A hacker managed to break into the system of a vending machine located in the courtyard of a university. The vending machine was using its own app as a payment method, which the hacker successfully breached.

The vending machine is from Argenta, a fairly popular coffee company in Italy. Its vending machines are located in thousands of locations across the country, selling everything from soft drinks to cigarettes. It has its own app for users to pay, which uses BLE (Bluetooth Low Energy) and NFC (Near Field Communication) to allow smartphones to communicate with the vending machine.
Italian Matteo Pisani decompiled the application and made it debuggable. After recompiling it, he installed it on his mobile phone and watched how it worked. What he soon noticed was that the application was using a database, and databases always hold valuable information.
Pisani located the database named argenta.db, which he transferred to his computer. However, he initially couldn't access it because the database was password-protected. Upon re-checking the application code, he discovered that the password for the database was the unique IMEI code of each device.
The database contained several tables, but what caught Pisani’s attention was a table called “UserWallets.” From the name alone, we can understand that this table contains the balance of each user. He created his own mobile application that changes the available balance with just a few clicks, and he even filmed a video demonstrating its operation.
Pisani contacted the company and informed them of the major security flaw he had identified in their app. A month later, he published the video and the steps he followed.
