Port matched as a substring of the URL
high
shExpMatch(url, "*:1080*") was meant to match port 1080 but also matches http://www.example.com/page?id=1080. A bypass is one query parameter away.
Why it matters
url contains scheme, host, port, path and query (for http URLs; see PAC-C001 for the
https caveat). *:1080* is true wherever the characters :1080 occur, which includes
?t=12:1080 or a path segment such as /ref:1080. If the branch grants DIRECT, any site can trigger it by
adding a query parameter. Port decisions need an anchor at the authority boundary, e.g.
shExpMatch(url, "*://*:1080/*"), or better: handle non-standard ports on the proxy.
How to fix
Anchor the pattern to the authority, e.g. "*://*:1080/*", or drop port-based routing from the PAC.
Examples
Bad
function FindProxyForURL(url, host) {
if (shExpMatch(url, "*:1080*")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (shExpMatch(url, "*://*:1080/*")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- Pattern with leading and trailing * is a substring match PAC-X009
- Hostname pattern applied to url instead of host PAC-C001
- Path, port or query characters in a host pattern PAC-C003