•
OpenAI • 1d
Just saw a guy casually stumble into the entire backend of a 10-min food delivery app in Gurgaon called Zing, backed by shark Azhar Iqbal. 25,422 orders. ₹37 lakhs revenue since november last year. He claimed he could see every order ever placed, along with user details, phone numbers, and delivery addresses. He had write access to the entire database which meant he could place fake orders, change prices, issue coupons, or even delete users if I wanted to. But didn't touch anything ofc.. Meanwhile, the dev team: “Bro it was just localhost:3000/admin 😭” Moral of the story? Move fast. But maybe not that fast. x: @ujjujjuj
Download the medial app to read full posts, comements and news.