Just like the real app's first screen. Tip: you don't actually need to pick the right one β the servers happily tell us which campus an ID belongs to (Finding F-ENUM), and this clone auto-reroutes.
Campus: β
The OTP is 4 digits (10,000 possibilities) and the server never locks the account β 30 wrong codes were live-proven to change nothing. This tool paces verification attempts (host-authorized), stops the instant one succeeds, and never floods: response-driven, capped in-flight requests. It demonstrates complete account takeover of any ID with nothing but the ID itself.
What are you craving today?
β
The server charges whatever the client puts in total. It never re-checks it against the menu. Change it and watch the order record. (Defaults to the honest price β leave it for a normal order.)
The server created this order from your cart β without a single credential.
Generated entirely inside this page by a from-scratch QR encoder (no libraries) β same as the real app's counter-scan code.
If checkout says the order wasn't found, the key belongs to another campus β try the next one.
Your order history, straight from the server.
The Get Orders command checks nothing but the user_id you type. Live-proven earlier: the test ID's full history (βΉ325 paid order included) came back on a fresh connection with no login. Type any ID β on the test account only for this demo.
The app's subscription / package screen β served by the same unauthenticated socket.
What the server handed over at login.
The QR the One-GITAM bridge can consume to log in as this user β generated in-page.
Live socket room for your account β joined automatically at login (watch π‘ telemetry).
Every card below is live-proven on the host-authorized test account. Tap Prove it to run the proof again β right here, right now, through the same pipes this app uses.
Everything this clone did on the live servers while you used it β copy this into the disclosure section of the report.
β nothing yet β
A faithful re-implementation of the real app's mess-card screen. Every value below arrives live from the unauthenticated API β type any user_id and all three campus servers are checked in parallel. NO LOGIN Β· NO OTP
Meal windows & statuses follow the same rules the app applies (server flags via get usage Β· Breakfast 7:00β9:00 Β· Lunch 11:30β14:00 Β· Snacks 16:30β18:00 Β· Dinner 19:00β21:30). The gate QR shown for a scan-now meal is assembled exactly like the real app builds it β in the browser, unsigned (finding F-QR).
A single HTML file that is the app: log in with OTP, browse real menus, place real orders, get the QR, pay through the real Razorpay checkout β while surfacing every security finding live as you go.
Note: in sandboxed previews network + popups are blocked β download this file and open it in a normal browser for the live demo.