July 8th, 2024

Australians Using Browser Replay Attacks to Get Cheap KFC

Users on OzBargain exploit KFC's system vulnerabilities to buy discounted chicken. Tactics include replay attacks and loophole exploitation. Despite KFC's efforts to patch, users persist in finding new ways for deals.

Read original articleLink Icon
Australians Using Browser Replay Attacks to Get Cheap KFC

Users on the Australian deals website OzBargain have been engaging in a cat-and-mouse game with KFC, exploiting vulnerabilities in the fast-food chain's systems to purchase chicken at discounted prices. One user named Andrew shared a method involving a replay attack on KFC's server requests, allowing users to buy chicken for half its normal price. This tactic is part of a trend where bargain hunters exploit loopholes to secure deals, with KFC being a popular target. Despite KFC's efforts to patch these exploits, users continue to find new ways to access discounted food, such as using older app versions or changing their location. The community on OzBargain sees these hacks not just as a way to save money but also as a demonstration of the "will of the people" in pursuing deals. While KFC has been trying to shut down unauthorized bargains, users remain persistent in their quest for discounted chicken.

Related

Software company plans to pay millions in ransom to hackers

Software company plans to pay millions in ransom to hackers

CDK Global faces a ransomware attack, disrupting operations at 15,000 car dealerships in North America. The company plans to pay hackers millions. The incident exposes the automotive industry's vulnerability to cyber threats.

Snowflake breach snowballs as more victims, perps, come forward

Snowflake breach snowballs as more victims, perps, come forward

The Snowflake data breach expands to include Ticketek, Ticketmaster, and Advance Auto Parts. ShinyHunters claim involvement, Snowflake enforces security measures. CDK faces ransomware attack, Juniper and Apple vulnerabilities identified. Jetflicks operators convicted.

Man makes money buying his own pizza on DoorDash app

Man makes money buying his own pizza on DoorDash app

A US pizza restaurant owner discovered DoorDash selling his pizzas at lower prices without permission. DoorDash conducted a trial without informing owners, sparking scrutiny over its business practices and CEO's controversial remarks.

DoorDash and Pizza Arbitrage

DoorDash and Pizza Arbitrage

The article explores pizza arbitrage, where a restaurant profits by exploiting price differences on Doordash. It critiques food delivery inefficiencies and proposes alternative models for sustainable growth in the industry.

WA man set up fake free WiFi at Australian airports and on flights,police allege

WA man set up fake free WiFi at Australian airports and on flights,police allege

A man in Western Australia was arrested for creating fake wifi networks at airports and flights to steal personal data. He faces cybercrime charges for setting up deceptive networks to collect users' information. Police advise caution and cybersecurity measures.

Link Icon 2 comments
By @ehnto - 6 months
Cheeky buggers.

I'm also aware of an attack/exploit on carpark ticketing systems that people are using to get cheap parking.

I wouldn't call it sophisticated but it does require an understanding of the system above your average punter.

But what is most interesting, is these kinds of exploits seem to be getting found by non-technical people, and while I see all the ways it is easy to trace the exploit back to them, they don't and so to them it's more akin to a videogame exploit. Ie: they can't envision real world consequences from messing with a computer system.

In their defense, they have been getting away with it for two years now.

By @airbreather - 6 months
The ui of the website is such a steaming pile of doo doo (and the app is no better), they sort of ask to be exploited because it's so painful to use.

I just tried to order delivery, because I never had and skipped dinner tonight, started at 9:45. By the time I managed to get an order together, with assorted difficulties, and was actually forced to accept receiving their "opt in" promo offers to be able to complete registration, it was after 10pm and deliveries were closed for the night.

I'm definitely trying to exploit them tomorrow after that experience.