dnsDomainLevels used without excluding IP literals
low
dnsDomainLevels counts dots. 192.0.2.10 has three, like a.b.c.example. A "this is a fully qualified name" test based on it also matches every IPv4 address.
Why it matters
dnsDomainLevels("192.0.2.10") is 3, indistinguishable from a three-level hostname. A
branch such as if (dnsDomainLevels(host) >= 2) return "PROXY ..." therefore routes IP
literals (often internal servers addressed by IP) to the proxy. Guard with an IP-literal
test first, or do not use the dot count as a proxy for “external name”.
How to fix
Test for IP literals (/^\d+\.\d+\.\d+\.\d+$/) before dnsDomainLevels, or use isPlainHostName and explicit domain suffixes instead.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainLevels(host) >= 2) {
return "PROXY proxy.corp.example:8080";
}
return "DIRECT";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host) || /^\d+\.\d+\.\d+\.\d+$/.test(host)) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- IP range matched as a text prefix PAC-X006