Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
BobDaHacker
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
BobDaHacker
3mo ago
That's a different thing. RTMP ingest endpoints aren't behind the same API layer, they're just open media endpoints that accept a connection if you have the stream key. The stream key was right there in the URL. There's
2.
▲
by
BobDaHacker
3mo ago
I am not much of a football gal myself, so I didn't know they were a shitty org.
3.
▲
by
BobDaHacker
3mo ago
Also, I am not much of a football gal myself, so I didn't know they were a shitty org.
4.
▲
by
BobDaHacker
3mo ago
As much as I like being butt fucked, I dont wanna go to prison :3
5.
▲
by
BobDaHacker
3mo ago
Yeah I used Claude as a writing assistant for the initial draft. I'm autistic and long-form writing isn't my strong suit, getting a 4000 word blog post to flow well is genuinely hard for me. But I do edit it pretty heavily after,
6.
▲
by
BobDaHacker
3mo ago
Good question! So RTMP doesn't really have a clean way to handle two publishers on the same stream key. What would actually happen is the two streams fighting for the ingest endpoint, so the output would glitch between the two sources.
7.
▲
by
BobDaHacker
3mo ago
Yeah I see this type of crap often honestly, especially at big companies.
8.
▲
by
BobDaHacker
3mo ago
I blocked my network traffic before clicking it cuz I've seen a lot of things without confirmation pop-ups. At least there was a confirmation pop-up.
9.
▲
I Could've Rickrolled the FIFA World Cup. All I Needed Was My ID
(bobdahacker.com)
315 points
by
BobDaHacker
3mo ago
|
99 comments
10.
▲
by
BobDaHacker
3mo ago
Registered on FIFA's public Agent Platform with my ID, got added to their Microsoft Entra tenant, and found the Angular app only checked roles client-side. The backend APIs served everything: RTMP ingest URLs and stream keys for every
11.
▲
by
BobDaHacker
1y ago
Burger King
12.
▲
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
(bobdahacker.com)
427 points
by
BobDaHacker
1y ago
|
218 comments
13.
▲
by
BobDaHacker
1y ago
Yes. I really hope this teaches them a lesson and they fix it before 4chan acts but that problem won't happen. Also If I would have stayed quiet and not informed the public that the app doesnt care about your privacy, a databreach was
14.
▲
by
BobDaHacker
1y ago
I do want people's privacy to be protected, this app has been insecure since day one, and they obviously don't care, it's been 9 months. I posted about it since they obviously didnt give a shit, because this will now hopefull
15.
▲
I Hacked India's Biggest Dating App (They Offered Me a $100 Gift Card)
(bobdahacker.com)
12 points
by
BobDaHacker
1y ago
|
3 comments
16.
▲
When South Park's Restaurant Had Worse Security Than Cartman's Password
(bobdahacker.com)
4 points
by
BobDaHacker
1y ago
|
0 comments
17.
▲
by
BobDaHacker
1y ago
You absolutely nailed it. As the researcher who found these vulns, I can confirm the over-engineering is real. They literally had internal user IDs (ofId) already implemented and working, but kept the email-based JIDs for "legacy suppo
18.
▲
by
BobDaHacker
1y ago
Hi HN, I'm the researcher who found these vulnerabilities. Happy to answer questions. A few clarifications on the technical side: The XMPP issue wasn't just about JIDs containing emails - it was that their roster sync actively lin