Connect with us
MARE BALTICUM Gaming & TECH Summit 2024

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement

Powered by WPeMatico

Continue Reading
Advertisement

Industry News

Meridian Donate: Revolutionizing CSR in the Betting and Gaming Industry

Published

on

meridian-donate:-revolutionizing-csr-in-the-betting-and-gaming-industry
Reading Time: 2 minutes

 

  • Innovative engagement strategy positions MeridianBet as a leader in CSR within the betting and gaming industry
  • Optimized brand loyalty as active customer participation in CSR strengthens connection and loyalty
  • Scalable impact, as the model is designed for expansion and could be adapted to new markets, indicating potential for widespread adoption and growth

Transforming Customers into Environmentalists and Humanitarians

MeridianBet’s pioneering initiative, Meridian Donate, is transforming the betting industry by engaging customers directly in corporate social responsibility (CSR) actions. This unique platform allows customers to actively participate in and fund various environmental, societal and humanitarian projects, setting a new standard for customer engagement and community impact.

Key Features of Meridian Donate:

  • Direct customer involvement: Customers are not just donors but active participants in CSR decisions
  • Diverse programs: Offers choices from global afforestation to local humanitarian efforts
  • Partnerships with renowned organizations: Collaborates with entities like the Red Cross and UNICEF

Expanding Impact: A Year-by-Year Growth

The Meridian Donate platform has seen substantial growth in its scope and impact:

Advertisement
  • Number of individual campaigns: Grew from 8 in 2021 to 20 in 2023
  • National markets Integrated: Expanded from 3 in 2021 to 8 in 2023
  • Direct Beneficiaries: Increased from 43 NGOs in 2021 to 159 in 2023

In 2023 alone, the platform’s expansion into eight markets facilitated 20 customer-funded campaigns, directly benefiting 159 NGOs, up from 122 the previous year.

Continued Commitment to Innovation and Community Involvement

Meridian Donate not only showcases MeridianBet’s dedication to CSR but also redefines the role of digital marketing within the industry. By converting sports bettors into active CSR participants, Meridian Donate enhances customer loyalty and brand value, making it a critical element of MeridianBet’s market strategy.

Recent Successes and Future Outlook

In its recent operation, Meridian Donate has launched an ambitious global afforestation initiative, committing to plant 20,000 seedlings across various regions. This project not only underscores our environmental commitment but also enhances our brand’s community presence. Already, several hundred contributions have been recorded in the platform’s first month, indicating robust customer engagement and support.

The post Meridian Donate: Revolutionizing CSR in the Betting and Gaming Industry appeared first on European Gaming Industry News.

Advertisement
Continue Reading

Industry News

Games Global Announces Launch of IPO

Published

on

games-global-announces-launch-of-ipo
Reading Time: 3 minutes

 

Games Global Limited (“Games Global”), a leading developer, distributor and marketer of innovative online, casino-style gaming (“iGaming”) content and integrated business-to-business solutions to iGaming operators, announced today that it has launched the roadshow for its initial public offering (“IPO”) of 14,500,000 ordinary shares. The offering consists of 6,000,000 ordinary shares offered by Games Global and 8,500,000 ordinary shares to be sold by Games Global’s existing shareholder (the “Selling Shareholder”). Games Global will not receive any proceeds from the sale of the shares by the Selling Shareholder. The underwriters will have a 30-day option to purchase up to an additional 2,175,000 ordinary shares from the Selling Shareholder at the IPO price, less underwriting discounts and commissions. The IPO price is currently expected to be between $16.00 and $19.00 per share. Games Global has applied to list its ordinary shares on the New York Stock Exchange under the symbol “GGL”.

J.P. Morgan, Jefferies and Macquarie Capital are acting as joint lead book-running managers for the proposed offering. Barclays and BTIG are acting as book-running managers for the proposed offering.

The proposed offering will be made only by means of a prospectus. Copies of the preliminary prospectus relating to the proposed offering, when available, may be obtained from:

Advertisement
  • J.P. Morgan Securities LLC, c/o Broadridge Financial Solutions, 1155 Long Island Avenue, Edgewood, NY 11717, or by email at [email protected] or [email protected];
  • Jefferies LLC, Attention: Equity Syndicate Prospectus Department, 520 Madison Avenue, New York, NY 10022, by phone at (877) 821-7388, or by email at [email protected]; or
  • Macquarie Capital (USA) Inc., Attention: Equity Syndicate Department, 125 West 55th Street, New York, NY 10019, or by email at [email protected]

A registration statement relating to these securities has been filed with the U.S. Securities and Exchange Commission but has not yet become effective. These securities may not be sold, nor may offers to buy be accepted, prior to the time the registration statement becomes effective. This press release does not constitute an offer to sell or the solicitation of an offer to buy these securities, nor shall there be any sale of these securities in any state or jurisdiction in which such offer, solicitation or sale would be unlawful prior to registration or qualification under the securities laws of any such state or jurisdiction.

In any member state of the European Economic Area (the “EEA”) this announcement, and the offering, are only addressed to and directed at persons who are “qualified investors” (“Qualified Investors”) within the meaning of Regulation (EU) 2017/1129 (the “Prospectus Regulation”). In the United Kingdom, this announcement, and the offering, are only addressed to and directed at persons who are “qualified investors” within the meaning of the Prospectus Regulation as it forms part of domestic law in the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 who (i) have professional experience in matters relating to investments falling within Article 19(5) of the Financial Services and Markets Act 2000 (Financial Promotion) Order 2005, as amended (the “Order”), (ii) are high net worth entities who fall within Article 49(2)(a) to (d) of the Order, or (iii) are persons to whom it may otherwise lawfully be communicated (all such persons being referred to as “relevant persons”).

This announcement must not be acted on or relied on (i) in the United Kingdom, by persons who are not relevant persons, and (ii) in any member state of the EEA, by persons who are not Qualified Investors. Any investment or investment activity to which this announcement relates is available only to and will only be engaged with (i) in the United Kingdom, relevant persons, and (ii) in any member state of the EEA, Qualified Investors.

The post Games Global Announces Launch of IPO appeared first on European Gaming Industry News.

Continue Reading

Industry News

Genome and Chilli Partners join forces to revolutionize iGaming affiliate payouts

Published

on

genome-and-chilli-partners-join-forces-to-revolutionize-igaming-affiliate-payouts
Reading Time: 2 minutes

 

Leading the charge in the convergence of financial technology and iGaming, Genome, a cutting-edge electronic money institution, is thrilled to announce its strategic partnership with Chilli Partners, a prominent iGaming affiliate program specializing in casino games.

The collaboration marks a pivotal moment in the iGaming industry, bringing together Genome’s expertise in online financial services and Chilli Partners’ prowess in affiliate marketing. The partnership is set to redefine the landscape of affiliate payouts, offering an array of benefits to both affiliates and the iGaming community at large.

“We are excited to embark on this journey with Chilli Partners. By combining our financial expertise with their influential position in the iGaming affiliate space, we aim to set new standards for efficiency and innovation in affiliate payouts,” – noted Genome’s CEO Daumantas Barauskas.

Advertisement

For one, the partnership offers efficient payouts. Affiliates can now enjoy expedited and secure payouts through Genome’s state-of-the-art financial infrastructure, enhancing their overall experience and satisfaction.

It also provides global reach for Chilli Partners, as it can extend its reach to affiliates worldwide with Genome’s international payment capabilities. This allows Chilli Partners to foster a more diverse and expansive network.

The partnership streamlines financial workflows, ensuring seamless transactions and reducing administrative overhead for Chilli Partners, allowing them to focus on delivering top-notch affiliate services.

Genome is all about innovation in payments and online financial services. This approach brings new possibilities for payment options, providing flexibility and convenience for affiliates participating in the Chilli Partners program.

Lastly, the collaboration prioritizes compliance and risk management, assuring affiliates of secure and compliant transactions in accordance with industry regulations.

Advertisement

“This partnership aligns perfectly with our commitment to providing the best possible experience for our affiliates. Genome’s advanced financial services will play a crucial role in elevating our affiliate program to new heights”, – added Clayton Zammit Cesare, Head of Affiliates at Chilli Partners.

As the iGaming industry continues to evolve, Genome and Chilli Partners stand united in their dedication to driving positive change, innovation, and reliability. The partnership is poised to create a ripple effect, positively impacting the entire iGaming ecosystem.

About Genome

Genome is a leading EMI that provides innovative financial services, including batch payouts, SWIFT, and SEPA transfers. With a focus on efficiency and compliance, Genome empowers businesses across various industries, including iGaming, to streamline financial operations and enhance user experiences.

For more information, please visit https://genome.eu/

Advertisement

About Chilli Partners

Chilli Partners is a prominent iGaming affiliate program specializing in casino games. With a commitment to excellence, Chilli Partners connects affiliates with top-tier iGaming brands, offering a lucrative partnership that includes competitive commission structures and tailored support.

For more information, please visit https://chillipartners.com/

The post Genome and Chilli Partners join forces to revolutionize iGaming affiliate payouts appeared first on European Gaming Industry News.

Advertisement
Continue Reading

Trending

Get it on Google Play

Fresh slot games releases by the top brands of the industry. We provide you with the latest news straight from the entertainment industries.

The platform also hosts industry-relevant webinars, and provides detailed reports, making it a one-stop resource for anyone seeking information about operators, suppliers, regulators, and professional services in the European gaming market. The portal's primary goal is to keep its extensive reader base updated on the latest happenings, trends, and developments within the gaming and gambling sector, with an emphasis on the European market while also covering pertinent global news. It's an indispensable resource for gaming professionals, operators, and enthusiasts alike.

Contact us: [email protected]

Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2024 - Recent Slot Releases is part of HIPTHER Agency. Registered in Romania under Proshirt SRL, Company number: 2134306, EU VAT ID: RO21343605. Office address: Blvd. 1 Decembrie 1918 nr.5, Targu Mures, Romania