(no title)
cscheid | 1 year ago
However, I then pasted the emoji into the _query_ part of a URL. I pointed it to my own website, and sure enough, I can definitely see the payload in the nginx logs. Yikes.
Edit: I pasted the very same Emoji that 'paulgb used in their post before the parenthetical in the first paragraph, but it seems HN scrubs those from comments.
bmicraft|1 year ago
[1] https://www.w3schools.com/tags//ref_urlencode.asp
echeese|1 year ago