Exploiting McDonald's APIs to hijack deliveries and order food for a penny
eaton-works.com
eaton-works.com
"The reward for a valid bug will be Rs. 2,500/- (Rupees Two Thousand Five Hundred only) in the form of coupons (applicable only in McDonald’s India West & South). Such coupons shall need to be used within the validity period mentioned therein and shall not be, encashable or transferable."
That's less than $30 per bug in non-transferable McDonald's coupons that only work in India, which is thousands of miles away from the bug reporter. Compared to what he thought he would get, a $240 Amazon gift card is a good deal.
No McDonalds is worth a felony.
it reminds me of a mysterious building no one knew the origin or purpose of. someone filled a form for poor cleaning then the message bounced around between a dozen cleaning companies who didn't have a contact for it. after decades a cleaning company filled a form because it didn't have a number and wasn't on the drawings.
* The ability to steal/hijack/redirect other people’s delivery orders through a specific sequence of carefully timed API calls.
* The ability to retrieve the details of any order.
Wait for a target to order something, redirect the delivery to yourself. Then take the order and deliver it yourself to the target. Access granted, and you’ve got a nice fall guy- the original delivery person. IDK, I’m not a criminal, but seems like it could go for more than $240 on the black market.
This is the most amazing thing about this story. Not only did the company not threaten him, they actually fixed the issues.
poor workers yes... but fuck them just constantly adding more things to say and getting you to donate