Results 1 to 5 of 5
  1. #1
    The Buzz's Avatar
    The Buzz is offline GPWA Gossip Hound
    Join Date
    February 2007
    Location
    Newton, MA
    Posts
    4,478
    Thanks
    454
    Thanked 2,028 Times in 1,267 Posts

    Default PokerStars, Full Tilt players vulnerable to Trojan that lets others see hole cards

    Sounds like online poker players have some new malware to look out for. At least "several hundred" players have been impacted by malware that looks innocent, but it surreptitiously sending screenshots of PokerStars and Full Tilt screens to another player, who can then find and join the table where the player is and run over the player, as they'll be able to see the other player's hole cards.

    Full report here: http://blog.eset.ie/2015/09/17/the-t...eats-at-poker/

  2. The Following 3 Users Say Thank You to The Buzz For This Useful Post:

    -Shay- (17 September 2015), ocreditor (20 September 2015), Vrindavan (23 September 2015)

  3. #2
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,974
    Thanks
    4,536
    Thanked 9,290 Times in 5,977 Posts

    Default

    So where is the ip or hostname address that is hard coded into the software?

    Whoever did all this research and reverse engineering, as well as packet inspection and forensics to figure out what is taking place and how the trojan is working and how the scumbags are using it, fails to provide millions of people with the information needed to stop the scumbags in their tracks even if they can not remove the trojan.

    By knowing the ip or hostname, and entry could be added to the host file, or a block added to the firewall and the trojan would be rendered useless even if it could not be removed.

    Also the web host as well as upstream providers could be notified as this is pretty clear proof of illegal hacking activity and would show whether the host is willing to follow policies.

    Depending on the subnet this server is in, I would most likely consider blocking the ip globally on all servers on my rack as this certainly is an indication of a bad actor.

    Rick
    Universal4

  4. #3
    Miles_FTA's Avatar
    Miles_FTA is offline No longer with Fast Track
    Join Date
    May 2010
    Posts
    1,490
    Thanks
    121
    Thanked 540 Times in 405 Posts

    Default

    So is this allowing players to basically learn a pattern of play by them receiving these screenshots and then giving them the edge on a table ?

  5. #4
    DaftDog's Avatar
    DaftDog is offline Private Member
    Join Date
    October 2008
    Location
    South Africa
    Posts
    2,162
    Thanks
    697
    Thanked 779 Times in 467 Posts

    Default

    Quote Originally Posted by Miles_FTA View Post
    So is this allowing players to basically learn a pattern of play by them receiving these screenshots and then giving them the edge on a table ?
    No, the malware sends a screenshot instantly after a new hand is dealt so that the spy can see what his target-players hole cards are.

  6. The Following User Says Thank You to DaftDog For This Useful Post:

    ocreditor (20 September 2015)

  7. #5
    ocreditor's Avatar
    ocreditor is offline Private Member
    Join Date
    April 2009
    Location
    Israel
    Posts
    7,353
    Blog Entries
    1
    Thanks
    7,103
    Thanked 4,342 Times in 2,835 Posts

    Default

    Thats amazing discovery, if its so simple to implement this to PS and FT imagine how much money is flowing to the same pockets
    of the cheaters

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •