Unable to load image

McDonalds India Gives Researcher A $240 Giftcard (lol) For Discovering These Huge Exploits

https://eaton-works.com/2024/12/19/mcdelivery-india-hack/

The researcher figured out the following (pasted from the blogpost):

The ability to order any number of menu items for ₹1 ($0.01 USD).

The ability to steal/hijack/redirect other people's delivery orders through a specific sequence of carefully timed API calls.

The ability to retrieve the details of any order.

The ability to track any order in the "On the way" status. You could real-time track the location of the driver for any order.

The ability to download invoices for any order.

The ability to submit feedback for orders that are not your own.

The ability to view admin KPI reports.

Sensitive driver/rider information that could be accessed:

  • Name

  • Email address

  • Phone number

  • Vehicle license plate number

  • Profile picture


Saar please take this amazon giftcard I stole from your mother saar

The post is very boring as the techniques used were very basic. I'm not calling the researcher garbage, I'm saying that their website was very poorly setup.

https://i.rdrama.net/images/1737838916DHFTAGqt2a1C1w.webp


53
Jump in the discussion.

No email address required.

Isn't that almost the average Indian's monthly salary tho? :marseysipping:

Jump in the discussion.

No email address required.

I truthfully do not know or care about the finances of a 3rd world :marseyww1german1: country; if you cannot pay researchers properly, then you'll be subject :marseyjurisdiction: to the bottom :marseycheeks: of the barrel


Jump in the discussion.

No email address required.

True, he should've just exploited it to get free food forever

Jump in the discussion.

No email address required.

That's what the next person will do, or rather sell the details on how to do it

Jump in the discussion.

No email address required.

Ah, just checked and apparently he's in the states.


Jump in the discussion.

No email address required.

:marseyxd: fricking McDonalds

Jump in the discussion.

No email address required.



Link copied to clipboard
Action successful!
Error, please refresh the page and try again.