Tweet épinglétmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…Traduire English491972.5K563.8K1.7K
tmctmt@tmctmt·1deveryone is familiar with the "reddit killed forums" discourse, but have you ever seen a site actually metamorphosize into reddit?Traduire English117637
tmctmt@tmctmt·1d@tester47546 The exploit hinged on the GCP connection being HTTP/1, otherwise Discord wouldn't have been able to introduce a CRLF injection vector.Traduire English000653
ester@tester47546·2d@tmctmt Congrats. How is something like this can even possible with http/2 today? I only see one case where downgrading happens . But not muchTraduire English1001.7K
tmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…Traduire English491972.5K563.8K1.7K