JavaScript is turned off in your web browser. Many features of this website depend on you having Javascript turned on, please enable it in your browser settings.

Main » Articles, Security

PTR Security Alert: Cake Poker Uses Weak Encryption

By dameon - July 26th, 2010


Game Security

Cake Poker Network uses weak encryption, poor security practices.

Release Date 2010-07-26
Last Update 2010-08-04
Severity Critical
Impact Exposure of sensitive information
Where Network access required
Solution Status None
Poker Sites Cake Poker, Cake Poker (beta), Doyle’s Room, RedStarPoker.com, Unabomber Poker, Intertops Poker, Sports Interaction



Description:
The Cake poker network uses a weak xor based encryption mechanism for all network transmissions instead of the industry standard SSL. The encryption key is sent in plain text and can be used to dump data from the datastream to the cake client application.

In our lab we are able to intercept and decode the user’s login name (e-mail address), screen name, and password in plain text, as well as their seat number and hole cards. We’ve also been able to remotely display all seat numbers and hole cards on a compromised network.

All proof of concepts have been shown to work over a compromised WPA2 encrypted wireless network as well as unencrypted wireless networks, and physical network access (either through a hub, ARP man in the middle attack, or otherwise).

Solution

Vendor has been notified of the vulnerability and advised to upgrade their software to use the free open source OpenSSL library. No solution available from Cake as of yet.

User Recommendations

PTR recommends that you discontinue using the Cake network until this issue is addressed.

If you continue to play on Cake PTR recommends that you physically plug into your modem and bypass any switch, router, wireless network or other network device. We do not recommend playing on any unknown network connections.

Update 2010-08-04: Cake poker version 1.0 client has added SSL support. Beta client has not added SSL support, nor have most/all of the skins. Please check for ssleay32.dll in the installation directory of your skin to see if it is safe to play on.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • StumbleUpon

6 Responses to “PTR Security Alert: Cake Poker Uses Weak Encryption”

  1. Barthold avatar Barthold says:

    Wow that’s big, glad I’m not part of their community. They have to fix this, good work PTR!

  2. Boohaa avatar Boohaa says:

    no wonder they dont like hh, datamining, hm, ptr etc

  3. RabbitFish72 avatar RabbitFish72 says:

    Ok, what site is next? :D

  4. floser1 avatar floser1 says:

    hopefully one day the ‘curse of withdrawal’ theory will be proven somehow too and all the population will say “i knew it”

  5. webhocke4 avatar webhocke4 says:

    are there any legit sites anymore? wtf? i try not to but into the theory that all online poker is rigged, but how many more sites will be exposed. whats next all ftp pros have the ability to see the flop turn and river cards when they play? lol

  6. danny avatar danny says:

    can tableratings do a poker is or isn’t rigged article with some graphs and charts “proving it” please! How bout show the ai ev of 40+ vpip players on stars.

    also i hope you guys arnt paid by stars or ftp

Leave a Reply

You must be logged in to post a comment.

Latest News
» Hands Tracked:
18,715,417,873
» Tables Watched:
4,099
By Lee Murphy 2 weeks ago
By Lee Murphy 2 weeks ago
By Lee Murphy 4 weeks ago
PTR_Dameon: PartyPoker Challenge II Winners Announced ...
3 months ago
PTR Wall
GabrielMoyaa is up $12,881 today
4 minutes ago
spielie commented on admirales
10 minutes ago ·More info
tilted247365 commented on jojojoma
19 minutes ago ·More info
bLightLV commented on timothytheman
19 minutes ago ·More info
fiat_100 won a $12,681 pot with 7ClubKDiamond5DiamondKSpade
3 hours ago ·More info
P.Turgeon won a $11,135 pot with KDiamondAClub6Diamond7Club
3 hours ago ·More info
P.Turgeon won a $15,110 pot with KDiamond8Club4Diamond7Diamond
4 hours ago ·More info