PAC served over plain HTTP
high
The PAC is executable routing policy fetched on every browser start. Over plain HTTP a network attacker (hostile Wi-Fi, compromised router, ISP middlebox) can rewrite it and route all web traffic through a proxy of their choice.
Why it matters
The PAC URL is fetched unauthenticated and the body is executed as JavaScript that decides
where every connection goes. Without TLS the body can be modified in transit; the attacker
prepends PROXY attacker:3128 to every return and becomes a full man-in-the-middle for
http and a traffic-observer and downgrade point for https. WPAD-discovered URLs are always
plain http and inherit the same exposure (PAC-D007, PAC-D008). Serve the PAC from an
https URL with a certificate the clients trust (enterprise CA or public CA) and distribute
that URL by policy (GPO, MDM) rather than by discovery.
Note on the lab finding: whether WPAD-discovered https PAC URLs are accepted differs per client; explicit AutoConfigURL settings accept https in Chromium, Firefox and Windows.
How to fix
Publish the PAC at an https:// URL with a trusted certificate and configure clients with that URL explicitly.
Examples
Related rules
- PAC distributed via WPAD DNS discovery PAC-D007
- PAC URL distributed via DHCP option 252 PAC-D008
- PAC loaded from a file path or SMB share PAC-D009