Have to switch it off next night.
Well, not much harm done, my alarm would have woken me up soon anyway for my Angel shift at 04:00 in the Cloakroom Lost and Found.
Can we hack it?? Yes we can!!! 😎😎😎
Hey Im BobDaHacker an ethical hacker 🤓
Thx 4 coming to my ted talk
| Website | https://bobdahacker.com |
| Pronouns | She/They |
I'm at 39C3 you can call me at 24630
Ok
#39C3 #ccc #gay #cybersecurity #germany #hamburg #likeandshare #penis
🐱 New Blog Post: Petlibro Smart Pet Feeder Vulnerabilities (Partially Fixed, $500)
Found critical vulns in Petlibro - one of the biggest smart pet feeder companies:
The worst part? They "fixed" the auth bypass by making a new endpoint... but left the old vulnerable one active for "legacy compatibility." Two months later, still working.
Also tried to get me to sign an NDA AFTER paying the bounty. That's not how contracts work.
Full writeup: https://bobdahacker.com/blog/petlibro
#InfoSec #BugBounty #ResponsibleDisclosure #IoT #Petlibro #Security #Privacy #CyberSecurity #SmartHome #OAuth

How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for 'legacy compatibility' two months later.
🎵 New Blog Post: Bandsintown Verification Bypass (Fixed, $200 + Swag)
Found a way to claim any unclaimed artist page on Bandsintown without verification:
I could have rickrolled 191k people for real. I did not.
Bandsintown handled it well - fast fix, honest about bounty limitations, shipped me swag.
Also found a new bypass while writing this - currently disclosing responsibly.
Full writeup: https://bobdahacker.com/blog/bandsintown
#InfoSec #BugBounty #ResponsibleDisclosure #Bandsintown #Security #Privacy #CyberSecurity #RickAstley #APISecuity #Music
🔓 Found critical vulns in Taimi (LGBTQ+ dating app) - all fixed, $10k bounty
What I found:
The good news: Taimi actually handled this right. Fast response, $10k bounty, everything fixed quickly. No lawyers, no threats.
This is how disclosure should work. Take notes, Lovense.
Full writeup: https://bobdahacker.com/blog/taimi-idor
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Taimi #DatingApp #Security #Privacy #CyberSecurity #LGBTQ
Apparently tons of people registered accounts on tons of platforms with [email protected]
Not knowing that .you would come to exist in 2025.
Lmfao
#CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy
rate my Subdomain on my Domain
#CyberSecurity #InfoSec #domains #subdomain #programming #ProgramerHumour #Privacy
RE: https://infosec.exchange/@cR0w/115265136537348697
Looks like this is resurfacing. Happy to see it getting more coverage.