Security Vulnerability in McDonald's India allows hackers to access Customer data
If you are from India and have ordered Burger in McDonald's, your personal details are at risk. Security researchers from Fallible foung a serious vulnerability McDonald’s India application that allows hackers to access millions of customer data. There is no authentication or authorization check in API used in the application. Sending request to "http://services.mcdelivery.co.in/ProcessUser.svc/GetUserProfile" with customer id in the header allows to access customer details. The customer id is a sequential number. All an attacker needs to do is create a script and increase the number to dump all customer data. "The lack of strong data protection and privacy laws or penalties in India, unlike the European Union , United States or Singapore has led to companies ignoring user data protection" The researcher said. "We have in the past discovered more than 50 instances of data leaks in several Indian organizations." The researcher said. The vul...