McDonald's not lovin' it when hacker exposes rotten security
5 Articles
5 Articles
A hacker managed to thwart the security of the McDonald's app with a disconcerting ease. She tells how, from a free nugget's order, she discovered unimaginable flaws for a company of this size. On the spot or to take away?
A white-hat hacker found serious vulnerabilities in McDonald's portals – including free orders and admin access. The researcher working under the pseudonym "Bobdahacker" first discovered a vulnerability in McDonald's online delivery app, as she explains in her blog. The system performed only client-side security checks when querying bonus points – server-side validation did not take place. "You only had to create a corresponding account and it a…
A professional hacker, known as "Bobdahacker," tells how her vulnerability hunt at McDonald's, initiated by a simple command of free nuggets, revealed other security flaws and led to the dismissal of an employee who had agreed to help her. A safety report that takes the stages of an investigation as effective as it is surprising.
Client-side authentication, login via URL change, important API keys in source code and difficult contact
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium