置顶推文tmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…翻译 English491942.5K563K1.7K
tmctmt@tmctmt·1deveryone is familiar with the "reddit killed forums" discourse, but have you ever seen a site actually metamorphosize into reddit?翻译 English116613
tmctmt@tmctmt·1d@tester47546 The exploit hinged on the GCP connection being HTTP/1, otherwise Discord wouldn't have been able to introduce a CRLF injection vector.翻译 English000629
ester@tester47546·1d@tmctmt Congrats. How is something like this can even possible with http/2 today? I only see one case where downgrading happens . But not much翻译 English1001.7K
tmctmt@tmctmt·3dSpying on everybody's Discord attachments with HTTP desync tmctmt.com/posts/http-des…翻译 English491942.5K563K1.7K