API flaws in McDonald’s McDelivery system in India allowed exploits such as ordering food for ₹1 ($0.01 USD), hijacking/redirecting delivery orders, accessing sensitive driver information, and downloading order details and invoices. These vulnerabilities, discovered by the author in an attempt to enhance food industry security, were reported and efficiently addressed through McDonald's India’s bug bounty program. The fixes were implemented server-side, ensuring that the system is now secure for users.

18m read timeFrom eaton-works.com
Post cover image
Table of contents
Key Points / SummaryThe McDelivery systemWalking through the archesGolden reviewsMapping a deliveryCheck, pleaseCreating an accountThe big bite: Ordering anything for a pennyStealing someone else’s orderAdmin panelTimelineUnofficial FAQ for McDelivery users
3 Comments

Sort: