Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

BobDaHacker 🏳️‍⚧️

@bobdahacker@infosec.exchange
  • Open on infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎

Hey Im BobDaHacker an ethical hacker 🤓

Thx 4 coming to my ted talk

0 Followers
0 Following
6 Posts
Joined July 31, 2025
Website:
https://bobdahacker.com
Pronouns:
She/They

Posts

Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Aug 05, 2026
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange
Replying to @bobdahacker@infosec.exchange
Still need someone.
0
0
0
0
Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Aug 02, 2026
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange
Does anyone have a contact at warner bros? I found several very detrimental security issues there, and their hacker one team is unresponsive and didn't care or understand the issues. Thanks
12
2
15
0
Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jul 24, 2026
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange
🙏 New Blog Post The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check. What's exposed: Email addressesNamesCountryDate of birth (they call it "borned_date" lol)Account role (it's "PRAYER" for everyone, obviously) Also found: Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inboxTheir verification emails fail their own domain's authentication requirements Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess. Full writeup: https://bobdahacker.com/blog/click-to-pray #InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
240
28
263
2
Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jun 16, 2026
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange
Boosted by Trending Bot @trending@homestead.social
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care. Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass. Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse. Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack #InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
32
0
55
0
Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jun 15, 2026
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide. Full writeup: https://bobdahacker.com/blog/fifa-hack #InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
138
18
160
6
Open post
bobdahacker
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange · Jul 31, 2025
BobDaHacker 🏳️‍⚧️
@bobdahacker@infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎 Hey Im BobDaHacker an ethical hacker 🤓 Thx 4 coming to my ted talk

infosec.exchange

Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🤦

What I found:

  • Email disclosure via XMPP (username→email)
  • Auth bypass (email→account takeover, no password)

History of ignoring researchers:

  • 2017: First recorded case of someone reporting XMPP email leak.
  • 2022: Someone else reports XMPP email leak, ignored
  • Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
  • 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
  • March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
  • Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
  • July 28: I go public
  • July 30: Both fixed in 48 hours

Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.

News covered it but my blog has the full technical details: https://bobdahacker.com/blog/lovense-still-leaking-user-emails/

#InfoSec #BugBounty #ResponsibleDisclosure #Security #Vulnerability #IoT #cybersecurity

176
0
155
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:50:39 UTC