//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...









Loading...
Every day, I pray for a world where everyone is kind and respectful of each other, regardless of gender. May unreasonable attacks against transgender people endπŸ³οΈβ€βš§οΈπŸ³οΈβ€πŸŒˆ May today be filled with happiness and love for you all🀍
5mo
🎡 Found a verification bypass in Bandsintown - fixed Used API endpoint to claim any unclaimed artist Got full access to Rick Astley's 191k followers Emails, names, push notifs Could have rickrolled 191k people. I did not. bobdahacker.com/blog/bandsin... #InfoSec #BugBounty #Security #CyberSecurity
9mo
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send pus...
bobdahacker.com
Bandsintown: How I Almost Rickrolled 191k People
Hacked every BellaBot & Pudu robot globally. Ignored emails until I told their biggest customers. Fixed in 48hrs after that. Their response was ChatGPT with "[Your Email Address]" placeholder still in it 😭 Full story: bobdahacker.com/blog/hacked-... #robotics #security #cybersecurity #infosec
Apparently tons of people registered accounts on tons of platforms with [email protected] Not knowing that .you would come to exist in 2025. Lmfao
⚽ I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, accessed RTMP stream keys for every live World Cup 2026 camera feed. An attacker could've replaced live TV worldwide. bobdahacker.com/blog/fifa-hack #InfoSec #FIFA #WorldCup
ChiitanπŸŒˆγ‘γƒγŸγ‚“β˜†
πŸ”“ Found critical vulns in Taimi (LGBTQ+ dating app) - fixed, $10k bounty - "Expiring" videos didn't expire - Decrement ID = anyone's private videos Taimi handled this right. Fast fix, proper bounty. bobdahacker.com/blog/taimi-i... #InfoSec #BugBounty #IDOR #Taimi #Security #CyberSecurity
🐱 Found critical vulns in Petlibro smart pet feeders - $500 bounty -Auth bypass -hijack any device -Private audio recordings exposed They "fixed" it but left the old endpoint up for "legacy compatibility" bobdahacker.com/blog/petlibro #InfoSec #BugBounty #IoT #Security #Petlibro #CyberSecurity
finally caved and added an RSS feed to my blog after everyone kept begging me in DMs 😀 find it yourself at bobdahacker.com/blog now stop asking me about it lol #RSS #cybersecurity #blog #infosec #bugbounty #hacker
Hacked India's biggest dating app Flutrr (backed by Times of India). Every API endpoint is broken - I could read anyone's messages, swipe for them, change their profile. No auth checks anywhere. bobdahacker.com/blog/indias-... #cybersecurity #infosec #india #dating #vulnerability #bugbounty
9mo
8mo
6d
5mo
5mo
10mo
rate my Subdomain on my Domain i.hate.you #CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy
10mo
Critical vulnerabilities in Pudu Robotics allowed unauthorized control of every Pudu Robotics Robot worldwide. They ignored emails until I contacted Skylark Holdings and Zensho about their compromised...
bobdahacker.com
I Hacked BellaBot and Every Robot from China's Biggest Robotics Company (Pudu Only Fixed It When I Told Their Clients)
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live ...
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
bobdahacker.com
8mo
How I found critical IDOR vulnerabilities in Taimi that exposed
bobdahacker.com
Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid
Security research, vulnerability disclosures, and tech thoughts
bobdahacker.com
Blog | BobDaHacker
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - an...
bobdahacker.com
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
Flutrr, India's biggest dating app backed by The Times of India, has critical security flaws allowing anyone to access all user data, send messages as anyone, and control any account. They've known si...
bobdahacker.com
How I Hacked India's Biggest Dating App (They Offered Me a $100 Gift Card)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)
i hate you
i hate you so much that i made this just for you ❀️
i.hate.you
BobDaHacker πŸ³οΈβ€βš§οΈ (she/her)