Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Chinese developers expose data belonging to Android gamers
#1
https://www.zdnet.com/article/chinese-de...RSSbaffb68       
Chinese developers expose data belonging to Android gamers

In the end, Hong Kong CERT was contacted in an attempt to resolve the security issue.
Charlie Osborne

By Charlie Osborne for Zero Day | August 26, 2021 -- 16:34 GMT (09:34 PDT) | Topic: Security

The Chinese developers of popular Android gaming apps exposed information belonging to users through an unsecured server.        In a report shared with ZDNet, vpnMentor's cybersecurity team, led by Noam Rotem and Ran Locar, revealed EskyFun as the owner of a 134GB server exposed and made public online.

EskyFun is the developer of Android games including Rainbow Story: Fantasy MMORPG, Adventure Story, The Legend of the Three Kingdoms, and Metamorph M.

On Thursday, the team said that users of the following games were involved in the data leak: Rainbow Story: Fantasy MMORPG, Metamorph M, and Dynasty Heroes: Legends of Samkok. Together, they account for over 1.6 million downloads. 

In total, the team said that an alleged 365,630,387 records contained data from June 2021 onward, leaking user data collected on a seven-day rolling system.

The team says that the developers impose "aggressive and deeply troubling tracking, analytics, and permissions settings" when their software is downloaded and installed, and as a result, the variety of data collected was, perhaps, far more than you would expect mobile games to require.

The records included IP and IMEI numbers, device information, phone numbers, the OS in use, mobile device event logs, whether or not a handset was rooted; game purchase and transaction reports, email addresses, EskyFun account passwords stored in plaintext, and support requests, among other data.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Android apps exposed data of millions of users through cloud authentication failure mrtrout 0 1,111 05-21-2021 , 12:58 AM
Last Post: mrtrout
  Malware hidden in game cheats and mods used to target gamers Bjyda 0 1,126 03-31-2021 , 07:57 PM
Last Post: Bjyda
  Thousands of Android and iOS Apps Leak Data From the Cloud Bjyda 0 1,158 03-05-2021 , 12:11 AM
Last Post: Bjyda
  Nginx: Server misconfigurations found in the wild that expose websites to attacks Bjyda 0 901 02-28-2021 , 07:26 PM
Last Post: Bjyda
  Chinese hackers cloned attack tool belonging to NSA’s Equation Group Bjyda 0 737 02-22-2021 , 10:57 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)