stats Widgets Introducing H2H Widget for Land-Based Terminals

Published

on

Reading Time: < 1 minute

FeedConstruct’s Stats Widgets is excited to introduce its new type of H2H widget for Land-Based terminals, designed to enhance user interaction and interface. This widget simplifies the presentation of head-to-head (H2H) data, providing deep insights into team performances with its non-clickable and screen-optimized design.

The H2H widget showcases detailed analysis across various metrics, including team performances, H2H comparison data, and recent match results. Here is the data you can find in this widget:

· H2H Comparison Data: Detailed comparisons between two teams, including historical matchups and relevant statistics.

· Team Performances: Highlighting the recent form and efficiency of both teams.

· Last 5 Matches: Reviewing the outcomes of the last five matches of the teams.

· Current Standings: Quick reference to the teams’ positions in the current league.

The widget is a ready-to-go solution, with easy iFrame integration into the sportsbook, and individual branding to reflect a personalized touch. The introduction of the new type of H2H widget makes a big step forward in simplifying the sports data presentation for the Land-Based terminals, thus enhancing the user experience and supporting our partners.

The post Stats Widgets Introducing H2H Widget for Land-Based Terminals appeared first on European Gaming Industry News.

Continue Reading

Latest News

Slotsjudge Expands Its Presence on Discord and Kick

Published

on

Reading Time: 2 minutes

It has been announced that Slotsjudge has expanded its presence by launching on new digital platforms, including Kick and Discord. The expansion will allow the team behind the brand to reach a wider audience for valuable reviews and insights. By introducing Kick video live streaming and a social Discord server, Slotsjudge aims to foster its vibrant community and provide even more interactive ways for users to discuss and engage with their insights, reviews and recommendations.

Details of the Expansion

Slotsjudge on Kick
The video live-streaming service from Kick offers a myriad of streaming topics and interactive features. It allows users to engage with Slotsjudge streamers in real-time through chat discussions and polls. By bolstering its digital platform expansion with Kick, Slotsjudge can create a dynamic and immersive streaming experience with community engagement and interaction at the forefront.

Slotsjudge’s Discord Server
Discord is a versatile communication platform that provides users with seamless cross-device syncing. By joining the Slotsjudge Discord community, users can benefit from in-built game streaming capabilities, and a wide range of chat and voice features for collaboration and community engagement within the iGaming industry. Additionally, the Discord community from Slotsjudge provides a streamlined platform for content sharing and community support, while maintaining a focus on creating a welcoming environment without promoting iGaming activities.

Impact and Expectations

For the iGaming Entertainment Community
With its new digital platform expansion, Slotsjudge brings a host of mutual benefits to the community. These include enhanced access to information and increased opportunities for engagement. Ultimately, it broadens the platform and reaches for shared experiences, strengthening the bond between players and creating a thriving iGaming community.

Future Directions
Leveraging the community foundations already established, Slotsjudge’s Kick and Discord channels are poised to build upon previous successes and bring even more engagement and enjoyment to users. They will foster a thriving community that continuously evolves and adapts to meet the needs and interests of its members.

Closing Remarks
With the expansion onto Kick and Discord, Slotsjudge aims to bring more fun and interaction to the experience. It is consistently creating spaces where like-minded users can easily connect, engage, and interact with one another, fostering a vibrant and dynamic community.

Pauls Spakovskis, live streamer and game expert at Slotsjudge commented:

“This is amazing news as Discord is the number one community hub to have and where I and Krista can interact with everyone interested in and about Slotsjudge. And streaming on Kick was just a question of time – fast growing streamer-friendly platform where we can build an even bigger community!”

The post Slotsjudge Expands Its Presence on Discord and Kick appeared first on European Gaming Industry News.

Continue Reading

Latest News

Play with the Ugliest, Quirkiest Pets Around in Stakelogic’s Fugly Pets

Published

on

Reading Time: 2 minutes

Get your eyes ready because it’s time to take a trip to the pet centre to meet the ugliest, quirkiest, wildest-looking pets you’ve ever seen in the brand new slot, Fugly Pets, from Stakelogic.

Fugly Pets takes players to a banged-up old pet store to explore its collection of weird and charming, downright ugly pets. Meet a scruffy parrot, a catnip crazed kitty, and an unfortunate-looking little dog.

The slot uses a 5×5 grid with 3,125 ways to win on each spin and is packed with a plethora of unique and exciting bonus features.

Landing Bonus symbols trigger up to 15 Free Spins! Keep your eyes peeled for symbol multipliers of up to 64x landing on any spin. What’s more, these become persistent during the Free Spins, only adding to the game’s huge winning potential.

Roadkill might spell bad news for these fugly-looking creatures, but it is a great thing for players! The Roadkill symbol lands on reel five and will remain inactive until no cascades are possible. The Roadkill symbol then moves across the reels, destroying everything its path or turning it into Wilds.

Fugly Pets is a Stakelogic slot, so there is always something a little extra. If you thought those animals were ugly in regular size, wait until they land in super-size! Super Symbols can land in 2×2, 3×3, or 4×4, allowing players to win big!

Speaking of big wins, players can grab wins of up to 5,000x their stake in this slot, with RTP models up to 96% available.

Daniela Fricchione, Head of Account Management at Stakelogic, said: One thing we love to do at Stakelogic is to play with player expectations. When you think of a pet-themed slot, you imagine something cute and cuddly. Well, we’ve taken that rulebook and fed it to the dogs, putting a fresh spin on the genre with Fugly Pets.

It’s not just the theme that is unconventional, either. The game is jam-packed with special features, with the Roadkill bonus and Super Symbols really helping the slot stand out from the pack.

The post Play with the Ugliest, Quirkiest Pets Around in Stakelogic’s Fugly Pets appeared first on European Gaming Industry News.

Continue Reading

Trending

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.