Pinned Tweettmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…Translate English491952.5K563.4K1.7K
tmctmt@tmctmt·1deveryone is familiar with the "reddit killed forums" discourse, but have you ever seen a site actually metamorphosize into reddit?Translate English117629
tmctmt@tmctmt·1d@tester47546 The exploit hinged on the GCP connection being HTTP/1, otherwise Discord wouldn't have been able to introduce a CRLF injection vector.Translate English000642
ester@tester47546·2d@tmctmt Congrats. How is something like this can even possible with http/2 today? I only see one case where downgrading happens . But not muchTranslate English1001.7K
tmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…Translate English491952.5K563.4K1.7K