Wildcard inside a domain label
medium
shExpMatch(host, "corp*.example") matches corp.example and corp-cdn.example but also corpevil.example. A wildcard inside a label spans arbitrary registrable names.
Why it matters
* in shExpMatch matches any run of characters, including dots. corp*.example is true
for corp.example, corp1.example and corpevil.example, and for corp.evil.example-style
names because the wildcard also absorbs dots. The owner’s lab confirmed the same with
example*.com (2026-05-20). The pattern is almost always an attempt to cover a few related
domains; list them explicitly instead.
How to fix
Enumerate the intended domains (host == "corp.example" || host == "corp-cdn.example") or use "*.corp.example" for subdomains.
Examples
Bad
function FindProxyForURL(url, host) {
if (shExpMatch(host, "corp*.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (host == "corp.example" || host == "corp-cdn.example" || shExpMatch(host, "*.corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| pacparser | A pattern of the form "name*.tld" matches look-alike names with extra characters before the TLD. | lab, verified 2026-05-20 |
Related rules
- Trailing * in a host pattern matches attacker-controlled suffixes PAC-X002
- Leading * without a dot matches look-alike domains PAC-X004