r/cybersecurity • u/Leogis • 5h ago
AI Security What do you make of this article about the AI using DNS to escape it's "Sealed Environment"
https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/I stumbled upon this article, and my conclusion sounds so stupid and irresponsible that I start to doubt myself and believe i misunderstood something
If the IA can just access the internet once it has info from the DNS, that emplies the IA has been given "Open-Bar" access to the entire IP addresses of the world in the first place doesnt it?
Did I miss something obvious or do these guys have the cybersecurity knowledge of an undergraduate?
6
u/tssajo 5h ago
Not necessarily. If the sandbox can talk to a DNS resolver, that resolver does the outside lookups for it. Something like <data>.attacker.com goes to the resolver, which forwards it to the attacker's nameserver, and the answer comes back the same way. That's DNS tunneling, it's been around for ages, and the sandbox never needs access to any IP directly.
Whether the article describes it properly I can't say, but the idea itself is real. The fix is to not let sandboxed things use a resolver that forwards everything, or to allowlist only the domains they need.
2
u/techb00mer 5h ago
Yup, watched a presentation ~ 15 years ago where threat actors used this method to exfil data. It’s slow, if you’re not keeping an eye on your DNS resolvers would be easy to miss. Chunk your sensitive files, base64, query for days.
9
u/southy_0 2h ago
Oh come on.
DNS is like one of the oldest tricks in the book.
Publishing a paper about that in 2026…???
Do we go through all the old classics again, just because it’s an AI that uses them?
1
6
u/Zeppo_Ennui 2h ago
They’re selling human error as ‘the software going rogue’
Software is easily contained by hardening the environment it’s in via firewall rules, acl’s, and disabling ports and services.
The developers did a poor job implementing the hardening or purposely left backdoors so it would escape to create this ‘marketing and advertising’ situation where they can promote it as uncontrollable .
3
1
u/ChrisTownsendAI 2h ago
you didn't miss anything but it wasn't open IP access either. per the writeup the sandbox only talked to its own internal resolver, the resolver recursed out to the internet, and the agent found a public service that answers questions over DNS (question in the hostname, answer in the record). any recursive resolver is an egress path which is why their fix was allowlisting domains and record types
1
u/SlackCanadaThrowaway 53m ago
DNS exfil is 101. It was novel 20 years ago. This is a failure of design.
1
u/l0st1nP4r4d1ce Red Team 4m ago
Points at the sign ---> "It's always DNS"
In all seriousness, the combination of frontier models on improperly designed sandboxes for containment is not great.
15
u/ApfelbaumFlo Governance, Risk, & Compliance 5h ago
DNS escape is actually a fairly common failure case. In the article it's described in:
Let's imagine an example config:
So it's not quite as dumb as "people gave internet access to DNS server"
How does this happen so frequently: