HTTP desync in Discord's media proxy: Spying on a whole platform

65 points by videah


kenballus

no halfway-decent request library would let you inject control characters into your messages.

You'd be surprised! I have seen this exact bug many times.

GCP's classic application load balancer used to be full of these bugs until pretty recently. Same with AWS CloudFront. Might still be :)