Technology

McDonald’s pays off security researchers cheaply

A security researcher has discovered serious vulnerabilities in the McDelivery system of the fast food chain McDonald. He was able to view other people’s orders, manipulate prices and order mass quantities of products for just one cent.

Fatal security gaps at McDonald

Security researcher Eaton Zveare has uncovered massive vulnerabilities in McDonald’s McDelivery delivery system in India and explained exactly how in his blog could have triggered masses of incorrect orders. So much in advance: The extent to which these security gaps also appeared in other countries is currently unknown. McDonalds has already reacted and closed the vulnerabilities. The researcher’s discoveries are definitely alarming. By simply changing IDs in the URL, he was not only able to gain insight into third-party orders, but also manipulate them at will.

Exploitation of BOLA vulnerabilities

The security expert exploited so-called BOLA and Broken Object Property Level Authorization vulnerabilities. These gaps made it possible to access data that was not actually intended for the respective user due to a lack of authorization. The researcher demonstrated the vulnerability by ordering 100 hash browns – McDonald’s popular potato pancakes – for just one cent. In order not to cause any actual damage, he immediately canceled the order.

According to Eaton Zveare, with the right timing it would also have been possible to redirect orders from other customers that had already been paid for. An attacker could theoretically have received a menu that was paid for by another customer – without the latter initially noticing the manipulation. This is not the first time that McDonald’s has faced safety issues. Back in 2017, a data breach at McDelivery made headlines in which personal customer data unintentionally became public.

McDonald’s response

McDonald’s responded quickly to the security researcher’s report – all discovered vulnerabilities have now been fixed. As a thank you, the expert received an Amazon voucher worth 240 US dollars (around 231 euros). However, his proposal to receive a “Gold Card” for free food for life at McDonald was rejected.

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

19 hours ago

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose…

19 hours ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

19 hours ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

19 hours ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

19 hours ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

19 hours ago