WPAD and wpad.dat

WPAD lets clients find a PAC file without configuration. It is convenient, and it is also one of the oldest ways to hijack a whole network's web traffic.

How discovery works

When “automatically detect settings” is enabled, a client tries to find a PAC URL on its own, following the WPAD draft:

  1. DHCP: the client asks the DHCP server for option 252, which carries a PAC URL.
  2. DNS: the client looks up a host called wpad in its DNS suffix and fetches http://wpad.<suffix>/wpad.dat. If that fails, it may strip a label and try again: wpad.eng.corp.example, then wpad.corp.example, then wpad.example.

Whatever answers first supplies the PAC, and the PAC decides where all web traffic goes.

The risks

  • The DNS walk leaves your namespace. The last steps of the walk ask for names your organisation does not own. Public wpad names have been registered and abused; the 2016 US-CERT alert TA16-144A documents the name-collision attacks. See PAC-D007.
  • Discovery uses plain HTTP. Anyone who can tamper with the network path can rewrite the file and route all traffic through a proxy of their choice. See PAC-D001.
  • DHCP is unauthenticated. Any device that answers DHCP on the segment can hand out its own PAC URL.

Doing it safely

  1. Distribute the PAC URL explicitly (group policy, MDM, configuration management) and serve it over HTTPS.
  2. If you must keep WPAD, create an authoritative wpad record in every internal DNS suffix and block wpad.* lookups to the internet at your resolvers.
  3. Serve the file with Content-Type: application/x-ns-proxy-autoconfig and an explicit Cache-Control: max-age=… of at most a day (PAC-D002, PAC-D003).
  4. Make sure the file ends with an unconditional return, so that clients never fall back to a direct connection by accident (PAC-X001).

You can paste the output of curl -sI https://pac.corp.example/proxy.pac into the checker to grade the delivery headers along with the file itself.

References

Frequently asked questions

What is the difference between proxy.pac and wpad.dat?

None in content. Both are PAC files with a FindProxyForURL function. wpad.dat is the file name that WPAD discovery asks for; proxy.pac is the conventional name when the URL is configured explicitly.

Which MIME type should a PAC file be served with?

application/x-ns-proxy-autoconfig. Most browsers do not insist on it, but an application/octet-stream or text/html response usually means the server is not set up for the file or is returning an error page.

Should I use WPAD at all?

Prefer distributing the PAC URL explicitly through group policy or MDM, served over HTTPS. Use WPAD only where you cannot configure clients, own every wpad name in your DNS suffixes and stop wpad lookups from leaving your network.

How long do browsers cache a PAC file?

That depends on the engine and on Cache-Control. Set an explicit max-age of at most one day so you know how long a change takes to reach every client.