Connect with us

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Powered by WPeMatico

Continue Reading
Advertisement

Gambling in the USA

Gaming Americas Weekly Roundup – July 21-27

Published

on

gaming-americas-weekly-roundup-–-july-21-27
Reading Time: 2 minutes

Welcome to our weekly roundup of American gambling news again! Here, we are going through the weekly highlights of the American gambling industry which include the latest news and new partnerships. Read on and get updated.

Latest News

ALT Sports Data, the global leader in engagement solutions and official data for emerging sports, has appointed Neale Deeley as SVP of Sportsbook. Deeley brings over two decades of industry experience and a proven track record of driving innovation and commercial growth in sports wagering. In his new role, Deeley will lead the company’s global sports betting strategy, spearheading market expansion, deepening operator partnerships and accelerating the monetization of emerging sports through regulated betting markets. He will work closely with sportsbooks and gaming partners to build scalable betting products that delivers unique fan engagement opportunities and new revenue streams across ASD’s portfolio of exclusive sports properties.

SEGG Media Corporation, a leading technology company transforming the global intersection of sports, entertainment and gaming, has selected IBN, a multifaceted financial news and publishing company serving private and public entities, to spearhead its corporate communications efforts. SEGG Media aims to deliver immersive, real-time experiences through next-generation technology that redefines how audiences interact with their favorite content and communities. Following a full-scale corporate transformation and rebrand, the company now operates across three high-growth verticals: Sports.com, Entertainment and Lottery.com.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Partnerships

Amusnet Brasil has announced the official go live of its partnership with Cactus Gaming, a B2B platform serving some of the leading operators in the Brazilian market. With this integration, the game provider adds 25 new operators to its distribution network, further expanding its reach through a structure aligned with the regulated market. With operations now underway, Cactus clients gain access to a robust portfolio and features that enhance the end-user experience. Among the featured games now live are the fun and dynamic Coin Gobbler, the immersive Cavemen and Dinosaurs, and titles that have proven their success in multiple markets, such as Rise of Ra, Cocktail Dice and 7 & Crystals.

TaDa Gaming has signed a new partnership with EveryMatrix for further exposure in the North American iGaming market through its B2B aggregator platform SlotMatrix. Powered by EveryMatrix, SlotMatrix offers effortless integration of premium content across global platforms for boosted revenue and game offering. Following its parent company’s 2022 signing with BetMGM, the leading iGaming operator in the US, SlotMatrix has built a solid reputation with BetMGM players who will now be able to access TaDa content, beginning with latest Triluck release, 3 Coins Treasure, across the states of Michigan and Pennsylvania.

Mission Media AI, a next-generation cross-platform distribution and monetization company, has announced a strategic partnership with VsiN. The partnership strengthens Mission Media’s growing footprint in the sports space and unlocks new revenue opportunities for VsiN across their multitude of consumer touch points, including 8 regional sports networks, YouTube TV, SiriusXM channel 158, more than 20 weekly podcasts, streaming audio station, website and an app available for mobile and connected devices like iOS, Roku, Fire TV, Samsung, Google Play and LG. VsiN delivers real-time, actionable sports betting content from some of the most respected and trusted voices in the industry. Mission Media AI will scale VsiN’s monetization strategy, enabling premium access for advertisers looking to reach an engaged, data-driven audience.

The post Gaming Americas Weekly Roundup – July 21-27 appeared first on European Gaming Industry News.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Accor

Accor Arrives on The Strip with Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection

Published

on

accor-arrives-on-the-strip-with-treasure-island-–-ti-las-vegas-hotel-&-casino,-handwritten-collection

 

Accor, in partnership with businessman and casino owner Phil Ruffin, announced the signing of Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection. The salient 2884 key property overlooks the city’s premier racing circuit and features some of the best panoramic views of Las Vegas. To be operated under a franchise agreement with Accor when it officially debuts later this year, Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection joins a global portfolio of carefully curated hotels and becomes the second Handwritten Collection address in the US, following Hotel Stratford San Francisco – Handwritten Collection last year. The signing further increases Accor’s presence in the Americas region, with more than 550 hotels open and operating, and reflects the Group’s growing presence across North America.

“The city’s tagline is ‘What happens here, only happens here’, and certainly there is no other place in the world where a collaboration of this scale and significance could come together. The union of Treasure Island and Handwritten Collection creates a one-of-a-kind guest journey, where connections are treasured, wonder is discovered, and every stay is a narrative waiting to unfold. We are incredibly proud to partner with Mr. Ruffin and confident that together we can create a bigger and bolder future for this iconic hotel now that it sits within the Handwritten Collection portfolio and part of the Accor network,” said Camil Yazbeck, Global Chief Development Officer at Accor.

With more than 40 million visitors drawn to Las Vegas each year, Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection is set to offer a truly memorable stay for those seeking genuine hospitality in the heart of the world’s entertainment capital. The franchise partnership between Accor and Treasure Island includes Handwritten Collection brand support, along with Accor’s full global array of services, including sales & marketing, distribution, and loyalty. The hotel will benefit from exposure to the ALL Accor loyalty program – one of the largest and most globally diversified loyalty databases in the world, with 100+ million members and growing.

“Treasure Island has long held a special place in the story of Las Vegas, and I am certain that Accor and Handwritten Collection will further enrich its legacy and attract new generations of guests and visitors. This next chapter brings new energy to the resort while preserving its unmistakable spirit. We are proud to align with Accor – a global leader in hospitality whose values resonate deeply with ours, and we look forward to a successful and long-lasting partnership,” said Phil Ruffin, owner of Treasure Island – TI Las Vegas Hotel & Casino.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

As the newest entrant to Handwritten Collection, Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection joins over 25 hotels now open and more than 35 addresses in the pipeline. Standing as a beacon of individuality in the global hospitality sector, Handwritten Collection properties weave character and personality into the guest experience, making every stay unique.

At Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection, the distinct design and whimsical personality of the hotel, inspired by the classic tale by Robert Louis Stevenson, carries through the guest experience, inviting travelers to rediscover their childhood spirit. Many of the hotel’s best-known features and perks, as conceived by Mr. Ruffin, will continue to be honored, such as free valet and self-parking.

The hotel has also recently been transformed by a multi-million-dollar refresh, blending contemporary comfort with thoughtful design elements, ensuring the energy of Las Vegas shines through in every detail. A breezy, sociable lobby overlooks a tropical pool, where intuitive self-check-in is complemented by a 24-hour guest relations team ready to offer a warm welcome. The resort features 10 diverse dining venues and eight upscale lounges and bars, including beloved options such as Phil’s Steak House, Golden Circle Sports Bar, and the popular Gilley’s Saloon, Dance Hall & Bar-B-Que.

The luxurious Oleksandra Spa & Salon is a favorite among guests and residents, part of the resort’s tapestry of experiences filled with local flair. Lively entertainment venues, elegant wedding chapels, state-of-the-art event spaces, and 90,000 sq. ft. of casino and gaming add to the attractions, while the hotel connects to Fashion Show Las Vegas, the largest mall in the city. The famed Mystère – the original Cirque du Soleil show in Las Vegas – performs at the Treasure Island theatre, having been honored eight times as ‘Best Production Show’ and continues to enchant audiences, underscoring the property’s connection to the city’s enduring sense of wonder.

Guestrooms and suites at Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection offer breathtaking views of the famed Las Vegas Strip, Sphere Las Vegas, and the stunning Spring Mountains that encircle the Nevada horizon. Signature SensaTIonalTM pillowtop beds, generous soaking bathtubs or whirlpools, marble finishes and upscale amenities ensure stays are as restorative as they are inspiring.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Aligning with Accor’s sustainability commitments, the hotel was awarded a Four Green Globes certification by the Green Building Initiative. The certification reflects meaningful improvements in energy and water efficiency, air quality and resource management – further aligning the hotel with conscientious travelers.

“We are thrilled to bring Accor to Las Vegas and to provide our ALL Accor members and guests here in the United States, as well as those visiting from around the globe, with an incredible opportunity to stay at this emblematic property – now the largest Accor hotel in the world. The addition of Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection is a milestone achievement, not only for our Handwritten Collection portfolio, but for Accor’s growing presence of exclusively selected properties in the U.S. market,” said Thomas Dubaere, CEO PM&E, Accor Americas.

The post Accor Arrives on The Strip with Treasure Island – TI Las Vegas Hotel & Casino, Handwritten Collection appeared first on Gaming and Gambling Industry in the Americas.

Continue Reading

Industry News

Rush Street Gaming Taps Scott Lokke to Lead Rivers Casino Philadelphia

Published

on

rush-street-gaming-taps-scott-lokke-to-lead-rivers-casino-philadelphia

 

Rush Street Gaming announced the appointment of Scott Lokke as general manager of Rivers Casino Philadelphia.

A gaming executive with more than 30 years of casino and hotel experience, Lokke joins the Philadelphia team from Cleveland, where he most recently served as senior vice president and general manager of JACK Cleveland Casino. He spent the past decade with JACK Entertainment and the 12 years prior with Caesars Entertainment.

“Having worked in Cleveland, Las Vegas and other major metropolitan areas, Scott is highly qualified to lead the Philly team. His achievements in gaming operations, combined with his hospitality expertise in restaurants and entertainment, uniquely position him to build on Rivers’ success,” said Tim Drehkoff, CEO of Rush Street Gaming.

Lokke’s career in the hospitality industry began at the Ritz-Carlton Hotel Company and Starwood Hotels directing food and beverage operations, followed by roles at Harrah’s casinos in St. Louis and Kansas City. He then advanced to vice president of hospitality enterprise shared services with Caesars Entertainment in Las Vegas before ultimately taking on leadership positions in Cleveland.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

As a senior property leader, Lokke excels in exceptional guest service, operational leadership, community involvement and Team Member engagement.

“I’m thrilled to build on the strong foundation the team already has in place. I’m committed to leading the team in delivering exceptional experiences, results and engagement. It’s truly my honor to be part of this team,” said Lokke.

Lokke is a graduate of Park University in Kansas City, where he earned a bachelor’s degree in business administration. In recent years, he served on the boards of the Downtown Cleveland Improvement Corporation, the Cleveland Group Planning Commission and the Greater Cleveland Sports Commission.

The post Rush Street Gaming Taps Scott Lokke to Lead Rivers Casino Philadelphia appeared first on Gaming and Gambling Industry in the Americas.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania