Connect with us

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Powered by WPeMatico

Continue Reading
Advertisement

Carsten Koerl Founder and CEO of Sportradar

Sportradar Introduces Playradar, Delivering Sports-Data-Backed Casino Content to Operators Around the Globe

Published

on

sportradar-introduces-playradar,-delivering-sports-data-backed-casino-content-to-operators-around-the-globe

New brand to link sportsbook and casino experiences via exclusive hybrid content.

Sportradar Group AG, a prominent worldwide sports technology firm that develops engaging experiences for sports enthusiasts and bettors, today unveiled Playradar, a specialized brand providing a comprehensive ecosystem of interconnected gaming experiences for international operators. This signifies the subsequent phase in the development of Sportradar’s iGaming operations.

Sportradar has recently appointed Edo Haitin, the former CEO of Playtech Live, to head its iGaming division as part of this expansion. Haitin offers over 20 years of experience in iGaming operations, live casino development, and executive leadership, contributing senior-level knowledge to enhance Sportradar’s iGaming expansion.

Playradar will leverage Sportradar’s live and historical sports data and AV streams, combined with casino games, to create unique, proprietary, hybrid products featuring:

  • Live 24/7 Experience Centre – players will be offered a game and a live stream to watch simultaneously on the same screen, blending sports viewing and gaming for pure engagement or betting real money. This creates a community and opportunities for players to interact in real-time, sharing tips, game preferences and reactions.
  • Live & Historical Streaming Sports/Casino Hybrid Content – transforming real sporting moments into interactive event driven gameplay by blending live and historical sports streaming with casino mechanics to create innovative hybrid gaming experiences. A live prediction product will also be powered by Sportradar’s live data.
  • Premium iGaming Content – virtual sports and a full suite of casino games, from slots and table games to arcade and crash, developed to the highest standards for a positive player experience.

Sportradar is exceptionally poised to expand its iGaming operations by leveraging its current game studio, sports data knowledge, streaming abilities, and worldwide distribution network. The marketing, acquisition, and retention technologies of the company utilize profound understanding of player behavior across both betting and iGaming sectors, strengthening Sportradar’s connections with sportsbook and casino operators globally. Since most of Sportradar’s clients already function in both areas, iGaming serves as an organic pathway to foster sustained monetization and lifetime value in conjunction with betting.

Playradar will function solely in regulated markets, incorporating responsible gaming and integrity into each product it offers. Game launches are planned for 2026, starting in the UK, North America, and Latin America. The complete product lineup will include classic table games, arcade games, slots, and virtual sports.

Carsten Koerl, Founder and CEO of Sportradar, said: “iGaming represents a natural and scalable extension of our business, and a strategic acceleration of our long-term growth roadmap. Playradar content is designed to provide optimized cross-sell between the worlds of sport and casinos, helping operators to increase player value and session length at a time when engagement and retention are key to operational sustainability. In Edo, we have an experienced and proven industry leader to drive the business forward, with the support of a passionate and dedicated team.”

Edo Haitin, EVP of iGaming added: “By combining our unrivalled experience in sports data and live streaming, along with a proven track record of product development, we aim to create hybrid content and gaming experiences to capitalize on the rising popularity of sports casino consumption. We’re uniquely positioned to seamlessly blend live and historical sports events, innovative gaming mechanics, and casino content and have the advantage of being able to distribute games to an already licensed portfolio of operators. I’m incredibly excited to be further strengthening our iGaming business through Playradar and to grow it into a leader in iGaming content, leveraging Sportradar’s existing resources and the highly experienced and skilled team already in place.”

The post Sportradar Introduces Playradar, Delivering Sports-Data-Backed Casino Content to Operators Around the Globe appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.

Continue Reading

AI

Table Trac Introduces Patent-Pending Artificial Intelligence Technology for Table Games

Published

on

table-trac-introduces-patent-pending-artificial-intelligence-technology-for-table-games

Table Trac Inc. (TBTC) has received patent-pending status from the U.S. Patent and Trademark Office for its proprietary AI-driven Table Games Manager / Manager Trainer. The system leverages machine learning trained on decades of table games transactional data and pit player data to create distinct player personas designed to challenge both human pit managers and artificial intelligence systems.

The solution is delivered through a realistic gaming floor simulation environment, allowing the generation of a simulated gaming floor to be configured. Each training session utilizes a randomized mix of the player personas, creating a continually changing set of scenarios that never repeat. This approach enables trainees to compete head-to-head against the AI, optimize floor decisions to improve yield, and better understand the factors driving each decision.

While initially developed for table games management and training, the underlying artificial intelligence, simulation, and decision support framework has broader applicability across the CasinoTrac platform. Management is exploring additional use cases for this technology across the Company’s suite of casino management solutions, reinforcing CasinoTrac’s long-term product roadmap and innovation strategy.

The post Table Trac Introduces Patent-Pending Artificial Intelligence Technology for Table Games appeared first on Americas iGaming & Sports Betting News.

Continue Reading

GR8 Tech

GR8 Tech Unveils Major Platform Enhancements Ahead of the World Cup

Published

on

gr8-tech-unveils-major-platform-enhancements-ahead-of-the-world-cup

GR8 Tech is implementing a series of platform-wide enhancements designed to help operators maximize performance during the year’s biggest sporting event. With the World Cup expected to drive massive traffic, repeated betting surges, and intense competition for player acquisition, these updates focus on the areas that most directly impact operator results. The improvements aim to help partners convert more traffic, retain more players, and extract greater value throughout the entire tournament journey.

“World Cup traffic by itself does not guarantee better results. What matters is how well operators can turn that attention into acquisition, conversion, retention, and long-term player value,” said Denys Parkhomenko, Chief Product Officer at GR8 Tech. “That is where our focus is right now. We are enhancing the sportsbook experience, expanding engagement and loyalty tools, and advancing our crypto capabilities to help partners make the most of the biggest opportunity of the year.”

Key Areas of Focus

1. Sportsbook
The sportsbook is receiving a comprehensive upgrade, including redesigned navigation for easier event discovery, improved campaign visibility, and enhanced Bet Builder functionality. Additional updates include quick-access, player-specific markets and new Odds Boost features, balancing player appeal with margin control.

2. Engagement and Retention
GR8 Tech is expanding its loyalty and bonus systems with a VIP-focused program, automated bonus mechanics, more flexible bonus selection, and enriched casino and sports-related engagement tools. The update also includes updated tournament settings and the introduction of new game content to enhance player retention.

3. Crypto
The company is strengthening its crypto offering with early-stage player segmentation based on wallet transaction history, more flexible VIP and risk management before first deposit, and smoother wallet-based payments, including ramp payments and direct top-ups via WalletConnect and other wallets.

Across the platform, these updates are designed to help operators capitalize on the World Cup’s peak traffic, delivering measurable improvements at every stage of the player journey. Detailed release notes will follow, highlighting specific product enhancements and the developments shaping GR8 Tech’s World Cup-ready platform.

GR8 Tech – Platform for Champions

GR8 Tech is an award-winning provider of high-performance sportsbook and iGaming solutions that empower operators to lead and win in competitive markets. Its portfolio includes Crypto Turnkey and Hyper Turnkey solutions, ULTIM8 Sportsbook, Infinite Casino Aggregation, and the proprietary affiliate management platform Aff.Tech.

With a geo-specific, operator-first approach, GR8 Tech delivers practical innovations that drive measurable results quickly and efficiently. Trusted by top operators worldwide, the company has over 100 successful deployments and multiple industry recognitions, including Platform Provider of the Year at the SBC Awards 2025.

The post GR8 Tech Unveils Major Platform Enhancements Ahead of the World Cup appeared first on Eastern European Gaming | Global iGaming & Tech Intelligence Hub.

Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania