lammertb / libhttp

Multi platform HTTP and HTTPS library
MIT License
957 stars 131 forks source link

malware #80

Open ChuckCottrill opened 1 year ago

ChuckCottrill commented 1 year ago

the file test/exploit.pl is malware and triggers a policy violation on some malware detection systems.

ChuckCottrill commented 1 year ago

Does the file test/exploit.pl need to be present, or can that file omit the malware so that it does not trigger a security alert? When looking at the testing, it does not appear that the actual malware contents are needed.

lammertb commented 1 year ago

Thanks for bringing this issue up. The script was already present before this library was forked. I have removed as it has no added value in the current environment.

Linked commit: https://github.com/lammertb/libhttp/commit/cec0e67238277d8b7c3ae79af1ed5a3891fd7373