conference-paper
W-Bad: Interception, Inspection, and Interference with Web Proxy Auto-Discovery (WPAD)
Research footprint
At a glance
- Citations
- 0
- References
- 7
- Comments
- 0
Paper overview
Abstract
The Web Proxy Auto-Discovery Protocol (WPAD) was developed decades ago as a way to automatically configure Web proxies for clients in a given network environment. However, almost since its inception it has been identified as being vulnerable—both in design and implementation. Yet even today it is found in popular operating systems and browsers. In this paper, we chronicle the history of the domain name wpad.domain.name, which has caused grief for users worldwide, due to router firmware bugs and efforts to intercept, inspect, and interfere with Web requests. We measure its delegation history, the manner in which it was opportunistically used for abuse, and the set of vulnerable clients over time.
Record transparency
Publication details
- DOI
- 10.23919/tma58422.2023.10199083
- OpenAlex
- W4385621807
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.