logo

WPAD Man in the Middle (Clear Text Passwords)

ID: 231ee0b8-f3db-5cbb-8e6a-b5459f7d98a5

STIX ID: report--231ee0b8-f3db-5cbb-8e6a-b5459f7d98a5

Feed Name: TrustedSec blog

Threat Score
60/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

This blog-style tutorial describes a practical credential-harvesting technique that abuses Internet Explorer's "Automatically detect proxy settings" behavior and name resolution fallbacks (DNS/WINS/LLMNR) to serve a malicious wpad.dat and capture clear-text HTTP basic-auth credentials using the Responder tool; the post includes installation and usage examples, captured credential output, and remediation advice (add a WPAD DNS entry or disable autodetect proxy settings via Group Policy).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.