Industry News
MMO game Street Mobster leaking data of 1.9 million users due to critical vulnerability
Attackers could exploit the SQL Injection flaw to compromise the game’s database and steal user data.
The CyberNews.com Investigation team discovered a critical vulnerability in Street Mobster, a browser-based massively multiplayer online game created by Bulgarian development company BigMage Studios.
Street Mobster is a free to play, browser-based online game in the mafia empire genre where players manage a fictional criminal enterprise. The game boasts a 1.9+ million player base and stores a user record database that can be accessed by threat actors by committing an SQL Injection (SQLi) attack on the game’s website.
Other games created by BigMage Studios are also potentially vulnerable to the same type of attack, which means that there is a possibility that even more users might be at risk.
The records that can be compromised by exploiting the SQLi vulnerability in Street Mobster potentially include the players’ usernames, email addresses, and passwords, as well as other game-related data that is stored on the database.
Fortunately, after we reported the vulnerability to BigMage Studios, CERT Bulgaria, and the Bulgarian data protection authority, the issue has been fixed by the developers and the user database is no longer accessible to potential attackers.
What is SQL Injection?
First found back in 1998, SQLi is deemed by the Open Web Application Security Project (OWASP) as the number one web application security risk.
Even though this vulnerability is relatively easy to fix, researchers found that 8% of websites and web applications are still vulnerable to SQLi attacks in 2020. Which, from a security perspective, is inexcusable. So much so, in fact, that UK internet service provider TalkTalk was hit with a record £400,000 fine over succumbing to a cyberattack that involved SQLi.
The vulnerability works by injecting an unexpected payload (a piece of code) into the input box on the website or in its URL address. Instead of reading the text as part of the URL, the website’s server reads the attacker’s payload as code and then proceeds to execute the attacker’s command or output data that would otherwise be inaccessible to unauthorized parties. Attackers can exploit SQLi even further by uploading pieces of code or even malware to the vulnerable server.
The fact that Street Mobster is susceptible to SQLi attacks clearly shows the disappointing and dangerous neglect of basic security practices on the part of the developers at BigMage Studios.
How we found this vulnerability
Our security team identified an SQL Injection vulnerability on the Street Mobster website and were able to confirm the vulnerability by performing a simple command injection test on the website URL. The CyberNews team did not extract any data from the vulnerable Street Mobster database.
What’s the impact of the vulnerability?
The data in the vulnerable Street Mobster database can be used in a variety of ways against the players whose information was exposed:
By injecting malicious payloads on Street Mobster’s server, attackers can potentially gain access to said server, where they can install malware on the game’s website and cause harm to the visitors – from using the players’ devices to mine cryptocurrency to redirecting them to other malicious websites, installing malware, and more.
The 1.9 million user credentials stored on the database can net the attackers user email addresses and passwords, which they can potentially use for credential stuffing attacks to hack the players’ accounts on other gaming platforms like Steam or other online services.
Because Street Mobster is a free-to-play game that incorporates microtransactions, bad actors could also make a lot of money from selling hacked player accounts on gray market websites.
What to do if you’ve been affected?
If you have a Street Mobster account, make sure to change your password immediately and make it as complex as possible. If you’ve been using your Street Mobster password on any other websites or services, change that password as well. This will prevent potential attackers from accessing your accounts on these websites in case they try to reuse your password for credential stuffing attacks.
However, it’s ultimately up to BigMage Studios to completely secure your Street Mobster account against attacks like SQLi.
Disclosure and lack of communication from BigMage Studios
Following our vulnerability disclosure guidelines, we notified the BigMage Studios about the leak on August 31, 2020. However, we received no reply. Our follow-up emails were left unanswered as well.
We then reached out to CERT Bulgaria on September 11 in order to help secure the website. CERT contacted the BigMage Studios and informed the company about the misconfiguration.
Throughout the disclosure process, BigMage Studios stayed radio silent and refused to get in touch with CyberNews.com. Due to this reason, we also notified the Bulgarian data protection agency about the incident on October 9 in the hopes that the agency would be able to pressure the company into fixing the issue.
Eventually, however, BigMage Studios appear to have fixed the SLQi vulnerability on streetmobster.com, without informing either CyberNews.com or CERT Bulgaria about that fact.
Industry News
Onlyplay Releases Gold Oktoberfest Video Slot

Onlyplay has released its latest game Gold Oktoberfest! This vibrant video slot takes you straight into the heart of the world’s most joyful celebration, where laughter fills the air, the smell of grilled sausages drifts through the crowd and every corner glitters with the promise of unexpected treasures. From the very first spin you are no longer just a player – you are a guest of honour at the grand Oktoberfest, with reels that shine like freshly polished beer mugs and symbols that dance with colour and flavour.
The reels are alive with frothy mugs of beer, golden pretzels, hunter hats with bright feathers, shining hops and bursting wursts, each symbol bringing a little more of that irresistible Bavarian charm to your screen. The mascot himself, a cheerful fellow in traditional costume with a hearty laugh and a stein in his hand, welcomes you into the game with warmth and good fortune, reminding you that this is not just a slot – this is a festival of joy, risk and reward. Every spin feels like another toast, another clink of mugs, another chance to step closer to the treasure hidden beneath the foam.
As the game unfolds, the atmosphere grows more intense. You feel the adrenaline rush with every coin that lands, the suspense when the reels slow down, the electricity of risk turning into triumph when the screen lights up with a jackpot win. Mini, Major or even Grand – each prize feels like the ultimate cheer from the crowd, a standing ovation of golden confetti and roaring applause. And when the bonus round begins, it’s like the music swells, the lights grow brighter and the party rises to a whole new level, carrying you on a wave of excitement that never seems to end.
The post Onlyplay Releases Gold Oktoberfest Video Slot appeared first on European Gaming Industry News.
Industry News
StatRankings Launches with Aim to Deliver Faster, Cleaner, and Smarter Sports Data Experience

StatRankings, the ultimate data hub for sports fans, bettors, and fantasy players, announced the launch of its new website. Designed for speed, simplicity, and privacy, StatRankings helps users make smarter decisions by removing the clutter of outdated, stat sites. With more than 500 NFL data points organized on dedicated, ad-free pages, fans can instantly find the data they need to help set fantasy lineups or put together a betting slip without endless tables, pop-ups, or dashboards getting in the way.
“The sports stats industry has been stuck in the past for too long. These sites supposedly designed for bettors, fantasy players, and media are archaic, cumbersome, and confusing. We are committed to keeping the experience of finding stats as smooth and easy as possible, without all the noise. We want StatRankings to represent a new standard in how sports data can be delivered,” said Kevin Adams, Founder of StatRankings and fantasy sports industry veteran.
In addition to the launch of its website, StatRankings created a partnership with One Week Season, a premium DFS (Daily Fantasy Sports) subscription service that offers content, tools, and community. StatRankings data will be used across shows and articles found on One Week Season’s site for the duration of the NFL season.
“One Week Season is all about teaching people the ‘how’ when it comes to becoming a better DFS player. StatRankings helps us in that mission by making sharper and deeper data more accessible and doing so in a manner that has previously been awkward and downright clumsy. By incorporating StatRankings into our content, we’re able to offer the most optimized insights to our users for their success,” said One Week Season’s CEO Jordan Tohline.
The post StatRankings Launches with Aim to Deliver Faster, Cleaner, and Smarter Sports Data Experience appeared first on Gaming and Gambling Industry in the Americas.
Gambling in the USA
Gaming Americas Weekly Roundup – August 11-17

Welcome to our weekly roundup of American gambling news again! Here, we are going through the weekly highlights of the American gambling industry which include the latest news and new partnerships. Read on and get updated.
Latest News
AU10TIX announced the launch of a free Child Safety Age Assurance Risk and Readiness Assessment and Age Assurance Readiness Guide designed to help businesses better understand their risk and tailor their strategy to meet regulatory obligations. They support AU10TIX’s Selfie-based Age Estimation service, which delivers the industry’s most precise and unbiased age assessment in just two seconds. In the US, federal legislation such as the Children’s Online Privacy Protection Act (COPPA) requires parental consent for users under 13, while the California Consumer Privacy Act mandates age verification for websites accessed by users under 16. Additionally, 19 U.S. states now enforce mandatory age checks for adult content and gambling platforms. Similar regulations are impacting social media and online services in the UK, EU and Australia.
Caesars Entertainment has launched its third fully in-house developed proprietary online casino title: Signature American Roulette. Now live in New Jersey, the game is available across Caesars Palace Online Casino, Caesars Sportsbook & Casino and Horseshoe Online Casino, bringing another standout addition to the Company’s Signature table game series. Developed by Empire Creative, Signature American Roulette reflects Caesars’ growing investment in building its own proprietary content, a cornerstone of its online casino strategy aimed at delivering a best-in-class player experience. Signature American Roulette follows the recent launches of fan-favourite Signature titles, Caesars Palace Signature Multihand Blackjack Surrender in May and Signature Blackjack Surrender in June, both also developed by Empire Creative.
Novig announced the successful close of an $18 million Series A funding round. The round was led by Forerunner, with participation from existing investors Y Combinator, NFX, Perceptive Ventures and Gaingels. Founded by Jacob Fortinsky and Kelechi Ukah, Novig is reimagining sports predictions as a transparent and fair marketplace. Unlike traditional sportsbooks, Novig allows users to trade directly with one another, rather than against the house, eliminating hidden fees, biased odds and the risk of being penalised for winning.
Partnerships
IGT announced that it has secured a multi-year sports betting technology and services agreement with Hipodromo de Agua Caliente SA de CV and Distribuidora Internacional de Equipos de Juego, S. De R.L. De C.V. that will significantly extend IGT PlaySports’ footprint to Mexico and Latin America via Corporación Caliente. Per the agreement, 42 Caliente sportsbooks in Mexico will leverage the IGT PlaySports platform and services from the Company’s Trading Advisory Services Team. Through a phased rollout, Caliente will also be able to provide select sportsbooks operators throughout Latin America access to IGT PlaySports’ technology, extending the technology’s reach to more than 100 additional venues across eight countries.
CT Interactive has announced a strategic partnership with Ondiss. Through this collaboration, CT Interactive’s top-performing titles are now integrated into the Ondiss platform, significantly expanding the company’s reach within the region’s regulated iGaming market. This integration adds value to the broad Argentine audience of Casino & Hotel Casino Magic S.A., which successfully uses the Ondiss platform. With CT Interactive’s certified and player-favourite content now available, operators on the platform are empowered to diversify their offerings and meet the increasing demand for engaging, high-quality games.
The post Gaming Americas Weekly Roundup – August 11-17 appeared first on European Gaming Industry News.
-
gaming3 years ago
ODIN by 4Players: Immersive, state-of-the-art in-game audio launches into the next generation of gaming
-
EEG iGaming Directory8 years ago
iSoftBet continues to grow with new release Forest Mania
-
News7 years ago
Softbroke collaborates with Asia Live Tech for the expansion of the service line in the igaming market
-
News7 years ago
Super Bowl LIII: NFL Fans Can Bet on the #1 Sportsbook Review Site Betting-Super-Bowl.com, Providing Free Unbiased and Trusted News, Picks and Predictions
-
iGaming Industry8 years ago
Rick Meitzler appointed to the Indian Gaming Magazine Advisory Board for 2018
-
News7 years ago
REVEALED: Top eSports players set to earn $3.2 million in 2019
-
iGaming Industry8 years ago
French Senator raises Loot Boxes to France’s Gambling Regulator
-
News7 years ago
Exclusive Interview with Miklos Handa (Founder of the email marketing solutions, “MailMike.net”), speaker at Vienna International Gaming Expo 2018