Free food bug done by burp suite

Disclosed: 2019-12-26 12:48:10 By joker7889 To zomato
None
Vulnerability Details
> NOTE! Thanks for submitting a report! Please replace *all* the [square] sections below with the pertinent details. Remember, the more detail you provide, the easier it is for us to verify and then potentially issue a bounty, so be sure to take your time filling out the report! **Summary:** [By this Vulnerability we can get free food] **Description:** [This vulnerability is done by paytm wallet] **Platform(s) Affected:** [www.Zomato.com] ## Browsers Verified In [If Applicable]: * [Chrome and version 79.0.3945.88] ## Steps To Reproduce: 1. [REQUIRMENTS 1.PC/LAPPY 2.os Kali 3.burp pro 4. paytm wallet] 2. [setup burpsuite create zomato id make your cart go to checkout selet paytm wallet option] 3. [turn on intercept refresh the page go on params section do a transaction of any low amount first and capture checksum key copy and save it] 4.[After copying that go to site and add some food to your cart make your food cart ready And go to payment page and refresh the payment page and capture the packets in burp suite] 5.[go to params change the cost value and checksum value + time by the previous one that u saved it and forward the request payment will go successfulll] ## Supporting Material/References: I dont have screenshots sorry ## Impact By this u can Book free food and atacker can enjoy freely
Actions
View on HackerOne
Report Stats
  • Report ID: 762883
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 17
Share this report