Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - an...
π± Found critical vulns in Petlibro smart pet feeders - $500 bounty
-Auth bypass
-hijack any device
-Private audio recordings exposed
They "fixed" it but left the old endpoint up for "legacy compatibility"
bobdahacker.com/blog/petlibro
#InfoSec #BugBounty #IoT #Security #Petlibro #CyberSecurity
27.12.2025 14:05
π 4
π 1
π¬ 0
π 0
Bandsintown: How I Almost Rickrolled 191k People
How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send pus...
π΅ Found a verification bypass in Bandsintown - fixed
Used API endpoint to claim any unclaimed artist
Got full access to Rick Astley's 191k followers
Emails, names, push notifs
Could have rickrolled 191k people. I did not.
bobdahacker.com/blog/bandsin...
#InfoSec #BugBounty #Security #CyberSecurity
26.12.2025 06:10
π 0
π 0
π¬ 0
π 0
Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid
How I found critical IDOR vulnerabilities in Taimi that exposed
π Found critical vulns in Taimi (LGBTQ+ dating app) - fixed, $10k bounty
- "Expiring" videos didn't expire
- Decrement ID = anyone's private videos
Taimi handled this right. Fast fix, proper bounty.
bobdahacker.com/blog/taimi-i...
#InfoSec #BugBounty #IDOR #Taimi #Security #CyberSecurity
26.12.2025 05:18
π 2
π 1
π¬ 0
π 0
Apparently tons of people registered accounts on tons of platforms with i@hate.you
Not knowing that .you would come to exist in 2025.
Lmfao
24.10.2025 11:12
π 1
π 1
π¬ 0
π 0
i hate you
i hate you so much that i made this just for you β€οΈ
rate my Subdomain on my Domain
i.hate.you
#CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy
24.10.2025 11:11
π 6
π 0
π¬ 1
π 0
Check dms π
05.10.2025 02:08
π 1
π 0
π¬ 0
π 0
Every day, I pray for a world where everyone is kind and respectful of each other, regardless of gender.
May unreasonable attacks against transgender people endπ³οΈββ§οΈπ³οΈβπ
May today be filled with happiness and love for you allπ€
24.09.2025 10:51
π 10805
π 3054
π¬ 116
π 83
Blog | BobDaHacker
Security research, vulnerability disclosures, and tech thoughts
finally caved and added an RSS feed to my blog after everyone kept begging me in DMs π€
find it yourself at bobdahacker.com/blog
now stop asking me about it lol
#RSS #cybersecurity #blog #infosec #bugbounty #hacker
25.08.2025 02:30
π 3
π 0
π¬ 0
π 0
Bruh, that would be illegal. I'm not gonna do illegal things. Also McDonald's gave me nothing.
23.08.2025 12:15
π 0
π 0
π¬ 0
π 0
When South Park's Restaurant Had Worse Security Than Cartman's Password
How I found critical security vulnerabilities in Matt Stone and Trey Parker's Casa Bonita restaurant, exposing customer data, payment info, and their entire POS system - plus how I accidentally got a ...
Hacked South Park's Casa Bonita. Could access their entire POS system and see all customer payments/tips. No security contact anywhere π¬
Fixed fast but never thanked me. Got a Founders Club card 6 months later though π
bobdahacker.com/blog/i-hacke...
#SouthPark #infosec #hacking #cybersecurity
18.08.2025 04:55
π 5
π 1
π¬ 1
π 0
Lovense Dan Liu response
@lovense-official.bsky.social
Dan Liu's threat to pursue litigation against @bobdahacker.com is the most ignorant shit I've even seen in my years of #dlp and #cybersecurity.
Plenty of proof of the #vuln, and the lack of response before public disclosure.
www.documentcloud.org/documents/26...
01.08.2025 15:17
π 1
π 1
π¬ 1
π 0
butt plug man it was fixed please retweet my latest post on bluesky and twitter thx butt plug man
30.07.2025 14:03
π 0
π 0
π¬ 0
π 0
butt plug man it was fixed please retweet my latest post on bluesky and twitter thx butt plug man
30.07.2025 14:02
π 0
π 0
π¬ 0
π 0
Lovense: The Company That Lies to Security Researchers
How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.
π¨ Lovense finally fixed their email leak after public pressure
They said: 14 months
Reality: 2 days after going viral
11M+ users at risk for YEARS. Read the full deception: bobdahacker.com/blog/lovense...
#InfoSec #Privacy #CyberSecurity #BugBounty
30.07.2025 13:45
π 6
π 4
π¬ 1
π 1
shame on Lovense
29.07.2025 20:16
π 0
π 0
π¬ 0
π 0
x.com/radiantnmyhe...
More people are coming out against Lovense
29.07.2025 17:29
π 5
π 0
π¬ 0
π 1
I agree
29.07.2025 16:57
π 2
π 0
π¬ 0
π 0
Lovense: The Company That Lies to Security Researchers
How Lovense has ignored the same critical vulnerabilities for 2+ years, lied about fixes, and manipulated bounty payouts while leaving 10s of millions of users exposed.
PSA: Lovense products leak your email from just your username. Reported in March, still broken.
Worse: Another Vulnerability was "fixed" in 2023 but wasn't. Company lied to researchers for 2+ years.
Full breakdown: bobdahacker.com/blog/lovense...
#cybersecurity #infosec #bugbounty #privacy
29.07.2025 11:05
π 95
π 58
π¬ 3
π 3