PAC-X005 · tld-only-pattern

Pattern matches an entire top-level domain

high · Security and fail-safety · Top 20 #8

shExpMatch(host, "*.de") or dnsDomainIs(host, ".com") routes a whole country or generic TLD. In the usual "proxy everything, except..." PAC this bypasses inspection for millions of unrelated sites.

Why it matters

Enterprise PACs mostly send everything to the proxy and list exceptions that go DIRECT. A TLD-only exception does not scope a policy to “our German sites”; it exempts every .de site on the internet from the proxy. The usual cause is a typo: .example.de (the subsidiary’s domain) was intended and .de was written.

Legitimate uses exist in multi-country deployments, e.g. routing *.il to an in-country proxy. Those should be rare, deliberate and commented. Two-label public suffixes (*.co. followed by a country code) have the same effect and are flagged when they are in the sample list.

How to fix

Replace the TLD with the actual second-level domain, e.g. "*.example.de"; if the TLD routing is intended, add a comment saying so.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*.de")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "example.de" || shExpMatch(host, "*.example.de")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References