11 ms·
Massive Breach in Panera Bread
- mr_overalls 9y agoWow, this looks pretty bad.
- pvaldes 9y agoIf in doubt, put a catputer photo. Cats always look fabulous. Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?. Wouldn't be much better to talk with Panera Bread directly?
- deleted 9y ago[deleted]
- sparrish 9y agoApparently he tried talking with Panera directly. First contact was 6 months ago. The vulnerability still exists so he decided to release it publically. I think that's reasonable.
- r00fus 9y agoAnd it's fixed immediately after release. 180 days seems about 90 days more than what major vendors get. I bet this vulnerability was open for years.
- erichurkman 9y agoI certainly have a few open reports to companies that I've been trying to reach for, in several cases, _years_. Or, in other cases, I found something but trying to reach the right person is nigh impossible. security@ bounces, general support is useless, no one responds on linkedin, no one responds to direct emails, pinging them on twitter does nil. Extremely sad.
- ethanwillis 9y agoIt wasn't fixed immediately after release. Apparently all they did at first was: 1.) Take down site for 2 hours 2.) Require logins to access api. 3.) Get on fox news and say it's "fixed" ... then we come to find out you can still access all data from the API once you login
- ctvo 9y agoI'm going to pick on your post a little: Why would you assume a security researcher who put in that much effort and kept the pastebin mostly anonymous didn't put in the effort to contact Panera Bread? Is there a reason you automatically assume that the security researcher is irresponsible, but companies, who almost daily, have data breaches, are responsible in these scenarios? "Hey, maybe you should contact the company?!" Thank you captain fucking obvious.
- pvaldes 9y ago> Why would you assume...? Because there is not data that specifies the opposite in the link (and extra info was lacking when I wrote it), thus is a reasonable and logical first thing to check. > Is there a reason you automatically assume that the security researcher is irresponsible...? Please, don't put words in my mouth. I didn't called irresponsible anybody and I didn't automatically assume anything. To be honest, I couldn't care less about who, if one, has the responsibility here. I'm trying to learn something. Not more, not less. Captain fucking obvious is a nice title. We'll have a safer world when people start paying notice to a lot of fucking obvious and boring things. This reminds me a lot to the outrageous lexNET case (that was much, much, worse than internet knowing who has a sweet tooth for buns).
- bt3 9y agoPerhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.
- pnrabrdthrwy 9y agoTo bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.
- ocdtrekkie 9y agoDid you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached. Good work, in any case.
- pnrabrdthrwy 9y agoI sent this to Krebs and Troy shortly after uploading it.
- technion 9y agoWhilst that does appear to have had the desired effect in this case, I do hope to never find ourselves into the position where "responsible disclosure" includes "consulted with Troy Hunt" as a step.
- mcthorogood 9y agoIt's also possible that Panera would prosecute you for hacking their systems, if they were able to identify you. Better to be safe and disclose anonomyously.
- 9y ago
- mxpxrocks10 9y agoVerified this is legit.
- zcdziura 9y agoOh boy. I just verified this with a few phone numbers of folks that I know personally, and their personal data came back just fine. This isn't good! I hope it's patched ASAP.
- dsl 9y agoVerified the vulnerability, but it looks like they have taken down the API now. Hopefully they will publicly acknowledge.
- CiPHPerCoder 9y agoI anticipated this and made archived copies of the hyperlink referenced in the Pastebin entry in case they tried to pretend there was no leak. https://www.webcitation.org/6yNwbyvu0 https://www.webcitation.org/6yNwbyvu0 https://archive.fo/h9mjp https://archive.fo/h9mjp
- d4mi3n 9y agoAPI seems to be down for maintenance. Nice to see Panera is taking action, sad to hear that this seems to be way, way after the original vulnerability was reported.
- thriftwy 9y agoThat's exactly what you should do when you see a vulnerability. "Internet" "businesses" has proven that they don't understand kind words. Take all those lawsuits, or promises thereof, and shove. Do this until they plead mercy. Are they? No they aren't yet!
- mxpxrocks10 9y agoIt's back online and they're verifying sessions now.
- gtirloni 9y agoAccess Denied You don't have permission to access "http://www.panerabread.com/" on this server. Reference #18.96d8f648.1522702964.2a61eebf The Web Archive can access it just fine though: https://web.archive.org/web/20180402210155/https://www.panerabread.com/en-us/home.html https://web.archive.org/web/20180402210155/https://www.paner...
- jclardy 9y agoThere whole system seemed a bit odd to me, given a password to your "account" is optional. Using the terminal you can login with no password, then at the end it asks you if you want to save your credit card to your account. Maybe it requires a password at that point, but I wasn't going to try.
- CiPHPerCoder 9y agoOh no no no no no please don't tell me that's true D:
- deft 9y agoA similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)
- CiPHPerCoder 9y agoYou probably still could, if they ignored you then chances are they never fixed it.
- papagg 9y agoYou should post your method. I could scrape it for data if you want
- dx034 9y agoYou should contact Troy Hunt or Krebs. They can make that public to get companies to actually change it.
- SoylentOrange 9y agoHey, I work at Symantec Research Labs. If you still have not been able to get this looked at by someone from Denny's, I can probably have the right people take a look. e-mail me at daniel_kats [at] symantec [dot] com EDIT: please do not post your method publicly. That is a bad idea.
- papagg 9y agoAnyone manage to scrape all data? If so please provide a link so it can be archived for a database search tool.
- dx034 9y agoFor non-Americans and as their page is down: What kind of accounts do you have at such a company? I never had an account with a restaurant, why would you use that and store personal information there?
- stevula 9y agoI’m American but I have made accounts with restaurants to order for pickup (or delivery). It’s especially helpful if you eat in an a busy area with long lunch lines. It’s also less error prone having the order in written form than trying to order over the phone. I think most restaurants use a vendor like Yelp for their ordering service, but I guess some big ones like Panera can afford to build one themselves (poorly).