Remotely Unlocking Electric Scooters

A security researcher details their process for identifying vulnerabilities in an electric scooter company's backend infrastructure. By enumerating subdomains and analyzing JavaScript bundles, the researcher discovered exposed API endpoints and administrative panels.
Why it matters
This highlights the security risks associated with rapidly deployed IoT fleets and the importance of securing backend APIs.
Note: to protect the company, I swapped out anything that could point back to it for fake examples. The domain electricscootercompany.com.br , the app package, and the user details (slug, name, and email) are all made up. None of it matches the real company.
It started with a news article. A company had just dropped a bunch of electric scooters in my city. Most people saw a new way to get around town. I saw a fleet of internet-connected devices running on a backend nobody had poked at yet.
First I needed two things: which company this was, and how the service worked for a normal user. The name was right there in the article, and a quick Google got me to their site, which laid out the flow:
That's the happy path for any user. I wanted to see what was going on behind it.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in