vger.social
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
beep@piefed.world to cybersecurity@infosec.pubEnglish · 4 days ago

HTTP desync in Discord's media proxy: Spying on a whole platform

tmctmt.com

external-link
message-square
0
link
fedilink
  • cross-posted to:
  • pulse_of_truth@infosec.pub
9
external-link

HTTP desync in Discord's media proxy: Spying on a whole platform

tmctmt.com

beep@piefed.world to cybersecurity@infosec.pubEnglish · 4 days ago
message-square
0
link
fedilink
  • cross-posted to:
  • pulse_of_truth@infosec.pub
HTTP desync in Discord's media proxy: Spying on a whole platform (2022)
tmctmt.com
external-link
In 2022, I came across a quirky behavior on media.discordapp.net when I miskeyed a space character into an attachment link: a 502 bad gateway. After some fiddling I realized that this was caused by a HTTP injection bug within the media proxy’s request to the upstream GCP bucket. The space character corrupted the proxied HTTP message, which caused the connection to prematurely terminate. For example, a crafted user request to the media proxy would look like this:

Lobsters.

alert-triangle
You must log in or register to comment.

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 68 users / day
  • 341 users / week
  • 799 users / month
  • 2.1K users / 6 months
  • 3 local subscribers
  • 6.07K subscribers
  • 988 Posts
  • 1.55K Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.11
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org