flâneur — a map of the web's best reading

I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny

eaton-works.com · 3,751 words · saved by 1 readers

A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people’s delivery orders, view user information, and more.

I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny Eaton • Dec 19, 2024 Copy Link Share Discussion links: Reddit | Hacker News Thank you to the Reddit netsec community for making this the most upvoted post of 2024 with 300k+ views ! 🏆 News coverage: TechCrunch Verdict Food Service SecurityWeek Heise (German) WinFuture (German) TechRadar Want to watch a video version? Check out this great video by LowLevelTV covering this disclosure. Key Points / Summary API flaws in the McDonald’s McDelivery system in India, one of the world&#8217

Explore this link on the map →

saved by

related reading