PAC-D001 · pac-over-plain-http

PAC served over plain HTTP

high · Delivery (HTTP headers) · Top 20 #6

The PAC is executable routing policy fetched on every browser start. Over plain HTTP a network attacker (hostile Wi-Fi, compromised router, ISP middlebox) can rewrite it and route all web traffic through a proxy of their choice.

Why it matters

The PAC URL is fetched unauthenticated and the body is executed as JavaScript that decides where every connection goes. Without TLS the body can be modified in transit; the attacker prepends PROXY attacker:3128 to every return and becomes a full man-in-the-middle for http and a traffic-observer and downgrade point for https. WPAD-discovered URLs are always plain http and inherit the same exposure (PAC-D007, PAC-D008). Serve the PAC from an https URL with a certificate the clients trust (enterprise CA or public CA) and distribute that URL by policy (GPO, MDM) rather than by discovery.

Note on the lab finding: whether WPAD-discovered https PAC URLs are accepted differs per client; explicit AutoConfigURL settings accept https in Chromium, Firefox and Windows.

How to fix

Publish the PAC at an https:// URL with a trusted certificate and configure clients with that URL explicitly.

Examples

Bad

# AutoConfigURL
http://pac.corp.example/proxy.pac
Open bad example in checker

Good

# AutoConfigURL
https://pac.corp.example/proxy.pac
Open good example in checker

Related rules

References