参考文章: Security Bugs in Practice: SSRF via Request Splitting
参考文章:
Security Bugs in Practice: SSRF via Request Splitting
For requests that do not include a body, Node.js defaults to using “latin1”, a single-byte encoding that cannot represent high-numbered unicode characters such as the javascript
For requests that do not include a body, Node.js defaults to using “latin1”, a single-byte encoding that cannot represent high-numbered unicode characters such as the