Massive Breach in Panera Bread
pastebin.com
pastebin.com
I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)
e-mail me at daniel_kats [at] symantec [dot] com
EDIT: please do not post your method publicly. That is a bad idea.
Hopefully they will publicly acknowledge.
Access Denied
You don't have permission to access "http://www.panerabread.com/" on this server.
Reference #18.96d8f648.1522702964.2a61eebf
The Web Archive can access it just fine though: https://web.archive.org/web/20180402210155/https://www.paner...Do this until they plead mercy. Are they? No they aren't yet!
Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?.
Wouldn't be much better to talk with Panera Bread directly?
I bet this vulnerability was open for years.
1.) Take down site for 2 hours 2.) Require logins to access api. 3.) Get on fox news and say it's "fixed" ... then we come to find out you can still access all data from the API once you login
Why would you assume a security researcher who put in that much effort and kept the pastebin mostly anonymous didn't put in the effort to contact Panera Bread?
Is there a reason you automatically assume that the security researcher is irresponsible, but companies, who almost daily, have data breaches, are responsible in these scenarios?
"Hey, maybe you should contact the company?!" Thank you captain fucking obvious.
Because there is not data that specifies the opposite in the link (and extra info was lacking when I wrote it), thus is a reasonable and logical first thing to check.
> Is there a reason you automatically assume that the security researcher is irresponsible...?
Please, don't put words in my mouth. I didn't called irresponsible anybody and I didn't automatically assume anything. To be honest, I couldn't care less about who, if one, has the responsibility here. I'm trying to learn something. Not more, not less.
Captain fucking obvious is a nice title. We'll have a safer world when people start paying notice to a lot of fucking obvious and boring things. This reminds me a lot to the outrageous lexNET case (that was much, much, worse than internet knowing who has a sweet tooth for buns).
Disclosing this as such was irresponsible, despite being an important discovery.
Good work, in any case.
Anyone can download a MITM proxy on their phone and replay HTTP/HTTPS calls.
How so? Is allowing a company a chance to patch a bug a responsibility that random people have to a company? What do those people get in return? Some companies will go as far as accusing the reporter of hacking them.
I might even go as far to say that if companies expect to be told of bugs and not have the information released to the wild, they will be less concerned with security because they can always patch the bugs as they come and perform the smallest disclosure they know of. Such an idea of 'responsible disclosure' may lead to less security overall.
Perhaps the responsible thing is reporting the breach to the public because they are the ones most hurt by it, so they can take immediate corrective actions.
The caveat, of course, is that the poster should definitely have first attempted to contact Panera. I would not be surprised at all if Panera responded by doing absolutely nothing, which eventually led to this post.
Not even once.