How I Hacked McDonald's (Their Security Contact Was Harder to Find Than Their Secret Sauce Recipe) | bobdahacker (bobdahacker.com)
from cm0002@piefed.world to cybersecurity@infosec.pub on 20 Aug 15:20
https://piefed.world/post/395311

#cybersecurity

threaded - newest

redsand@lemmy.dbzer0.com on 20 Aug 15:32 next collapse

I can’t even summarize this. I’m only half through reading and there are plain text passwords sent via emails and unauthenticated admin panels. This is crazy for a company of this size.

frongt@lemmy.zip on 20 Aug 17:55 collapse

This is all too common for a company of this size. Bigger doesn’t mean better.

mfed1122@discuss.tchncs.de on 20 Aug 16:23 collapse

Really incredible. This is what I imagined hacking stopped being like in 1995. I applaud Bob for having the inner fortitude to not just exploit them for infinite nuggies. The fact someone got fired for it probably contributes to why the security is so bad, corporations truly don’t deserve white hat hackers.

cm0002@piefed.world on 20 Aug 16:48 collapse

I applaud Bob for having the inner fortitude to not just exploit them for infinite nuggies

My literal first thought was "got dammit, why didn't I try that" (I had assumed McD would have rolled out an app with proper server-side validation and never bothered)

I do not have the inner fortitude to not exploit a giant corpo for free nuggies LMAO

redsand@lemmy.dbzer0.com on 20 Aug 17:21 collapse

I’m downloading the android SDK again. Can’t say for sure what I’m going to do with it but I can say for sure you woln’t be reading about client side validated food from me.

cm0002@piefed.world on 20 Aug 17:31 collapse

woln't be reading about client side validated food from me.

I'll make an attempt to call their security department to disclose a security issue to them, but if they can't hear me through my mouth full of nuggies, that's their problem ¯⁠\⁠⁠(⁠ツ⁠)⁠⁠/⁠¯