PAC-X013 · proxy-without-port

PROXY entry without a port

medium · Security and fail-safety · Top 20 #15

"PROXY proxy.corp.example" names no port. Chromium assumes 80; other engines are reported to reject the entry, and a rejected sole entry means a direct connection. Always write host:port.

Why it matters

The PAC return grammar is PROXY host:port. Chromium fills in a per-scheme default (80 for PROXY, 443 for HTTPS, 1080 for SOCKS), so the entry works there if the proxy happens to listen on that port, which enterprise proxies on 8080, 3128 or 9090 do not. Firefox and WinHTTP are reported to discard the unported entry; if nothing valid remains, the request goes DIRECT. pacparser returns the string verbatim (lab, 2026-05-20), so desk tests do not reveal the problem. This is mechanism (c) of the “silent DIRECT” family.

How to fix

Write the port explicitly, e.g. "PROXY proxy.corp.example:8080".

Examples

Bad

function FindProxyForURL(url, host) {
  return "PROXY proxy.corp.example";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumMissing port is replaced by the scheme default (PROXY 80, HTTPS 443, SOCKS/SOCKS4/SOCKS5 1080; ProxyServer::GetDefaultPortForScheme). "host:" with an empty port is rejected as an invalid entry.code, verified 2026-10-04 · ref
firefoxReported to reject the entry; needs lab confirmation.expert, unverified
pacparserReturns the unported string unchanged; no validation.lab, verified 2026-05-20
winhttpReported to reject the entry; needs lab confirmation.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References