Loading HuntDB...

Free food bug done by burp suite

None
Z
Zomato
Submitted None

Team Summary

Official summary from Zomato

We're doing a public disclosure of this since we have received similar reports with the same title and content without any evidence regarding the vulnerability. Also, after the investigation, it was found that ~~security researchers~~ lot of folks bought this ~~vulnerability~~ from Telegram and started submitting it to us without any POC and proof of the exploitation. {F668942} Going forward, any such submissions will be marked as spam. Nevertheless, we encourage reports which can help us build a secure trustworthy platform for our users. Happy Holidays and Happy Hacking!! Zomato Security Team

Reported by joker7889

Vulnerability Details

Technical details and impact analysis

Man-in-the-Middle
> NOTE! Thanks for submitting a report! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is for us to verify and then potentially issue a bounty, so be sure to take your time filling out the report! **Summary:** [By this Vulnerability we can get free food] **Description:** [This vulnerability is done by paytm wallet] **Platform(s) Affected:** [www.Zomato.com] ## Browsers Verified In [If Applicable]: * [Chrome and version 79.0.3945.88] ## Steps To Reproduce: 1. [REQUIRMENTS 1.PC/LAPPY 2.os Kali 3.burp pro 4. paytm wallet] 2. [setup burpsuite create zomato id make your cart go to checkout selet paytm wallet option] 3. [turn on intercept refresh the page go on params section do a transaction of any low amount first and capture checksum key copy and save it] 4.[After copying that go to site and add some food to your cart make your food cart ready And go to payment page and refresh the payment page and capture the packets in burp suite] 5.[go to params change the cost value and checksum value + time by the previous one that u saved it and forward the request payment will go successfulll] ## Supporting Material/References: I dont have screenshots sorry ## Impact By this u can Book free food and atacker can enjoy freely

Report Details

Additional information and metadata

State

Closed

Substate

Not-Applicable

Submitted

Weakness

Man-in-the-Middle