Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

Absolute Poker Network Encryption Vulnerability

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
35,839
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on May 6, 2010

http://www.pokertableratings.com

The Cereus poker network uses a weak xor based encryption mechanism for all network transmissions instead of the industry standard SSL. The encryption key can be easily identified from a network dump and used to decrypt all information transmitted between the client application and the Cereus servers.

In our lab we are able to intercept and decode the user's login name (e-mail address), and receive an MD5 hash of their password, as well as their seat number and hole cards. Once the MD5 password hash has been intercepted, we've been able to log in using the intercepted login name by overwriting the outgoing login packet with the intercepted MD5 hash - thus logging in the victim's poker account without their knowledge, remotely.

We've also been able to remotely display all seat numbers and hole cards on a compromised network.

All proof of concepts have been shown to work over a compromised WPA2 encrypted wireless network as well as unencrypted wireless networks, and physical network access (either through a hub, ARP man in the middle attack, or otherwise).

Category:

Gaming

Tags:

License:

Standard YouTube License

  • likes, 3 dislikes

Link to this comment:

Share to:
see all

All Comments (28)

Sign In or Sign Up now to post a comment!
  • @TBKV hmm...are u serious ? how can they detect what i'm doing with my computer lol ? and what webpages i'm browsing

  • @pawppy on Pokerstars/FullTilt etc. they encrypt the data, so it looks like *&^@*&#$@JHKJFHDFHDO*&ZX^&%!11­2764 gobbledygook (unless you have the key to decrypt it).

    But on Absolute Joker, apparently it was sent as "free text" and probably also contained the identifying information for Player and Table Name/Number, since that would be needed by the poker site's client software.

    The issue is that the data (whatever it contained!) was not encrypted once it gets to your home computer :(

  • @simonjeste k so what if you open 1 table of 25/50$ and 11 tables of 1c/2c could you track what hand you get dealt at the 25/50 hand specifically? on PokerStars for example?

  • what about when having a cable internet network in your neighbourhood. someone could track those packets if he has access to the hub or even the isp servers right? if so could you track at which stake you get dealt a hand on let's say PokerStars? meaning if it would be possible to sniff the cable connection or maybe even listen from the isp and you would have 1 table of 5/10$ and 11 tables of 0.01/0.02c$ could you track what holecards you get dealt just at the 5/10 table?

  • Got huge $600? poker deposit bonus by using this Fulltilt poker bonus code POKERDEAL14

  • PKR online poker $800 sign up bonus code DEAL14

  • If you use fulltilt referral code POKERDEAL14 you will get $600 Free bonus!!

  • @18000rpm BROCK should read this response!

  • @brocktherock68 brock... pay attention to what is said at the start of the video.

    The server only sends him HIS hole card information -- which should ONLY be understood by the poker client application. Instead, it is sent almost "clear text" over the internet, which means ANYONE who is tapped into the network stream could simply XOR the text contents and see the information, including the hole cards. Someone at his ISP could even do it -- if they knew his IP, and knew how to tap the stream.

  • @squarerabbits

    No, the big sites are safe. Its tested regularly and its not possible to cheat on stars or full tilt.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more