{"id":206,"date":"2011-07-08T00:01:31","date_gmt":"2011-07-07T14:01:31","guid":{"rendered":"http:\/\/www.reenadu.com\/?p=206"},"modified":"2011-07-08T00:01:31","modified_gmt":"2011-07-07T14:01:31","slug":"dominos-pizza-5-95-mobile-ordering-site-exploit","status":"publish","type":"post","link":"https:\/\/nickdu.com\/?p=206","title":{"rendered":"Domino&#8217;s Pizza $5.95 mobile ordering site exploit"},"content":{"rendered":"<p><a href=\"http:\/\/www.dominos.com.au\/\" target=\"_blank\">Domino&#8217;s Pizza<\/a> has new mobile ordering site, and any value or traditional pizza only $5.95 each pick up.<br \/>\nThis deal is for mobile user only. It will re-direct non-mobile user to normal online ordering site, and the price jumps up to $7.95.<\/p>\n<p>From technical perceptive, how does Domino&#8217;s server determine a mobile user? Normally a web request contains &#8220;<em>User-Agent<\/em>&#8221; to help web server tell who is visiting. This is a typical example of web request. If we change the &#8220;<em>User-Agent<\/em>&#8221; content, we can cheat domino&#8217;s web server and order $5.95 pizza.<\/p>\n<p style=\"padding-left: 30px;\">GET \/ HTTP\/1.1<br \/>\nHost: www.dominos.com.au<br \/>\n<span style=\"color: #ff0000;\">User-Agent: Mozilla\/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.18) Gecko\/20110614 Firefox\/3.6.18<\/span><br \/>\nAccept: text\/html,application\/xhtml+xml,application\/xml;q=0.9,*\/*;q=0.8<br \/>\nAccept-Language: en-us,en;q=0.5<br \/>\nAccept-Encoding: gzip,deflate<br \/>\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br \/>\nConnection: keep-alive<\/p>\n<p>OK, let&#8217;s do it!<\/p>\n<ol>\n<li>Download <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/user-agent-switcher\/\" target=\"_blank\">user agent switcher<\/a> for your <a href=\"http:\/\/www.mozilla.com\/en-US\/firefox\/new\/\" target=\"_blank\">Firefox<\/a> and install.<\/li>\n<li>Change user agent to iPhone<\/li>\n<li>Star ordering from <a href=\"http:\/\/dominos.com.au\/mobile.aspx\" target=\"_blank\">http:\/\/dominos.com.au\/mobile.aspx<\/a> and enjoy $5.95 pizza<\/li>\n<\/ol>\n<p style=\"padding-left: 60px;\"><a href=\"http:\/\/www.nickdu.com\/wp-content\/uploads\/2011\/07\/mobileordring.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-209\" title=\"mobileordring\" src=\"http:\/\/www.nickdu.com\/wp-content\/uploads\/2011\/07\/mobileordring-196x300.jpg\" alt=\"\" width=\"196\" height=\"300\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Domino&#8217;s Pizza has new mobile ordering site, and any value or traditional pizza only $5.95 each pick up. This deal is for mobile user only. It will re-direct non-mobile user to normal online ordering site, and the price jumps up to $7.95. From technical perceptive, how does Domino&#8217;s server determine a mobile user? Normally a &hellip; <a href=\"https:\/\/nickdu.com\/?p=206\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Domino&#8217;s Pizza $5.95 mobile ordering site exploit&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,8],"tags":[],"class_list":["post-206","post","type-post","status-publish","format-standard","hentry","category-it","category-web"],"_links":{"self":[{"href":"https:\/\/nickdu.com\/index.php?rest_route=\/wp\/v2\/posts\/206","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nickdu.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nickdu.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nickdu.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nickdu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=206"}],"version-history":[{"count":0,"href":"https:\/\/nickdu.com\/index.php?rest_route=\/wp\/v2\/posts\/206\/revisions"}],"wp:attachment":[{"href":"https:\/\/nickdu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=206"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nickdu.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=206"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nickdu.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=206"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}