some of the worst API security i've EVER seen

some of the worst API security i've EVER seen

Source: YouTube · Low Level · published Jan 25, 2025 · 27:55

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The McDonald's India MCD Delivery app contains critical security flaws enabling unauthorized access, order manipulation, and data exfiltration, including access to driver details and user orders via broken authorization and JWT validation. 0:07

Key Takeaways:
• Broken object-level authorization allows access to any order by manipulating order IDs, enabling viewing, tracking, and theft of others' orders 3:45.
• A guest JWT token is used without backend validation, permitting unauthorized access to order and driver data 6:45.
• A backdoor user creation API allows account creation without verification, granting full system access 11:31.
• A time-of-check/time-of-use vulnerability enables redirecting in-progress orders to different addresses, posing fraud risks 22:01.
• The admin panel can be accessed with a consumer JWT token, exposing sensitive KPIs and driver data 23:47.

The researcher exploited these flaws to order food for one cent and redirect deliveries, demonstrating severe privacy and financial risks—yet the report was resolved within 90 days with a $240 Amazon gift card awarded. 26:16

Sources:

  • 0:07 Discussion of API flaws and user data exposure in MCD Delivery.
  • 3:45 Discovery of broken object-level authorization in order tracking.
  • 6:45 JWT token misuse without backend validation.
  • 11:31 Backdoor user creation API enabling unverified account acc

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

exploiting McDonald's apis to hijack deliveries and order food for a penny API flaws in the McDonald's M delivery system in India one of the world's most popular food delivery apps that is lowkey concerning I I am shocked that it's that popular in India I feel like people in India like are fairly healthy and I I I feel like if you're eating McDonald's exclusively you are you are not going to be that way for a long time so variety of fun exploits the ability to order any number of food items for one rupe which is one US Cent the ability to steal hijack redirect other people's deliveries through a specific sequence of carefully timed API calls retrieve details of any order track the order in the on the way status download invoices for any order submit feedback for orders that are not your ow…