In past few days, we have been listening about a number of bugs being reported in the Indian tech startups. Started with the Ola hack, which allowed people to recharge Ola wallets without having to actually pay, another post written by Shivani Maheshwari on Medium showing how she tricked the ZopNow payment gateway to order products for which didn’t pay got people attention. However, ZopNow’s response was quick and it fixed the issue in just 8 hours.
This time there is another startup which has been dragged into this and it is Rocket Internet backed FoodPanda. Few students from IIIT Hyderabad found a bug that allowed foodpanda users to get orders delivered without making the payment. The bug was reported by a startup called Brthe in a medium post.
How does that work, you say? Here it goes:
- Build your order as you’d usually do, use the coupon code ‘welcome’ which is only applicable for new users and check out
- Fill out the details and click on the payment options. PayUMoney is the preferred option for this as it offers an additional discount
- When you are at the final payment page, hold on for a while without closing the tab or making the payment
- Within seconds you’ll receive a message from FoodPanda stating your order has been placed.
- Click on the “back to foodpanda.in” button
- Voila! You’re food shall be delivered.
“We at Brthe have a chrome extension that prompts the most suitable coupon to let you order food at the best possible price and have a good user base in IIIT-H. It was the evening of April 8th, we noticed our chrome extension getting abnormally large traffic. When we checked on this, the news about the bug was spreading through IIIT hostels like wild fire. Each person went on to fulfill their food fantasies. After all free food does taste better. The fanciest desserts from Baskin Robins and the largest pizzas were from Papa John’s were ordered. Delivery boys queued up outside the campus for hours after the gates closed. According to the students, orders worth over 6 lakhs were placed,” said the company in a blogpost.
Well in response to this, rather than resolving the issue, foodpanda first shutdown services in Hyderabad, and later restricted the shutdown to the Gachibowli area where IIIT Hyderabad is located.