Massive Breach in Panera Bread
41–44 of 44 posts
Re: Massive Breach in Panera Bread
#42Earlier quoted context omitted.
To bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.
Did you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached. Good work, in any case.
Re: Massive Breach in Panera Bread
#43For non-Americans and as their page is down: What kind of accounts do you have at such a company? I never had an account with a restaurant, why would you use that and store personal information there?
Re: Massive Breach in Panera Bread
#44A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)
e-mail me at daniel_kats [at] symantec [dot] com
EDIT: please do not post your method publicly. That is a bad idea.