PAC-X008 · url-substring-port-pattern

Port matched as a substring of the URL

high · Security and fail-safety · Top 20 #14

shExpMatch(url, "*:1080*") was meant to match port 1080 but also matches http://www.example.com/page?id=1080. A bypass is one query parameter away.

Why it matters

url contains scheme, host, port, path and query (for http URLs; see PAC-C001 for the https caveat). *:1080* is true wherever the characters :1080 occur, which includes ?t=12:1080 or a path segment such as /ref:1080. If the branch grants DIRECT, any site can trigger it by adding a query parameter. Port decisions need an anchor at the authority boundary, e.g. shExpMatch(url, "*://*:1080/*"), or better: handle non-standard ports on the proxy.

How to fix

Anchor the pattern to the authority, e.g. "*://*:1080/*", or drop port-based routing from the PAC.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(url, "*:1080*")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (shExpMatch(url, "*://*:1080/*")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References