linksfor.dev(s)

Featured post what's this?

✨ HTTP desync in Discord's media proxy: Spying on a whole platform

In 2022, I came across a quirky behavior on media.discordapp.net when I miskeyed a space character into an attachment link: a 502 bad gateway. After some fiddling I realized that this was caused by a HTTP injection bug within the media proxy’s request to ...