# hackedteam/vector-exploit

src/edn2/2014-004-AndroidBrowser/slowaes.py

### Summary

F
2 mos

#### Function `decrypt` has a Cognitive Complexity of 80 (exceeds 5 allowed). Consider refactoring. Open

``````    def decrypt(self, cipherIn, originalsize, mode, key, size, IV):
# cipherIn = unescCtrlChars(cipherIn)
if len(key) % size:
return None
if len(IV) % 16:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 day to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### Function `encrypt` has a Cognitive Complexity of 70 (exceeds 5 allowed). Consider refactoring. Open

``````    def encrypt(self, stringIn, mode, key, size, IV):
if len(key) % size:
return None
if len(IV) % 16:
return None``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 day to fix

#### File `slowaes.py` has 475 lines of code (exceeds 250 allowed). Consider refactoring. Open

``````#!/usr/bin/python
#
# aes.py: implements AES - Advanced Encryption Standard
# from the SlowAES project, http://code.google.com/p/slowaes/
#``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 7 hrs to fix

#### Function `expandKey` has a Cognitive Complexity of 12 (exceeds 5 allowed). Consider refactoring. Open

``````    def expandKey(self, key, size, expandedKeySize):
"""Rijndael's key expansion.

Expands an 128,192,256 key into an 176,208,240 bytes key

``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

#### Function `encrypt` has a Cognitive Complexity of 10 (exceeds 5 allowed). Consider refactoring. Open

``````    def encrypt(self, iput, key, size):
output = [0] * 16
# the number of rounds
nbrRounds = 0
# the 128 bit block to encode``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

#### Function `decrypt` has a Cognitive Complexity of 10 (exceeds 5 allowed). Consider refactoring. Open

``````    def decrypt(self, iput, key, size):
output = [0] * 16
# the number of rounds
nbrRounds = 0
# the 128 bit block to decode``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

#### Avoid deeply nested control flow statements. Open

``````                        if firstRound:
plaintext[i] = IV[i] ^ output[i]
else:
plaintext[i] = iput[i] ^ output[i]
firstRound = False``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(plaintext)-1 < i:
ciphertext[i] = 0 ^ output[i]
elif len(output)-1 < i:
ciphertext[i] = plaintext[i] ^ 0
elif len(plaintext)-1 < i and len(output) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if firstRound:
iput[i] =  plaintext[i] ^ IV[i]
else:
iput[i] =  plaintext[i] ^ ciphertext[i]
# print 'IP@%s:%s' % (j, iput)``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(output)-1 < i:
plaintext[i] = 0 ^ ciphertext[i]
elif len(ciphertext)-1 < i:
plaintext[i] = output[i] ^ 0
elif len(output)-1 < i and len(ciphertext) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(plaintext)-1 < i:
ciphertext[i] = 0 ^ output[i]
elif len(output)-1 < i:
ciphertext[i] = plaintext[i] ^ 0
elif len(plaintext)-1 < i and len(output) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        for k in range(end-start):
stringOut += chr(plaintext[k])
iput = ciphertext``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Function `decrypt` has 6 arguments (exceeds 4 allowed). Consider refactoring. Open

``    def decrypt(self, cipherIn, originalsize, mode, key, size, IV):``
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(output)-1 < i:
plaintext[i] = 0 ^ ciphertext[i]
elif len(ciphertext)-1 < i:
plaintext[i] = output[i] ^ 0
elif len(output)-1 < i and len(ciphertext) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        for k in range(originalsize-start):
stringOut += chr(plaintext[k])
else:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Function `encrypt` has 5 arguments (exceeds 4 allowed). Consider refactoring. Open

``    def encrypt(self, stringIn, mode, key, size, IV):``
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 35 mins to fix

#### Identical blocks of code found in 4 locations. Consider refactoring. Open

Found in src/edn2/2014-004-AndroidBrowser/slowaes.py and 3 other locations - About 2 mos to fix
src/ht-webkit-Android4-src/ext/slowaes.py on lines 0..656
src/ht-webkit-Android4-src/precompiled/debug/slowaes.py on lines 0..656
src/ht-webkit-Android4-src/precompiled/release/slowaes.py on lines 0..656

