# hackedteam/vector-exploit

src/edn2/2014-004-AndroidBrowser/slowaes.py

### Summary

F
2 mos

#### Function `decrypt` has a Cognitive Complexity of 80 (exceeds 5 allowed). Consider refactoring. Open

``````    def decrypt(self, cipherIn, originalsize, mode, key, size, IV):
# cipherIn = unescCtrlChars(cipherIn)
if len(key) % size:
return None
if len(IV) % 16:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 day to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### Function `encrypt` has a Cognitive Complexity of 70 (exceeds 5 allowed). Consider refactoring. Open

``````    def encrypt(self, stringIn, mode, key, size, IV):
if len(key) % size:
return None
if len(IV) % 16:
return None``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 day to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### File `slowaes.py` has 475 lines of code (exceeds 250 allowed). Consider refactoring. Open

``````#!/usr/bin/python
#
# aes.py: implements AES - Advanced Encryption Standard
# from the SlowAES project, http://code.google.com/p/slowaes/
#``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 7 hrs to fix

#### Function `expandKey` has a Cognitive Complexity of 12 (exceeds 5 allowed). Consider refactoring. Open

``````    def expandKey(self, key, size, expandedKeySize):
"""Rijndael's key expansion.

Expands an 128,192,256 key into an 176,208,240 bytes key

``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### Function `encrypt` has a Cognitive Complexity of 10 (exceeds 5 allowed). Consider refactoring. Open

``````    def encrypt(self, iput, key, size):
output = [0] * 16
# the number of rounds
nbrRounds = 0
# the 128 bit block to encode``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### Function `decrypt` has a Cognitive Complexity of 10 (exceeds 5 allowed). Consider refactoring. Open

``````    def decrypt(self, iput, key, size):
output = [0] * 16
# the number of rounds
nbrRounds = 0
# the 128 bit block to decode``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 1 hr to fix

# Cognitive Complexity

Cognitive Complexity is a measure of how difficult a unit of code is to intuitively understand. Unlike Cyclomatic Complexity, which determines how difficult your code will be to test, Cognitive Complexity tells you how difficult your code will be to read and comprehend.

### A method's cognitive complexity is based on a few simple rules:

• Code is not considered more complex when it uses shorthand that the language provides for collapsing multiple statements into one
• Code is considered more complex for each "break in the linear flow of the code"
• Code is considered more complex when "flow breaking structures are nested"

#### Avoid deeply nested control flow statements. Open

``````                        if firstRound:
plaintext[i] = IV[i] ^ output[i]
else:
plaintext[i] = iput[i] ^ output[i]
firstRound = False``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(plaintext)-1 < i:
ciphertext[i] = 0 ^ output[i]
elif len(output)-1 < i:
ciphertext[i] = plaintext[i] ^ 0
elif len(plaintext)-1 < i and len(output) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if firstRound:
iput[i] =  plaintext[i] ^ IV[i]
else:
iput[i] =  plaintext[i] ^ ciphertext[i]
# print 'IP@%s:%s' % (j, iput)``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(output)-1 < i:
plaintext[i] = 0 ^ ciphertext[i]
elif len(ciphertext)-1 < i:
plaintext[i] = output[i] ^ 0
elif len(output)-1 < i and len(ciphertext) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(plaintext)-1 < i:
ciphertext[i] = 0 ^ output[i]
elif len(output)-1 < i:
ciphertext[i] = plaintext[i] ^ 0
elif len(plaintext)-1 < i and len(output) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        for k in range(end-start):
stringOut += chr(plaintext[k])
iput = ciphertext``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Function `decrypt` has 6 arguments (exceeds 4 allowed). Consider refactoring. Open

``    def decrypt(self, cipherIn, originalsize, mode, key, size, IV):``
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        if len(output)-1 < i:
plaintext[i] = 0 ^ ciphertext[i]
elif len(ciphertext)-1 < i:
plaintext[i] = output[i] ^ 0
elif len(output)-1 < i and len(ciphertext) < i:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Avoid deeply nested control flow statements. Open

``````                        for k in range(originalsize-start):
stringOut += chr(plaintext[k])
else:``````
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 45 mins to fix

#### Function `encrypt` has 5 arguments (exceeds 4 allowed). Consider refactoring. Open

``    def encrypt(self, stringIn, mode, key, size, IV):``
Found in src/edn2/2014-004-AndroidBrowser/slowaes.py - About 35 mins to fix

#### Identical blocks of code found in 4 locations. Consider refactoring. Open

Found in src/edn2/2014-004-AndroidBrowser/slowaes.py and 3 other locations - About 2 mos to fix
src/ht-webkit-Android4-src/ext/slowaes.py on lines 0..656
src/ht-webkit-Android4-src/precompiled/debug/slowaes.py on lines 0..656
src/ht-webkit-Android4-src/precompiled/release/slowaes.py on lines 0..656

## Duplicated Code

Duplicated code can lead to software that is hard to understand and difficult to change. The Don't Repeat Yourself (DRY) principle states:

Every piece of knowledge must have a single, unambiguous, authoritative representation within a system.

When you violate DRY, bugs and maintenance problems are sure to follow. Duplicated code has a tendency to both continue to replicate and also to diverge (leaving bugs as two similar implementations differ in subtle ways).

## Tuning

This issue has a mass of 5908.

We set useful threshold defaults for the languages we support but you may want to adjust these settings based on your project guidelines.

The threshold configuration represents the minimum mass a code block must have to be analyzed for duplication. The lower the threshold, the more fine-grained the comparison.

If the engine is too easily reporting duplication, try raising the threshold. If you suspect that the engine isn't catching enough duplication, try lowering the threshold. The best setting tends to differ from language to language.

See `codeclimate-duplication`'s documentation for more information about tuning the mass threshold in your `.codeclimate.yml`.