-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Expand file tree
/
Copy pathWeakEncryption.ql
More file actions
41 lines (39 loc) · 1.28 KB
/
Copy pathWeakEncryption.ql
File metadata and controls
41 lines (39 loc) · 1.28 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
/**
* @name Weak cryptography
* @description Finds explicit uses of symmetric encryption algorithms that are weak, unknown, or otherwise unaccepted.
* @kind problem
* @id cpp/weak-crypto/banned-encryption-algorithms
* @problem.severity error
* @precision high
* @tags external/cwe/cwe-327
*/
import cpp
import experimental.cryptography.Concepts
from SymmetricEncryptionAlgorithm alg, Expr confSink, string msg
where
exists(string resMsg |
(
if alg.getEncryptionName() = unknownAlgorithm()
then (
alg instanceof Literal and
resMsg =
"Use of unrecognized symmetric encryption algorithm: " +
alg.(Literal).getValueText().toString() + "."
or
not alg instanceof Literal and
resMsg = "Use of unrecognized symmetric encryption algorithm."
) else (
not alg.getEncryptionName().matches("AES%") and
resMsg = "Use of banned symmetric encryption algorithm: " + alg.getEncryptionName() + "."
)
) and
(
if alg.hasConfigurationSink() and alg.configurationSink() != alg
then (
confSink = alg.configurationSink() and msg = resMsg + " Algorithm used at sink: $@."
) else (
confSink = alg and msg = resMsg
)
)
)
select alg, msg, confSink, confSink.toString()