PAC-X004 · shexpmatch-leading-asterisk-without-dot

Leading * without a dot matches look-alike domains

high · Security and fail-safety · Top 20 #5

shExpMatch(host, "*corp.example") matches badcorp.example as well as www.corp.example. The safe form is "*.corp.example", where the dot forces a label boundary.

Why it matters

Without the dot, the leading wildcard can absorb part of a label. *corp.example is true for www.corp.example, but also for badcorp.example and notcorp.example, which anyone could register. This is the glob twin of PAC-X003. *.example.com requires at least one full label before the dot and only matches real subdomains; the apex itself then needs its own clause.

How to fix

Use "*.example.com" (with the dot) and add host == "example.com" for the apex.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*example.com")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "example.com" || shExpMatch(host, "*.example.com")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
pacparser"*example.com" matches a look-alike domain ending in "example.com"; "*.example.com" does not.lab, verified 2026-05-20

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References