PAC-C010 · dnsdomainlevels-on-ip-literal

dnsDomainLevels used without excluding IP literals

low · Correctness

dnsDomainLevels counts dots. 192.0.2.10 has three, like a.b.c.example. A "this is a fully qualified name" test based on it also matches every IPv4 address.

Why it matters

dnsDomainLevels("192.0.2.10") is 3, indistinguishable from a three-level hostname. A branch such as if (dnsDomainLevels(host) >= 2) return "PROXY ..." therefore routes IP literals (often internal servers addressed by IP) to the proxy. Guard with an IP-literal test first, or do not use the dot count as a proxy for “external name”.

How to fix

Test for IP literals (/^\d+\.\d+\.\d+\.\d+$/) before dnsDomainLevels, or use isPlainHostName and explicit domain suffixes instead.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainLevels(host) >= 2) {
    return "PROXY proxy.corp.example:8080";
  }
  return "DIRECT";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host) || /^\d+\.\d+\.\d+\.\d+$/.test(host)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References