jvoisin/php-malware-finder

Rule $concat_with_spaces causes a lot of false positives

scottcwilson opened this issue · 3 comments

I wonder if there's a better way of doing this.

Feel free to issue a PR if you come up with a better solution :)

Can you show me some true positives that this catches? I would need something to verify my work.

Something like "s". "y" ."st"."e"."m(". I guess, or $a.$b.$c.$d. $cd, or "sy" . $s . "em(" . $BinA_ry .")"