JavaScript is turned off in your web browser. Many features of this website depend on you having Javascript turned on, please enable it in your browser settings.

Main » Articles, Featured Articles, Security

Cereus Patch adds SSL, Update: SSL live

By dameon - May 14th, 2010

Game Security

Cereus has just updated to include SSL support, aimed at fixing the security vulnerabilities we previously disclosed at http://www.pokertableratings.com/blog/2010/05/ptr-security-alert-cereus-poker-network/

We’re in the midst of auditing it at the moment. We will post details as they come in.

Update 1 @ 5/14/2010: The update seems to use OpenSSL ONLY for player actions such as hole cards, bets, etc – we have already been able to hijack a test poker account using the exact same methods. More to follow

Update 2 @ 5/14/2010: We’ve re-run all tests and can confirm that we are still able to hijack logins by sniffing the network, this is not by hacking someones individual computer, but the same exact security hole as before. We can confirm that it is now impossible to steal hole cards using the previous exploit

Update 3 @ 5/14/2010: Cereus acknowledges issue via e-mail “Thanks for getting back to me and bringing this to my attention. Our developers are working on resolving this issue right now and will follow up with a second update later today that will fix this.” This is great news, we will verify the fix as soon as it goes live.

Update 4 @ 5/16/2010: Cereus patched again and have informed us they believe the issue is solved. We’re attempting to confirm this via testing and will report back soon.

Update 5 @ 5/16/2010: We can confirm that SSL is now being used everywhere for Cereus. The login vulnerability no longer exists. We’re now ensuring a proper implementation, but it seems like the biggest problems have been addressed.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • StumbleUpon

Tags:

48 Responses to “Cereus Patch adds SSL, Update: SSL live”

  1. pitcold avatar pitcold says:

    @PTR. Please skip Cereus off your site. Add Ongame instead.

  2. YOURTHERAKE avatar YOURTHERAKE says:

    its so funny that this site is truly a scam, ive told there support 3 months ago that something was going on, they blow it off as if they don’t care!

  3. Astroxss avatar Astroxss says:

    LOL :D

  4. missarcade avatar missarcade says:

    Cereus is a joke site, bunch of apprentice programmers who work for free, and earn money by stealing from players.

  5. mboyle4999 avatar mboyle4999 says:

    During the server restart associated with the first update, I was playing 3 tables of 10nl. I had money invested in the pot at each table when the server restarted. Guess what happened to the money in the pot? Noboday knows!!!!!!!! Support won’t even get back to my e-mails. I am done with that joke of a site.

  6. psalm 71 avatar psalm 71 says:

    Also, Cereus was arrested for drunk driving early this morning!

  7. Raikaclaws avatar Raikaclaws says:

    last sentence:”We can confirm that it is now impossible to steal hole cards using the previous exploit”

    Does this mean Cereus is safe?

  8. dameon avatar dameon says:

    “We’ve re-run all tests and can confirm that we are still able to hijack logins by sniffing the network”

    I think it’s that sentence that you should be concentrating on ;) Your hole cards are safe, your account is not.

    Dameon

  9. zachvac avatar zachvac says:

    lol seriously this is ridiculous how can a site be this incompetent?

  10. igdoof avatar igdoof says:

    what is the big commotion about? players have choices, the most full proof method of avoiding cheating/security hole/trust issues at cereus is simply to not play there … i dont’ understand why so many ppl continue to play there when it’s just as easy to play stars or tilt …

    security/trust is a huge factor with online poker … if cereus wasn’t proactive enuf to be on top of these issues, people should not play there … the burden should not be on the poker community to discover security issues and inform them … the burden should be on cereus to protect the players as much as possible … they are not fulfilling their fiduciary duty on an acceptable manner …

    the fix is easy … just play somewhere else …

  11. Raikaclaws avatar Raikaclaws says:

    Just a question to understand the situation perfectly:

    Is a cereus-account unsafe when using a private password-protected network?

  12. dameon avatar dameon says:

    @Raikaclaws: The same rules apply as our original post on the matter suggests http://www.pokertableratings.com/blog/2010/05/ptr-security-alert-cereus-poker-network/

    It’s all levels of risk.

  13. armor32 avatar armor32 says:

    Yes, very easy to bash when everyone’s bashing, right mboyle? I play at Cereus for three years now, they have great customer service, including live chat. They response time is very very quick. I have full confidence that all issues will be fixed and overall it’s quite over-hype.

  14. aenetomic avatar aenetomic says:

    I think its great that you guys are doing this audit but I’ve heard quite enough of cereus for now. How long till some new topics hit the front page?

  15. northkato avatar northkato says:

    bad players never realize why they lose money. funny the 10nl players are concerned that someone is going to hack them for their 55 dollar roll.

  16. mboyle4999 avatar mboyle4999 says:

    Lol Armor….you must not have read my post. Read it again. You would be pissed if u were in the same situation as me. Read it again….lol.

  17. Kaibraine avatar Kaibraine says:

    OMG I just heard about this!

    Im tempted to go and play about on Cereus network tonight! Just for educational purposes of course :)

    Hopefully something good will come across.

  18. polkaqueen avatar polkaqueen says:

    No matter what they do, you’d have to be a fool to ever play there again. Stars FTW hands down!!!

  19. LazYguY13 avatar LazYguY13 says:

    You know PTR, for having a site that dosent work properly half the time, and seems to miss a majority of big hands played, you sure are pointing alot of fingers.=)

  20. HalfThreat avatar HalfThreat says:

    cant believe cereus…

  21. aise0603 avatar aise0603 says:

    I just listened to the PTR interview on Cash Plays. You guys are great with super integrity. I love the questions that you are posing and will be shocked if they give you the answers to them. Keep up the great work.

  22. zachvac avatar zachvac says:

    lol LazYguY you’re equating a site not having perfect information to a site making it extremely easy for your pw to be hacked? No one ever lost money because PTR missed hands, plenty of people have lost tens of thousands of dollars because their account got hacked. Also PTR I still hate your site and I think the entire premise of the site is helping to destroy online poker but gotta give credit where it’s due thanks for exposing this and helping inform the poker community of the updates.

  23. dameon avatar dameon says:

    @zachvac: …thanks? ;)

  24. slipperysilver avatar slipperysilver says:

    lmao still not secure.

  25. Roller avatar Roller says:

    Great work, PTR!

    I’m just curious if you track non-US poker rooms same way?

  26. haroldw_pp avatar haroldw_pp says:

    Thank you PTR for the research and hard work on this. I have no more questions. Whatever that poker network (not worth the name imho; since an online poker room/network should first and foremost be secure) is going to come up with, I am not going to trust them with my money. And never will, since they don’t even succeed in securely transferring data from client to server and back – apparently genuinely believing themselves that things are secure (even after being pointed to the weakness and having had the chance to change things).

  27. checkdiana85 avatar checkdiana85 says:

    Cereus get serious

  28. REturnofzx avatar REturnofzx says:

    news f;ash stars and ftp aren’y any safer who knows who controling the strings behind closed doors

  29. 2pairs1pot avatar 2pairs1pot says:

    hey dameon does Stars and Tilt have this problem too?

  30. d1337er avatar d1337er says:

    Don’t play there, cereusly

  31. zachvac avatar zachvac says:

    @dameon I mean you datamine and break TOS and give away info on players’ games for money. You don’t really expect poker players to like you right? But like I said gotta give credit where it’s due I’m not smart enough to be able to check that stuff and you’re keeping people informed, even if the motives are selfish.

    @REturnofzx you’re kidding right? Cereus has had like 5 different scandals, Stars/FTP have had none. stars/FTP actually use software developed by people who know what they’re doing, Cereus seriously has the feel of some high school kid who wrote it for a project. The waitlists are terrible and basically it just seems super amateurish. I’ve never trusted them since the super-users but never thought they’d be THAT incompetent. Ask anyone who has a clue about serious software development and you’d realize this would not pass even the basic initial security testing, let alone thourough testing they claimed was conducted when they merged. Playing on Cereus is like playing in a fishy home game where the sketchy host plays and deals all the hands. Some people play there because they can win even with the risk of cheating but no one has any room to complain if they play there and get hacked/robbed due to negligence or holes in the Cereus software. Stars/FTP have excellent software that was clearly developed by professionals. If you think they’re no more safe how about some proof?

  32. KoldShadow avatar KoldShadow says:

    Wow, I am so glad I got a hefty $125 no deposit bonus on Absolute. Feels so good with all this going down now, especially since I was able to play a little on there before the news broke. Of course, it feels even better to have other no deposit bonuses on the Merge Network and deposited money on Full Tilt so as to have an alternative. Furthermore, the lack of a time limit to fulfill my no deposit bonuses makes this whole fiasco less than an inconvenience, because it’s not like the clock is ticking to get the APP’s I need. Whether it takes 5 more days or 5 more weeks to get Cereus secure, I CAN WAIT! B-)

  33. mrjoecoool avatar mrjoecoool says:

    its simple..DONT PLAY THERE, easy problem solved

  34. screenname420 avatar screenname420 says:

    DO NOT PLAY THERE… PERIOD,.. END OF STORY…

    #1) THEY DIDN’T CARE ABOUT YOUR PROTECTION WHEN DESIGNING THE SOFTWARE

    #2) THERE IS A HUGE SECURITY LEAK. THEY SAY THEY FIXED IT. AND IT’S NOT FIXED.

    #3) THESE PEOPLE ARE MURDERING CRIMINAL BLOOD DRINKERS. DO NOT SEND ONE MORE CENT OF ANY MONEY TO THEIR SERVERS.

    THEY DONT GIVE A SHIT ABOUT YOU
    THEY DONT CARE IF THEIR SOFTWARE LOOKS LIKE A 3 YEAR OLD GIRL MADE IT
    THEY DONT CARE ABOUT YOUR SAFETY.
    THEY NEVER CARED TO BEGIN WITH.
    DO NOT SEND THEM ANY MORE MONEY.

    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!
    BOYCOTT, REVOLUTION TELL THOSE MURDERERS WE WILL NOT SUPPORT THEM ANY MORE!!!!

  35. jaxdiamond avatar jaxdiamond says:

    Have we heard from Annie Duke or Phil Hellmuth lately?

  36. hoku10 avatar hoku10 says:

    I just love the personalized letter from the CEO with his full-on boss assurance that this issue be fixed in a matter of hours through his crack team of amateur programmers. What salvation!

    What’s even more funny is how PTR decides to blow up their exposure themselves by getting directly involved, making us all think they are this altruistic mediating party without any ulterior motives. Get REAL.

    ITS ALL ABOUT THE CHEESE!

    Make some news and splash around. Nice one PTR, grab everyone by the balls.

  37. cbart_05 avatar cbart_05 says:

    hoku u must of listened to the poker cast

  38. probability avatar probability says:

    thanks again for doing this.

  39. Cleaner44 avatar Cleaner44 says:

    igdoof is right. Everyone is free to make their own choice. Let the free market decide where they want to take their business. I will not be giving my rake to Cereus.

  40. racenutalways avatar racenutalways says:

    I am not one to blame sites, just the ineptitude of bad players. But when ones winrate goes form winning player over 18 months, then joining the Cereus network and winrate drops 8X as compared to other sites (over 200k hands). There is something truly wrong in the software and I will be not coming back to Cereus. Can’t trust them. Period!!!!

    Not sure why people are jumping on PTR’s throat, they are our voices. If all you can do better, please audit the software and post it in your bloody site.

  41. m4rkym avatar m4rkym says:

    I haven’t played on the site since the potripper scandal.ABSOLUTE NO CHANCE I WILL EVER PLAY ON IT AGAIN.

  42. n3wj0k3c1ty avatar n3wj0k3c1ty says:

    It looks like they just updated the site not sure if this is for the ssl issue

  43. Daryle avatar Daryle says:

    Cereus is a rip you can play pennys 1 day and profit 12 bucks. Thats a 300 big blind profit. The next session its like a suck out city on your ass. Change tables no problem the suck outs follow, then the tilt factor kicks in, then more suck outs and then your pissed at your girl cause all your pennys are gone. Sorry cereus, you lost. Stop dumping files on my desk top. Stop booting me off when I am running hot. Stop dealing me AK they never hit. I am not mad about losing $180 I have spent more on a round of golf. I am pissed that I see the same group of players playing 8 hours at a time. Then the next group show up for their 8 hour shift. But they never play at the same time. hmmm. (could workers be playing?) I live in California where card games are legal and slots are not. So Cereus get real and stop acting like you shit is legit.

  44. Daryle avatar Daryle says:

    woops 600 no wounder i lose. lol

  45. Daryle avatar Daryle says:

    I was a littly tilty when I wrote this sorry about the typo’s. But I have been booted a couple of times on streaks and their program has dumped files on my desk top. Some times while I am in a game at a table and I check the cashier it has asked me to sign back in. That seems to happen alot. I like UB they just need to get it together.

  46. KoldShadow avatar KoldShadow says:

    LOL, so much strife here from people that obviously deposited on a network with security/fidelity issues and HORRIBLE software (at least Absolute) . . . I FEEL SORRY FOR YA’LL! NO DEPOSIT BONUSES FTW!!!!!! X-D X-P X-D

  47. killer108 avatar killer108 says:

    the question now is , is ub poker save now or still not.
    PTR goes to do more tests?

    thks

  48. foldilocks avatar foldilocks says:

    Why would it matter if a site that cheats has SSL anyway

Leave a Reply

You must be logged in to post a comment.

Latest News
» Hands Tracked:
18,715,417,873
» Tables Watched:
3,130
By Lee Murphy 2 weeks ago
By Lee Murphy 3 weeks ago
By Lee Murphy 1 month ago
PTR_Dameon: PartyPoker Challenge II Winners Announced ...
3 months ago
PTR Wall
tevtonik is up $5,707 today
7 minutes ago
E1ephant is up $5,482 today
20 minutes ago
nd2wtch commented on channti
20 minutes ago ·More info
Reg commented on captivater
20 minutes ago ·More info
VictorBloomCunt commented on !p0krparty¡
21 minutes ago ·More info
Hildburg V (Deep, Ante, 6 max) $100/$200 PL (6 max) has opened on PokerStars
1 hour ago ·More info
Lampetia V (Deep, Ante, 6 max) $100/$200 PL (6 max) has opened on PokerStars
2 hours ago ·More info
YOU_OWE_ME won a $10,540 pot with ASpadeAClub
4 hours ago ·More info
herbert_1974 won a $10,749 pot with QSpadeJDiamond
4 hours ago ·More info