Connect with us
Prague Gaming & TECH Summit 2025 (25-26 March)

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading
Advertisement

Industry News

Public Voting Starts for Ortak x B.F.T.H. Arena Awards 3.0

Published

on

public-voting-starts-for-ortak-x-bfth-arena-awards-3.0
Reading Time: < 1 minute

 

The highly anticipated Ortak x B.F.T.H. Arena Awards 3.0 has officially entered the public voting phase as submissions are closed.

More than 70 game providers have turned in over 160 submissions, including Tom Horn Gaming, Pragmatic Play and RubyPlay. Public voting involves enthusiasts casting their votes to pick the winner of the Game of Public Choice category.

The Public voting phase ends on December 1st 23:59 GMT+4.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Concurrent to public voting, the first phase of private voting also starts during which all participants who have submitted entries get the chance to vote for one favourite in each category. An international auditing company oversees this phase to eliminate duplicate votes and self-votes. This phase ends on November 19, 23:59 GMT+4.

The second phase of private voting will also take place with a jury of industry experts making their decisions based on the shortlist picked by participants during the first phase.

The post Public Voting Starts for Ortak x B.F.T.H. Arena Awards 3.0 appeared first on European Gaming Industry News.

Continue Reading

Industry News

BC.GAME Launches Exclusive Airdrop for Polymarket Users, Rewarding Participation in U.S. Election Prediction Markets

Published

on

bcgame-launches-exclusive-airdrop-for-polymarket-users,-rewarding-participation-in-us.-election-prediction-markets
Reading Time: 2 minutes

 

Following the frenzy surrounding the 2024 U.S. presidential election, global leading crypto igaming platform BC.GAME has officially announced an exciting airdrop campaign aimed specifically at Polymarket users. This initiative will bring BC.GAME’s gaming entertainment together with the wisdom of Polymarket users, offering a much-needed opportunity for those who actively participated in the election prediction market.

Airdrop Frenzy Amid the Hype: Special Rewards for Polymarket Users

Following the intense activity during the 2024 U.S. presidential election, Polymarket saw an unprecedented surge in user participation. Thousands of individuals placed bets on the election results, turning this prediction market into a major financial event.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

To capitalise on this momentum, BC.GAME is launching an exclusive airdrop for Polymarket users. The campaign will reward active participants with exclusive prizes and access to BC.GAME’s expansive gaming ecosystem, creating an exciting opportunity for those who took part in one of the most talked-about prediction markets in history.

Exclusive Airdrop: A Chance to Turn the Tide

The BC.GAME airdrop campaign will offer Polymarket’s active users unique rewards, creating an exciting and unparalleled experience in the crypto gaming space. By leveraging the buzz surrounding Polymarket, BC.GAME aims to bring its innovative gaming ecosystem to more users, giving them the opportunity to earn substantial rewards through this airdrop. Polymarket users will not only enjoy exclusive games on the BC.GAME platform, but also have the chance to claim specially designed rewards. The BC.GAME team guarantees a transparent and fair process throughout the event, ensuring that every participant receives maximum benefits.

BC.GAME: Igniting the Future of Crypto Communities

BC.GAME has always been at the forefront of innovation, providing users with a never-before-seen gaming experience. According to data from 1ml .com, BC.GAME is ranked 14th globally in the crypto gaming space and supports hundreds of cryptocurrencies, including Poly, providing users with diverse payment and gaming options.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

In addition, BC.GAME actively participates in the development of the crypto community by investing in NFTs and supporting the growth of the metaverse. For example, BC.GAME has invested 700 ETH into various NFT projects to foster growth in the metaverse and iGaming sectors. By engaging with Polymarket users, BC.GAME is lighting up new possibilities in the crypto world and paving the way for the future of digital entertainment.

The post BC.GAME Launches Exclusive Airdrop for Polymarket Users, Rewarding Participation in U.S. Election Prediction Markets appeared first on European Gaming Industry News.

Continue Reading

Industry News

Double win for Kaizen Gaming at the SBC Awards Latinoamérica 2024

Published

on

double-win-for-kaizen-gaming-at-the-sbc-awards-latinoamerica-2024

Kaizen Gaming, one of the biggest GameTech companies in the world, had an impressive double-win at the SBC Awards Latinoamérica 2024 on the 31st October in Miami, Florida. Awarded ‘Brazilian Market Entrant of the Year’, and ‘Marketing Campaign of the Year’, the two wins follow an impressive year of growth and exposure for Kaizen Gaming, as well as its premium brand Betano, across Latin America and globally.

Betano is rapidly growing its user base and presence in Brazil, serving as the main and title sponsor of Brasileirão Betano and Copa Betano do Brasil. As a founding member of the ANJL and IBJR regulatory bodies, Betano is recognised for its dedication to upholding the highest standards of responsible gaming and integrity. Furthermore, the Betano brand has launched multiple CSR initiatives across the country in partnership with sponsored team, Clube Atlético Mineiro. It also recently launched the “Juntos em Campo” long-term program in cooperation with CBF (Brazilian Football Confederation) to promote initiatives focused on gender equality.

Awarded for the results and creativity of its innovative “Football in America” marketing campaign, Betano successfully introduced Latin America to its “Confia” brand platform by leveraging on its CONMEBOL Copa America™ 2024 sponsorship. The campaign chimed with the spirit of fans across the continent by celebrating Latin America’s rich football heritage, playfully responding to Kylian Mbappe’s 2022 comments questioning the region’s football quality.

Vangelis Skarkalis, Kaizen Gaming Senior Commercial Director LATAM, said: “Latin America is one of the world’s most dynamic and exciting regions for i-gaming. Being recognised as a leading player in this important market with two wins at the prestigious SBC Awards Latinoamérica is a great honour – especially on the heels of our recent double-win as ‘Operator of the Year’ at both the EGR Operator Awards and SBC Awards. Achieving this success requires an exceptional team of dedicated, ambitious professionals. This award honours everyone’s hard work and commitment to always going above and beyond in delivering the best experiences for our customers not only in Latin America, but worldwide too.”

Continue Reading

Trending