I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.
I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny Eaton • Dec 19, 2024 Copy Link Share Discussion links: Reddit | Hacker News Thank you to the Reddit netsec community for making this the most upvoted post of 2024 with 300k+ views ! 🏆 News coverage: TechCrunch Verdict Food Service SecurityWeek Heise (German) WinFuture (German) TechRadar Want to watch a video version? Check out this great video by LowLevelTV covering this disclosure. Key Points / Summary API flaws in the McDonald’s McDelivery system in India, one of the world’
Explore this link on the map →saved by
related reading
- They Hacked McDonald’s Ice Cream Machines—and Started a Cold War | WIREDwired.com
- Riley Walzwalzr.com
- The Indytheindy.org
- Doordash and Pizza Arbitragereadmargins.com
- Turbo MCPmcp.run
- GitHub - mc2-project/mc2: A Platform for Secure Analytics and Machine Learning · GitHubgithub.com
- 星箭廣播 - Podcast on Firstorypodcast.starrocket.io
- APIs All the Way Down - Not Boring by Packy McCormicknotboring.co
- McMaster-Carrmcmaster.com
- POS Systems | Point of Sale Systems for all Businesses | Squaresquareup.com
- Brooklyn Bagel & Coffee Company Menudirect.chownow.com
- GitHub - plaid/pattern: An example end-to-end Plaid integration to create items and fetch transaction data · GitHubgithub.com