3 ms·
This is a well known attack and has been for a while. There are established domain suffixes which block registration for 'wpad' (as well as a few other domains)
by DanielDent 10y ago
This is a well known attack and has been for a while. There are established domain suffixes which block registration for 'wpad' (as well as a few other domains) for exactly this reason. Which is only a partial mitigation in a world where MITM is a potential attack vector.
I have domains which receive a steady stream of 'wpad.$domain' queries from machines which have nothing to do with me. I don't know who owns the machines. I also don't think anyone would notice if I decided to actually provide them with the proxy service they keep requesting from my infrastructure.
- johncolanduoni 10y ago> I also don't think anyone would notice if I decided to actually provide them with the proxy service they keep requesting from my infrastructure. If you did so, it would make for a really interesting CFAA (or your country's equivalent) case. Unless there is precedent for this kind of thing?
- DanielDent 10y agoI'm unaware of any precedent... I could certainly see people getting upset, but I don't think they'd have solid grounds. The interesting thing is that I actually am considering setting up a WPAD entry on a domain where I am seeing that traffic, for my own purposes (i.e. unrelated to the random queries I am getting). In fact, I have just as much an argument that they would be the ones with possible CFAA liability if they start using my proxy server in a way I don't intend. The CFAA is a mess.