Security researcher driven by free nuggets unearths McDonald's security flaw — changing 'login' to 'register' in URL prompted site to issue plain text password for a new account

McDonalds storefront
(Image credit: Getty / Bernd Obermann)

"Would you like to access sensitive information?" might be the new "Would you like fries with that?" A security researcher called "BobDaHacker" has just revealed how he went from scoring free McNuggets via the fast food chain's mobile app to repeatedly gaining access to a McDonald's platform meant only for employees and franchisees.

"The McDonald's Feel-Good Design Hub is their central platform for brand assets and marketing materials - used by teams and agencies across 120 countries. It used to be 'protected' by a client-side password. Yes, CLIENT-SIDE," BobDaHacker said, an issue he first spotted while trying to use a reward for some free nuggets. "After I reported this, they took 3 months to implement a proper account system with different login paths for McDonald's employees (using their EID/MCID) and external partners ... Except there was still an issue. All I had to do was change 'login' to 'register' in the URL" to create a new account that could access the platform.

Follow Tom's Hardware on Google News to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.

Nathaniel Mott
Freelance News & Features Writer

Nathaniel Mott is a freelance news and features writer for Tom's Hardware US, covering breaking news, security, and the silliest aspects of the tech industry.

  • TechieTwo
    Just your typical negligence and incompetence on display for the world to see.
    Reply
  • JamesJones44
    I doubt MCD has an internal development team, if they do, it's likely not one versed in security. MCD most likely farms that out to a 3rd party vendor (not uncommon in the non-tech industries) and MCD's security architects are asleep at the wheel or consultants themselves with several different clients.
    Reply
  • USAFRet
    JamesJones44 said:
    I doubt MCD has an internal development team
    They have plenty:
    https://careers.mcdonalds.com/technology
    Reply
  • King_V
    Can't say I'm lovin' it...

    (couldn't resist)
    Reply
  • JamesJones44
    USAFRet said:
    They have plenty:
    https://careers.mcdonalds.com/technology
    I have to say that surprises me. I would have expected MCD to farm most of that out like Coke does (Coke does have some internal engineers, but they are more spec writers than guys putting code to keyboard).
    Reply
  • jp7189
    Securing logins to broad, external user base without causing significant friction is hard.
    Reply
  • hwertz
    Given this approach to security, now I'm glad I don't have the McDonalds app,
    Reply
  • Mini0n0
    Doesn't surprise me, Mcdonalds itself has just been a glorified realtor that comes with a prefabricated design for years now. I'm surprised he found anybody, McDs itself only owns the name, logo, distributors and whatever properties they can get for dirt cheap everything else is completely done by whoever buys/rents the property and prefab. There's got to be a completely different 3rd party that runs the web part of the company. And I'm guessing the same company probably also does the sites for BK, Wendys and 100+ other fast food companies since they're all basically ran by the same 5 companies anymore. Subway was basically the last well known one to corporatize... Right where DG is now on the retail side, only a matter of time before they're basically forced into corporatizing.
    Reply