Connect with us
European Gaming Congress 2024

Industry News

MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability

Published

on

Reading Time: 3 minutes

Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.

The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.

Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.

Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.

Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.

What is SQL Injection?

First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.

Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.

The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.

 

How we found this vulnerability

Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What’s the impact of the vulnerability?

The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:

By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.

The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.

Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

What to do if you’ve been affected?

If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.

However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.

Disclosure and lack of communication from BigMage Studios

Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.

Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.

Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.

 

Source

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading
Advertisement

Industry News

Melco’s Cyprus “Glow Your Way to Macao” Roadshow Promotes Macao’s Status as a Leading Leisure and Business Travel Destination to European and Arabian Markets

Published

on

melco’s-cyprus-“glow-your-way-to-macao”-roadshow-promotes-macao’s-status-as-a-leading-leisure-and-business-travel-destination-to-european-and-arabian-markets
Reading Time: 3 minutes

 

With the aim of supporting the SAR government’s plans to promote international travel and boost tourism in Macao, on September 17, hosted the second in its series of “Glow Your Way to Macao” events, this time in Cyprus, to promote Macao’s status as a top travel leisure and business destination.

To appeal to travelers from European and Arabian countries, Melco invited approximately 150 guests from the government of the Republic of Cyprus, the Macao SAR government, travel agencies, business associations and media representatives from across Europe, the Gulf Cooperation Council (GCC) countries and Macao to the event hosted at City of Dreams Mediterranean. The roadshow introduced attendees to Macao’s diverse historical and cultural offerings and attractions, as well as Melco’s unparalleled and award-winning hotel, entertainment, dining and exhibition facilities.

Showcasing Melco’s steadfast commitment to promoting Macao as a global hub for both leisure and business travelers, Melco has set up sales offices to promote the city in Singapore, Hong Kong and the Philippines, and is currently in the process of setting up a sales office the Republic of Cyprus.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

Mr. Lawrence Ho, Chairman and CEO of Melco, said: “As a prominent integrated resort operator deeply rooted in Macao, we are thrilled to host our second ‘Glow Your Way to Macao’ event at City of Dreams Mediterranean. It serves as a testament to our support for the SAR government’s drive to attract further international travelers the city, and to expand Macao’s visitor sources in alignment with the “1+4” diversified development strategy. Being a study of contrasts — from its multicultural heritage to its culinary identity, Macao is a unique destination that truly never sleeps. We are thrilled to support the Macao government’s efforts to promote the city’s gastronomy, sporting events, culture, heritage and the creative arts as it continues to diversify and bloom. We are confident that Macao will grow to become an even more cherished and popular destination for travelers from Cyprus, the broader European and GCC market, as an exciting and remarkable city for visitors to immerse themselves in electrifying excitement.”

Mr. Andreas Gregoriou, Head of Presidency, Cyprus, said: “It is a great pleasure to welcome the Macao Authorities to Cyprus for this roadshow, showcasing Macao’s potential as a global destination for leisure and business travel. Cyprus, with its strategic location at the crossroads of Europe, Asia, and Africa, offers unparalleled access to markets in the wider Mediterranean, the Middle East, and beyond. As a member of the European Union, Cyprus serves as a gateway to one of the largest and most diverse economic zones in the world.”

Ms. Maria Helena de Senna Fernandes, Director of the Macao Government Tourism Office, said: “Macao and Cyprus have much in common and great room for cooperation in tourism and beyond. Helped by Melco Resorts & Entertainment’s City of Dreams Mediterranean and its Macao Sales Office in Cyprus, I believe that we can spark a long-lasting friendship and cooperation between our two destinations. We look forward to joining hands with Macao’s integrated resort enterprises to create more cooperation and jointly expand the international visitor source markets.”

Mr. Sam Lei, Director of Commerce and Investment Promotion Institute (IPIM) of Macao SAR, said: “As we strive to enhance Macao’s MICE development, it is great to see Melco continue to implement initiatives to promote the city and its MICE infrastructure to overseas markets, this time to audiences in Europe and the GCC. We will continue to leverage Macao’s unique advantages by collaborating with cross-sector stakeholders to attract more professional and international events, and make the ‘Golden Calling Card’ of Macao as an international metropolis shine brighter.”

The post Melco’s Cyprus “Glow Your Way to Macao” Roadshow Promotes Macao’s Status as a Leading Leisure and Business Travel Destination to European and Arabian Markets appeared first on European Gaming Industry News.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)
Continue Reading

Industry News

Rossi McKee will Participate in Omnichannel Strategy Panel at SBC Summit 2024

Published

on

rossi-mckee-will-participate-in-omnichannel-strategy-panel-at-sbc-summit-2024
Reading Time: < 1 minute

 

Rossi McKee, entrepreneur, co-founder of Telematic Interactive, CT Interactive and CT Gaming, will participate in the panel discussion at SBC Summit 2024 titled “Omnichannel Strategy for Enhanced Customer Experience”. The session will take place on Tuesday, September 24, 2024.

The discussion will address how businesses can leverage the latest technologies to ensure a seamless experience across online and offline platforms. McKee, alongside other panellists, will explore how lessons from online gaming, such as personalised marketing and advanced data analytics, can enhance land-based casino experiences. Panellists will also evaluate the current state of omnichannel implementation in the industry, considering whether businesses are fully capitalising on its potential to drive engagement and satisfaction.

Additionally, the conversation will cover how omnichannel strategies align with modern consumer expectations, aiming to provide a cohesive and exceptional customer experience.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

McKee’s extensive expertise in the gaming sector will provide valuable perspectives on navigating these complexities. Attendees can look forward to gaining actionable insights on creating a unified customer experience that bridges digital and physical touchpoints.

The post Rossi McKee will Participate in Omnichannel Strategy Panel at SBC Summit 2024 appeared first on European Gaming Industry News.

Continue Reading

Industry News

Play’n GO Honoured at Corporate Star Awards Ceremony

Published

on

play’n-go-honoured-at-corporate-star-awards-ceremony
Reading Time: < 1 minute

 

Play’n GO, the world’s leading casino entertainment provider, was honoured as a global leader in Environmental Social Governance (ESG) practices at the prestigious Corporate Star Awards held in Amsterdam. The company was the only iGaming company shortlisted at the ceremony, and was nominated for the Best ESG Report award, placing it among renowned organisations such as Globo, EVS and SONY Entertainment, who won the category overall.

The Corporate Star Awards are known for recognising excellence in corporate reporting and sustainability, and Play’n GO’s nomination for the Best ESG Report Award is testament to its commitment to transparency and responsible business practices.

Play’n GO’s ESG Report provides comprehensive insights into the company’s environmental initiatives, social impact and governance practices, and showcases Play’n GO’s commitment to reducing its carbon footprint, promoting diversity and inclusion, and maintaining high ethical standards throughout its operations.

Advertisement
European Gaming Congress 2024 (Warsaw, Poland)

The Corporate Star Awards recognise organisations that go above and beyond in their commitment to ESG practices, setting a benchmark for corporate responsibility. Play’n GO’s inclusion among the shortlisted companies underscores its position as a global leader in the iGaming industry and its dedication to sustainable business practices.

Johan Törnqvist, CEO and co-founder of Play’n GO, said: “We are truly honoured to be recognized as a global ESG leader at the Corporate Star Awards. This nomination is a testament to our unwavering dedication to sustainability and responsible business practices. We believe that a strong ESG framework is essential for the long-term success of any organization, and we are proud to be at the forefront of this movement. We look forward to participating in next year’s awards, and to furthering our own ESG initiatives.”

The post Play’n GO Honoured at Corporate Star Awards Ceremony appeared first on European Gaming Industry News.

Continue Reading

Trending