I’m Lovin’ It: Exploiting McDonald’s APIs to hijack deliveries and order food for a penny
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
API flaws in McDonald’s McDelivery system in India allowed exploits such as ordering food for ₹1 ($0.01 USD), hijacking/redirecting delivery orders, accessing sensitive driver information, and downloading order details and invoices. These vulnerabilities, discovered by the author in an attempt to enhance food industry security, were reported and efficiently addressed through McDonald's India’s bug bounty program. The fixes were implemented server-side, ensuring that the system is now secure for users.
Table of contents
Key Points / SummaryThe McDelivery systemWalking through the archesGolden reviewsMapping a deliveryCheck, pleaseCreating an accountThe big bite: Ordering anything for a pennyStealing someone else’s orderAdmin panelTimelineUnofficial FAQ for McDelivery users3 Comments
Sort: