PAC-D009 · pac-from-file-share

PAC loaded from a file path or SMB share

medium · Delivery (HTTP headers)

A PAC on a file share is executable policy stored where many people can write. Access control on the share, not on the proxy team, now decides who controls routing. Chromium also no longer accepts file-scheme PAC URLs.

Why it matters

The PAC body is code that every client runs. On an SMB share or a local path its integrity depends on NTFS/share permissions that are rarely reviewed with that in mind. Chromium stopped supporting file:// PAC URLs years ago, so the setting silently does nothing in those browsers while Windows components may still use it. Serve the PAC from a web server with a restricted document root, over https, with fetch logging (PAC-D001).

How to fix

Move the PAC to an https web server with write access restricted to the proxy team.

Examples

Bad

# AutoConfigURL
file://fileserver.corp.example/public/wpad.dat
Open bad example in checker

Good

# AutoConfigURL
https://pac.corp.example/proxy.pac
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumfile: PAC URLs are not supported.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules