WPAD and wpad.dat
WPAD lets clients find a PAC file without configuration. It is convenient, and it is also one of the oldest ways to hijack a whole network's web traffic.
How discovery works
When “automatically detect settings” is enabled, a client tries to find a PAC URL on its own, following the WPAD draft:
- DHCP: the client asks the DHCP server for option 252, which carries a PAC URL.
- DNS: the client looks up a host called
wpadin its DNS suffix and fetcheshttp://wpad.<suffix>/wpad.dat. If that fails, it may strip a label and try again:wpad.eng.corp.example, thenwpad.corp.example, thenwpad.example.
Whatever answers first supplies the PAC, and the PAC decides where all web traffic goes.
The risks
- The DNS walk leaves your namespace. The last steps of the walk ask for names your
organisation does not own. Public
wpadnames have been registered and abused; the 2016 US-CERT alert TA16-144A documents the name-collision attacks. See PAC-D007. - Discovery uses plain HTTP. Anyone who can tamper with the network path can rewrite the file and route all traffic through a proxy of their choice. See PAC-D001.
- DHCP is unauthenticated. Any device that answers DHCP on the segment can hand out its own PAC URL.
Doing it safely
- Distribute the PAC URL explicitly (group policy, MDM, configuration management) and serve it over HTTPS.
- If you must keep WPAD, create an authoritative
wpadrecord in every internal DNS suffix and blockwpad.*lookups to the internet at your resolvers. - Serve the file with
Content-Type: application/x-ns-proxy-autoconfigand an explicitCache-Control: max-age=…of at most a day (PAC-D002, PAC-D003). - Make sure the file ends with an unconditional
return, so that clients never fall back to a direct connection by accident (PAC-X001).
You can paste the output of curl -sI https://pac.corp.example/proxy.pac into the
checker to grade the delivery headers along with the file itself.
References
- WPAD Internet-Draft (draft-ietf-wrec-wpad-01)
- US-CERT TA16-144A: WPAD name collision vulnerability
- MDN: Proxy Auto-Configuration (PAC) file
Frequently asked questions
What is the difference between proxy.pac and wpad.dat?
None in content. Both are PAC files with a FindProxyForURL function. wpad.dat is the file name that WPAD discovery asks for; proxy.pac is the conventional name when the URL is configured explicitly.
Which MIME type should a PAC file be served with?
application/x-ns-proxy-autoconfig. Most browsers do not insist on it, but an application/octet-stream or text/html response usually means the server is not set up for the file or is returning an error page.
Should I use WPAD at all?
Prefer distributing the PAC URL explicitly through group policy or MDM, served over HTTPS. Use WPAD only where you cannot configure clients, own every wpad name in your DNS suffixes and stop wpad lookups from leaving your network.
How long do browsers cache a PAC file?
That depends on the engine and on Cache-Control. Set an explicit max-age of at most one day so you know how long a change takes to reach every client.