Advertisement Β· 728 Γ— 90

Posts by BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)

Preview
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - an...

🐱 Found critical vulns in Petlibro smart pet feeders - $500 bounty

-Auth bypass
-hijack any device
-Private audio recordings exposed

They "fixed" it but left the old endpoint up for "legacy compatibility"

bobdahacker.com/blog/petlibro

#InfoSec #BugBounty #IoT #Security #Petlibro #CyberSecurity

3 months ago 4 1 0 0
Preview
Bandsintown: How I Almost Rickrolled 191k People How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send pus...

🎡 Found a verification bypass in Bandsintown - fixed

Used API endpoint to claim any unclaimed artist
Got full access to Rick Astley's 191k followers
Emails, names, push notifs

Could have rickrolled 191k people. I did not.
bobdahacker.com/blog/bandsin...
#InfoSec #BugBounty #Security #CyberSecurity

3 months ago 0 0 0 0
Preview
Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid How I found critical IDOR vulnerabilities in Taimi that exposed

πŸ”“ Found critical vulns in Taimi (LGBTQ+ dating app) - fixed, $10k bounty

- "Expiring" videos didn't expire
- Decrement ID = anyone's private videos

Taimi handled this right. Fast fix, proper bounty.

bobdahacker.com/blog/taimi-i...

#InfoSec #BugBounty #IDOR #Taimi #Security #CyberSecurity

3 months ago 2 1 0 0
Post image Post image

Apparently tons of people registered accounts on tons of platforms with i@hate.you

Not knowing that .you would come to exist in 2025.

Lmfao

5 months ago 1 1 0 0
Preview
i hate you i hate you so much that i made this just for you ❀️

rate my Subdomain on my Domain

i.hate.you

#CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy

5 months ago 6 0 1 0

Check dms πŸŽƒ

5 months ago 1 0 0 0
Post image

Every day, I pray for a world where everyone is kind and respectful of each other, regardless of gender.

May unreasonable attacks against transgender people endπŸ³οΈβ€βš§οΈπŸ³οΈβ€πŸŒˆ

May today be filled with happiness and love for you all🀍

6 months ago 10786 3044 116 82
Preview
I Hacked BellaBot and Every Robot from China's Biggest Robotics Company (Pudu Only Fixed It When I Told Their Clients) Critical vulnerabilities in Pudu Robotics allowed unauthorized control of every Pudu Robotics Robot worldwide. They ignored emails until I contacted Skylark Holdings and Zensho about their compromised...

Hacked every BellaBot & Pudu robot globally. Ignored emails until I told their biggest customers. Fixed in 48hrs after that.

Their response was ChatGPT with "[Your Email Address]" placeholder still in it 😭

Full story: bobdahacker.com/blog/hacked-...

#robotics #security #cybersecurity #infosec

7 months ago 6 2 2 0
Advertisement
Preview
Blog | BobDaHacker Security research, vulnerability disclosures, and tech thoughts

finally caved and added an RSS feed to my blog after everyone kept begging me in DMs 😀

find it yourself at bobdahacker.com/blog
now stop asking me about it lol

#RSS #cybersecurity #blog #infosec #bugbounty #hacker

7 months ago 3 0 0 0

Bruh, that would be illegal. I'm not gonna do illegal things. Also McDonald's gave me nothing.

7 months ago 0 0 0 0
Preview
How I Hacked India's Biggest Dating App (They Offered Me a $100 Gift Card) Flutrr, India's biggest dating app backed by The Times of India, has critical security flaws allowing anyone to access all user data, send messages as anyone, and control any account. They've known si...

Hacked India's biggest dating app Flutrr (backed by Times of India). Every API endpoint is broken - I could read anyone's messages, swipe for them, change their profile. No auth checks anywhere.

bobdahacker.com/blog/indias-...

#cybersecurity #infosec #india #dating #vulnerability #bugbounty

7 months ago 3 1 1 0
When South Park's Restaurant Had Worse Security Than Cartman's Password How I found critical security vulnerabilities in Matt Stone and Trey Parker's Casa Bonita restaurant, exposing customer data, payment info, and their entire POS system - plus how I accidentally got a ...

Hacked South Park's Casa Bonita. Could access their entire POS system and see all customer payments/tips. No security contact anywhere 😬

Fixed fast but never thanked me. Got a Founders Club card 6 months later though πŸ˜‚

bobdahacker.com/blog/i-hacke...

#SouthPark #infosec #hacking #cybersecurity

7 months ago 5 1 1 0
Preview
How I Hacked McDonald's (Their Security Contact Was Harder to Find Than Their Secret Sauce Recipe) How I found critical security vulnerabilities in McDonald's systems affecting millions of employees, and had to cold-call their HQ pretending to know security staff just to report them.

Found huge security flaws in McDonalds: crew members could access corporate sites, API keys exposed. Had to call HQ pretending to know people to report it 🀦

They fixed it but fired my friend who helped

bobdahacker.com/blog/mcdonal...

#McDonalds #hacking #cybersecurity #infosec #bugbounty

7 months ago 10 2 3 0
Preview
Lovense Dan Liu response

@lovense-official.bsky.social
Dan Liu's threat to pursue litigation against @bobdahacker.com is the most ignorant shit I've even seen in my years of #dlp and #cybersecurity.

Plenty of proof of the #vuln, and the lack of response before public disclosure.

www.documentcloud.org/documents/26...

8 months ago 1 1 1 0
BobDaHacker (@bobdahacker@infosec.exchange) Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🀦 What I found: - Email disclosu...

If anyone has mastodon, please boost and favorite this

infosec.exchange/@bobdahacker...

8 months ago 0 0 0 0

butt plug man it was fixed please retweet my latest post on bluesky and twitter thx butt plug man

8 months ago 0 0 0 0

butt plug man it was fixed please retweet my latest post on bluesky and twitter thx butt plug man

8 months ago 0 0 0 0
Preview
Lovense: The Company That Lies to Security Researchers How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.

🚨 Lovense finally fixed their email leak after public pressure

They said: 14 months
Reality: 2 days after going viral

11M+ users at risk for YEARS. Read the full deception: bobdahacker.com/blog/lovense...

#InfoSec #Privacy #CyberSecurity #BugBounty

8 months ago 6 4 1 1
Advertisement

shame on Lovense

8 months ago 0 0 0 0
Post image

x.com/radiantnmyhe...

More people are coming out against Lovense

8 months ago 5 0 0 1

I agree

8 months ago 2 0 0 0
Preview
Lovense: The Company That Lies to Security Researchers How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.

PSA: Lovense products leak your email from just your username. Reported in March, still broken.

Worse: Another Vulnerability was "fixed" in 2023 but wasn't. Company lied to researchers for 2+ years.

Full breakdown: bobdahacker.com/blog/lovense...

#cybersecurity #infosec #bugbounty #privacy

8 months ago 95 58 3 3