The researcher figured out the following (pasted from the blogpost):
The ability to order any number of menu items for ₹1 ($0.01 USD).
The ability to steal/hijack/redirect other people's delivery orders through a specific sequence of carefully timed API calls.
The ability to retrieve the details of any order.
The ability to track any order in the "On the way" status. You could real-time track the location of the driver for any order.
The ability to download invoices for any order.
The ability to submit feedback for orders that are not your own.
The ability to view admin KPI reports.
Sensitive driver/rider information that could be accessed:
Name
Email address
Phone number
Vehicle license plate number
Profile picture
Saar please take this amazon giftcard I stole from your mother saar
The post is very boring as the techniques used were very basic. I'm not calling the researcher garbage, I'm saying that their website was very poorly setup.
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
*indian franchisee of major corporation developing local software using local "talent"
Jump in the discussion.
No email address required.
More options
Context
It's rough when you have thousand or tens of thousands of developers, one dumb team can cause something like this
Jump in the discussion.
No email address required.
Combination of r-slurred PM and not my problem atmosphere.
Jump in the discussion.
No email address required.
Too common sadly, we could probably make better products with 1/3 of the headcount if everyone cared
Jump in the discussion.
No email address required.
!kino !music
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context
Especially if you buy the cheapest of the cheapest
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context