Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

BobDaHacker 🏳️‍⚧️

@bobdahacker@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Can we hack it?? Yes we can!!! 😎😎😎

Hey Im BobDaHacker an ethical hacker 🤓

Thx 4 coming to my ted talk

645 Followers
59 Following
11 Posts
Joined July 31, 2025
Website:
https://bobdahacker.com
Pronouns:
She/They
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 2mo ago
🙏 New Blog Post The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check. What's exposed: Email addressesNamesCountryDate of birth (they call it "borned_date" lol)Account role (it's "PRAYER" for everyone, obviously) Also found: Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inboxTheir verification emails fail their own domain's authentication requirements Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess. Full writeup: https://bobdahacker.com/blog/click-to-pray #InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Click to Pray, Click to Leak: The Pope
bobdahacker.com

Click to Pray, Click to Leak: The Pope

How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope

254
32
263
2
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 3mo ago
Boosted by @trending@homestead.social
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care. Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass. Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse. Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack #InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn
bobdahacker.com

Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn

How I found that anyone with a boarding pass photo can pull full passport numbers, home addresses, children

217
14
275
4
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 3mo ago
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID. Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide. Full writeup: https://bobdahacker.com/blog/fifa-hack #InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
I Could
bobdahacker.com

I Could

How I found that anyone could register on FIFA

139
27
160
6
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 2mo ago

🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.

What's exposed:

  • Creator emails, conference IDs, recording status, timestamps
  • Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
  • Government meetings from 23 countries
  • Corporate meetings from thousands of companies

Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.

Full writeup: https://bobdahacker.com/blog/tldv-hack

#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy

tl;dv (Too Lazy; Didn
bobdahacker.com

tl;dv (Too Lazy; Didn

How a missing Firestore security rule on tl;dv exposed 181,874 meetings from 84,312 users across 35,003 domains, including live calls I could join uninvited, and how six months of disclosure got me nothing but seen receipts.

32
3
32
3
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 4w ago

Anyone based in Tokyo want to make some friends? :3

im 20TF, been here since last summer. im very geeky and i love everything tech, cybersecurity, and programming. i also love animals, nature, geocaching, theme parks, musicals, cocktail mixing, baking, hiking, travelling, gaming, playing clarinet, listening to music (Tally Hall, Will Wood, classic rock, metal etc), tv shows, movies, and crime documentaries. i also turned my apartment into a whole hangout spot with a dart machine, karaoke, and a room full of 400 Blåhajs, (I call the Blåhaj pit) lol

always free and always down to grab a drink or explore the city.

#tokyo #japan #friends #t4t #cybersecurity #infosec #techie #gaming #hiking #karaoke

infosec.exchange
3
0
0
0
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 14mo ago

Found critical vulns in Lovense (the biggest sex toy company) affecting 11M+ users. They ignored researchers for 2+ years, then fixed in 2 days after public exposure. 🤦

What I found:

  • Email disclosure via XMPP (username→email)
  • Auth bypass (email→account takeover, no password)

History of ignoring researchers:

  • 2017: First recorded case of someone reporting XMPP email leak.
  • 2022: Someone else reports XMPP email leak, ignored
  • Sept 2023: Krissy reports account takeover + different email leak via HTTP API, paid only $350
  • 2024: Another person reports XMPP email leak AND Account Takeover vuln, offered 2 free sex toys (accepted for the meme)
  • March 2025: I report account takeover + XMPP email leak, paid $3000 (after pushing for critical)
  • Told me fix for email vuln needs 14 months because "legacy support" > user security (had 1-month fix ready)
  • July 28: I go public
  • July 30: Both fixed in 48 hours

Same bugs, different treatment. They lied to journalists saying it was fixed in June, tried to get me banned from HackerOne after giving permission to disclose.

News covered it but my blog has the full technical details: https://bobdahacker.com/blog/lovense-still-leaking-user-emails/

#InfoSec #BugBounty #ResponsibleDisclosure #Security #Vulnerability #IoT #cybersecurity

bobdahacker.com
176
0
155
0
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 2mo ago
Replying to
Still need someone.
1
0
0
0
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 9mo ago

I'm at 39C3 you can call me at 24630

Ok
#39C3 #ccc #gay #cybersecurity #germany #hamburg #likeandshare #penis

infosec.exchange
4
0
0
0
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 9mo ago

Call me on my DECT Phone, late-night when you need my love:

24630
24630
24630
24630

#39c3 #hamburg

infosec.exchange
3
0
1
0
Open post
BobDaHacker 🏳️‍⚧️ @bobdahacker@infosec.exchange
· 3mo ago

@AlexQR@mastodon.social blud, what are you on about

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:10:57 UTC