<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://leo.leung.xyz/wiki/index.php?action=history&amp;feed=atom&amp;title=Web_Proxy_Auto-Discovery</id>
	<title>Web Proxy Auto-Discovery - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://leo.leung.xyz/wiki/index.php?action=history&amp;feed=atom&amp;title=Web_Proxy_Auto-Discovery"/>
	<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=Web_Proxy_Auto-Discovery&amp;action=history"/>
	<updated>2026-10-09T01:26:24Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=Web_Proxy_Auto-Discovery&amp;diff=6483&amp;oldid=prev</id>
		<title>Leo: Added networking category</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=Web_Proxy_Auto-Discovery&amp;diff=6483&amp;oldid=prev"/>
		<updated>2021-12-30T02:26:30Z</updated>

		<summary type="html">&lt;p&gt;Added networking category&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 02:26, 30 December 2021&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l29&quot;&gt;Line 29:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 29:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Protocol&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Protocol&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[Category:Networking]]&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key wiki:diff:1.41:old-5201:rev-6483:php=table --&gt;
&lt;/table&gt;</summary>
		<author><name>Leo</name></author>
	</entry>
	<entry>
		<id>https://leo.leung.xyz/wiki/index.php?title=Web_Proxy_Auto-Discovery&amp;diff=5201&amp;oldid=prev</id>
		<title>Leo: Created page with &quot;The Web Proxy Auto-Discovery Protocol (WPAD) is used by organizations to automatically configure the proxy server on clients connected to a network. This is useful if the orga...&quot;</title>
		<link rel="alternate" type="text/html" href="https://leo.leung.xyz/wiki/index.php?title=Web_Proxy_Auto-Discovery&amp;diff=5201&amp;oldid=prev"/>
		<updated>2020-06-21T17:29:41Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;The Web Proxy Auto-Discovery Protocol (WPAD) is used by organizations to automatically configure the proxy server on clients connected to a network. This is useful if the orga...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The Web Proxy Auto-Discovery Protocol (WPAD) is used by organizations to automatically configure the proxy server on clients connected to a network. This is useful if the organization has network resources that are only accessible via a proxy server.  &lt;br /&gt;
&lt;br /&gt;
WPAD could be abused on an untrusted network (such as public WiFi networks) to configure your computer to use an attacker&amp;#039;s proxy server and expose you to MITM attacks. While most operating systems support this protocol but have it disabled, Windows has this feature enabled by default which may be a security risk. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== How it works ==&lt;br /&gt;
The location of the WPAD file is probed first from DHCP.  With [[dnsmasq]], the WPAD option is set with DHCP option &amp;lt;code&amp;gt;252&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
If the DHCP server does not offer any information, attempts to obtain the file will be performed from a &amp;#039;&amp;lt;code&amp;gt;wpad&amp;lt;/code&amp;gt;&amp;#039; host on the network&amp;#039;s domain. If the file does not exist, it will try again on the parent domain until it is at the root domain. For example, if the client is at &amp;lt;code&amp;gt;pc.office.example.com&amp;lt;/code&amp;gt;, the WPAD file is obtained from &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;http://wpad.office.example.com/wpad.dat&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;, or if that fails, from &amp;lt;code&amp;gt;&amp;lt;nowiki&amp;gt;http://wpad.example.com/wpad.dat&amp;lt;/nowiki&amp;gt;&amp;lt;/code&amp;gt;. The file must be served with a MIME type of &amp;lt;code&amp;gt;application/x-ns-proxy-autoconfig&amp;lt;/code&amp;gt; or &amp;lt;code&amp;gt;application/x-javascript-config&amp;lt;/code&amp;gt; in order to be valid.&lt;br /&gt;
&lt;br /&gt;
The &amp;lt;code&amp;gt;wpad.dat&amp;lt;/code&amp;gt; file contains a proxy auto-config (PAC) script.  This script defines a javascript function &amp;lt;code&amp;gt;FindProxyForURL(url, host)&amp;lt;/code&amp;gt; which returns either &amp;lt;code&amp;gt;DIRECT&amp;lt;/code&amp;gt; for a direct connection or the proxy protocol and servername &amp;lt;code&amp;gt;PROXY proxy-server:port&amp;lt;/code&amp;gt;. &lt;br /&gt;
&lt;br /&gt;
== Security Issue ==&lt;br /&gt;
On a any network, an attacker could launch a MITM attack by setting up a rogue DHCP server and directing clients to the attacker&amp;#039;s PAC file. All traffic would then be routed through the attacker&amp;#039;s proxy server and users would be none the wiser since typically nothing warns the user a proxy server is being used.&lt;br /&gt;
&lt;br /&gt;
Additionally, unlike a regular MITM attack where HTTPS is entirely protected, the use of a PAC script allows an attacker to expose the URL that you are accessing even with HTTPS. This could be done by leaking your URL by encoding it as part of the proxy server domain.&lt;br /&gt;
&lt;br /&gt;
== Disabling in Windows ==&lt;br /&gt;
&lt;br /&gt;
=== Windows 10 ===&lt;br /&gt;
Open the settings window and search for &amp;#039;Proxy Settings&amp;#039;. Switch the &amp;#039;Automatically detect settings&amp;#039; to off.&lt;br /&gt;
[[File:Windows 10 Automatic Proxy Setup.png|alt=Windows 10 Automatic Proxy Setup|center|thumb|Windows 10 Automatic Proxy Setup]]&lt;br /&gt;
&lt;br /&gt;
== Windows 7 ==&lt;br /&gt;
Go to Control Panel, Network and Internet, Internet Options. Under Internet Properties, Connections tab, click &amp;#039;LAN settings&amp;#039; button. Ensure that &amp;#039;Automatically detect settings&amp;#039; is unchecked.&lt;br /&gt;
&lt;br /&gt;
= See Also =&lt;br /&gt;
&lt;br /&gt;
* https://en.wikipedia.org/wiki/Web_Proxy_Auto-Discovery_Protocol&lt;/div&gt;</summary>
		<author><name>Leo</name></author>
	</entry>
</feed>