Choose your campus

Just like the real app's first screen. Tip: you don't actually need to pick the right one β€” the servers happily tell us which campus an ID belongs to (Finding F-ENUM), and this clone auto-reroutes.

Log in

Campus: β€”

πŸ”¬ Recovery tool β€” no inbox needed F-ATO

The OTP is 4 digits (10,000 possibilities) and the server never locks the account β€” 30 wrong codes were live-proven to change nothing. This tool paces verification attempts (host-authorized), stops the instant one succeeds, and never floods: response-driven, capped in-flight requests. It demonstrates complete account takeover of any ID with nothing but the ID itself.

Hello πŸ‘‹

What are you craving today?

πŸ›’ Your cart

β€”

Real subtotal (menu prices)β‚Ή0
πŸ”¬ AMOUNT YOU DECLARE TO THE SERVER F-PRICE

The server charges whatever the client puts in total. It never re-checks it against the menu. Change it and watch the order record. (Defaults to the honest price β€” leave it for a normal order.)

Order placed πŸŽ‰

The server created this order from your cart β€” without a single credential.

ORDER ID
β€”
INTERNAL
β€”
ITEMS
β€”
STATUS
unpaid
MENU PRICE
β‚Ήβ€”
SERVER RECORDS
β‚Ήβ€”
πŸ”³ Your order QR

Generated entirely inside this page by a from-scratch QR encoder (no libraries) β€” same as the real app's counter-scan code.

πŸ’³ Pay β‚Ήβ€”

If checkout says the order wasn't found, the key belongs to another campus β€” try the next one.

🧾 Orders

Your order history, straight from the server.

πŸ”¬ Open ANY user's order history F-BOLA

The Get Orders command checks nothing but the user_id you type. Live-proven earlier: the test ID's full history (β‚Ή325 paid order included) came back on a fresh connection with no login. Type any ID β€” on the test account only for this demo.

πŸ“¦ Packages & usage

The app's subscription / package screen β€” served by the same unauthenticated socket.

πŸ‘€ Profile

What the server handed over at login.

CAMPUS
DEVICE ID
β€”
CRYPTO
β€”
AES KEY
loading from secret… served from secret
πŸ”³ Login deep-link QR

The QR the One-GITAM bridge can consume to log in as this user β€” generated in-page.

πŸ”” Notifications

Live socket room for your account β€” joined automatically at login (watch πŸ“‘ telemetry).

No notifications yet. Anything the server pushes to this room lands here live.

πŸ”Ž Security findings

Every card below is live-proven on the host-authorized test account. Tap Prove it to run the proof again β€” right here, right now, through the same pipes this app uses.

πŸ“‹ Disclosure tracker (this session)

Everything this clone did on the live servers while you used it β€” copy this into the disclosure section of the report.

β€” nothing yet β€”

🍚 Mess card β€” no-auth replica

A faithful re-implementation of the real app's mess-card screen. Every value below arrives live from the unauthenticated API β€” type any user_id and all three campus servers are checked in parallel. NO LOGIN Β· NO OTP

Subscription lookup by bare user_id

Meal windows & statuses follow the same rules the app applies (server flags via get usage Β· Breakfast 7:00–9:00 Β· Lunch 11:30–14:00 Β· Snacks 16:30–18:00 Β· Dinner 19:00–21:30). The gate QR shown for a scan-now meal is assembled exactly like the real app builds it β€” in the browser, unsigned (finding F-QR).

πŸ“‘ Live socket telemetry EVERY COMMAND β€” ZERO AUTH

🍽️ G-Diner β€” security research clone

A single HTML file that is the app: log in with OTP, browse real menus, place real orders, get the QR, pay through the real Razorpay checkout β€” while surfacing every security finding live as you go.

  • It speaks the real protocol (AES-256-CBC envelope + Socket.IO) to the live campus servers.
  • No token, cookie or credential is ever attached β€” none exists. That is the finding.
  • Use only the host-provided test account, inside the authorized window.
  • Real money can move in the Razorpay step β€” the app asks before opening checkout.

Note: in sandboxed previews network + popups are blocked β€” download this file and open it in a normal browser for the live demo.