Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Powered by WPeMatico
Industry News
Wazdan schedules three-stage Network Promotion campaign for summer
The operator-facing series runs 29 June to 13 September and uses Mystery Drop and Mystery Multiplier Drop mechanics.
Wazdan will launch a summer-long Network Promotion series for partner casinos, running from 29th June to 13th September. The campaign is structured in three stages with breaks between each phase.
The promotion will use Wazdan’s Mystery Drop
and Mystery Multiplier
Drop mechanics. The supplier said the programme is designed to be easy for operators to activate and will be supported with marketing materials, including promotional assets, brochures and newsletter content for partners to use across their own channels.
Alongside the promotion, Wazdan has a summer content roadmap with three slot releases scheduled: Mighty Hot
: Amazonia (30th June), Magic Fruit$: Cherries (30th July) and Mighty Crown
: Empire of Gold (6th August).
Radka Bacheva, Head of Sales and Business Development at Wazdan, said: “Summer presents a valuable opportunity for operators to keep engagement levels high, and this promotion has been designed to deliver exactly that through Wazdan’s proven promotional tools.
“Combined with our upcoming game releases, we are excited to offer partners a strong seasonal campaign with plenty of player appeal.”
The post Wazdan schedules three-stage Network Promotion campaign for summer appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
Casino Content
ICONIC21 launches Football Cup-branded casino games and debut network tournament
ICONIC21 has rolled out three limited-edition Football Cup-branded casino games and launched its first network tournament, ICONIC Showdown Football Cup, running from 9th of July to 19th of July.
The new titles are Football Cup Roulette, Football Cup Blackjack 360, and Football Cup Gravity Blackjack. ICONIC21 said the releases showcase different customisation approaches, including green screen production for the roulette environment and an updated visual rebrand for its RNG blackjack table.
For Football Cup Gravity Blackjack, ICONIC21 said it used its latest LED technology and applied the Gravity Series multiplier mechanic, with a custom felt, a football gate, and bespoke 3D-printed decorations.
Alongside the three new games, ICONIC21 pointed to its previously launched slot Soccer World Championship, plus The Kickoff and Top Card, which it said received football-season branding and UI/UX updates.
The ICONIC Showdown Football Cup tournament covers 11 games in total and is positioned around the quarter finals, semi-finals and final period. ICONIC21 said 1,000 winners will share a €50,000 prize pool, and operators can enroll via their account manager or by contacting the company directly.
Edvardas Sadovskis, Chief Product Officer at ICONIC21, said:
“What I’m most proud of with this project is the turnaround. We built three fully branded, technically distinct games, enhanced existing ones with promotional branding, and launched our first-ever network tournament around them, all timed to coincide with peak player interest and traffic.
That kind of speed doesn’t happen by accident, it reflects how this team works. ICONIC Showdown is a meaningful first step for us as a provider, and launching it during the Football Cup, with this much energy around the game, feels like the right way to do it. We’re genuinely excited to see how the leaderboard shapes up and even more excited for the finals.”
The post ICONIC21 launches Football Cup-branded casino games and debut network tournament appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
Brand Ambassador
Ronaldinho visits CreedRoomz Yerevan studio to front Marble Cup and Kickoff Roulette
CreedRoomz has brought footballer Ronaldinho to its headquarters in Yerevan, where the company filmed an “exclusive interview” with the former player in connection with two new live casino game shows, Marble Cup and Kickoff Roulette. CreedRoomz said Ronaldinho is the global ambassador for both titles.
In the interview, Ronaldinho said: “For me, it’s a great joy to be a part of this partnership. Since arriving here at the office, everyone has treated me with great affection. I already feel at home, very happy.” Asked to choose between the two games, he added: “Honestly, it’s difficult to choose one, both are wonderful, I loved them, so it’s very difficult to choose one, I think everyone will really like them, I think the whole world will really enjoy them.”
Ronaldinho also described his first impressions of the studio and gameplay: “I was surprised and very happy, everything is very beautiful, everything is very innovative, so I believe that’s why everyone will really like them, so I’m looking forward to everyone starting to enjoy them a lot.”
On why CreedRoomz expects the titles to gain traction, he said: “These are different games. I think that will attract attention, the fact that football is a global passion also helps, so I believe everyone will like it for those reasons.. and for the innovation of everything that is happening.”
CreedRoomz linked the interview to upcoming “World Cup and R10 Tournaments,” with Ronaldinho closing by telling fans: “A message of gratitude for the continued affection. I’m very happy and excited. for the next competitions for the next games, the games are all ready, I hope everyone enjoys them and everyone be very happy and have good times together.”
The post Ronaldinho visits CreedRoomz Yerevan studio to front Marble Cup and Kickoff Roulette appeared first on EE Gaming | Global iGaming & Tech Intelligence Hub.
-
Bragg Gaming Group4 days agoMassive Gaming launches Blitzcrown titles on Superbet Brazil via Bragg Hub
-
Compliance4 days agoHIPTHER Launches HALLO: The Standard in Compliance Expertise
-
Compliance Updates4 days agoHIPTHER Launches HALLO: The Standard in Compliance Expertise
-
Alex Cuoci4 days agoWealthsimple and Kalshi Partner to Bring Prediction Markets to Canada
-
7Games4 days ago7Games, Betão & R7 Launch FIRST.bet Sportsbook in Brazil
-
30-0 Kongeserien3 days agoKongebonus launches 30-0 Kongeserien Eliteserien fantasy draft game
-
Channelisation4 days agoSwedish Gambling Authority consults tighter duty of care rules as channelisation slips
-
Bonusetu.com3 days agoFinland Sets Casino Gambling Risk Limits at 2% of Income, 4 Days, 2 Game Types



