RSSAmplifier

Blog

bobdahacker blog

cybersecurity insights, hacking tutorials, and digital security research

bobdahacker.comRSS feed ↗12 posts

Latest posts

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

How a missing Firestore security rule on tl;dv exposed 181,874 meetings from 84,312 users across 35,003 domains, including live calls I could join uninvited, and how six months of disclosure got me nothing but seen receipts.

Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails

How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later. Nobody has ever responded.

Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.

How I found that anyone with a boarding pass photo can pull full passport numbers, home addresses, children's dates of birth, credit card details, and Known Traveler Numbers for every passenger on a Frontier Airlines booking. Reported March 3rd. Still live 105 days later.

I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.

How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks

How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for 'legacy compatibility' two months later.

Bandsintown: How I Almost Rickrolled 191k People

How I found a verification bypass in Bandsintown that let anyone claim unclaimed artist pages with a single API call - including Rick Astley's 191k followers, their emails, and the ability to send push notifications as any artist.

Taimi: Finding Everyone's Private Photos Was Easy, But So Was Getting Paid

How I found critical IDOR vulnerabilities in Taimi that exposed "expiring" videos, private photos through a bizarre location feature, and allowed fake system messages - and how they actually handled it right with a $10k bounty.

I Hacked BellaBot and Every Robot from China's Biggest Robotics Company (Pudu Only Fixed It When I Told Their Clients)

Critical vulnerabilities in Pudu Robotics allowed unauthorized control of every Pudu Robotics Robot worldwide. They ignored emails until I contacted Skylark Holdings and Zensho about their compromised robot fleets.

How I Hacked India's Biggest Dating App (They Offered Me a $100 Gift Card)

Flutrr, India's biggest dating app backed by The Times of India, has critical security flaws allowing anyone to access all user data, send messages as anyone, and control any account. They've known since November 2024 and offered me $100.

When South Park's Restaurant Had Worse Security Than Cartman's Password

How I found critical security vulnerabilities in Matt Stone and Trey Parker's Casa Bonita restaurant, exposing customer data, payment info, and their entire POS system - plus how I accidentally got a Founders Club membership card 6 months later.

How I Hacked McDonald's (Their Security Contact Was Harder to Find Than Their Secret Sauce Recipe)

How I found critical security vulnerabilities in McDonald's systems affecting millions of employees, and had to cold-call their HQ pretending to know security staff just to report them.

Lovense: The Company That Lies to Security Researchers

How Lovense ignored critical vulnerabilities for 8+ years despite multiple researchers reporting them since 2017, exposed 11+ million users' emails through XMPP, allowed account takeovers without passwords, lied to researchers about fixes, and only patched after public exposure forced their hand.