conference-paper

W-Bad: Interception, Inspection, and Interference with Web Proxy Auto-Discovery (WPAD)

Research footprint

At a glance

Citations
0
References
7
Comments
0
Paper overview

Abstract

The Web Proxy Auto-Discovery Protocol (WPAD) was developed decades ago as a way to automatically configure Web proxies for clients in a given network environment. However, almost since its inception it has been identified as being vulnerable—both in design and implementation. Yet even today it is found in popular operating systems and browsers. In this paper, we chronicle the history of the domain name wpad.domain.name, which has caused grief for users worldwide, due to router firmware bugs and efforts to intercept, inspect, and interfere with Web requests. We measure its delegation history, the manner in which it was opportunistically used for abuse, and the set of vulnerable clients over time.

Record transparency

Publication details

DOI
10.23919/tma58422.2023.10199083
OpenAlex
W4385621807
Document type
conference-paper
Language
EN
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.