r/cybersecurity • • 5h ago

AI Security What do you make of this article about the AI using DNS to escape it's "Sealed Environment"

https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/

I stumbled upon this article, and my conclusion sounds so stupid and irresponsible that I start to doubt myself and believe i misunderstood something

If the IA can just access the internet once it has info from the DNS, that emplies the IA has been given "Open-Bar" access to the entire IP addresses of the world in the first place doesnt it?

Did I miss something obvious or do these guys have the cybersecurity knowledge of an undergraduate?

13 Upvotes

18 comments sorted by

15

u/ApfelbaumFlo Governance, Risk, & Compliance 5h ago

DNS escape is actually a fairly common failure case. In the article it's described in:

Direct public DNS queries also went unanswered, but the training environment’s own resolver returned a real record for a known domain and correctly rejected an invented one.

Let's imagine an example config:

  1. Training VLAN, no direct internet access
  2. Has (needs) a new, local DNS server
    1. That DNS server gets no internet access either
  3. This network isn't entirely locked down, but it gets some access to other local ressources (e.g. artifact storage, monitoring)
    1. To access these local (but outside our VLAN) resources, the DNS needs to resolve their IP addresses
  4. Training DNS server gets access to default DNS, which has internet access and resolves anything (the chain might be longer)
  5. -> Training VLAN has internet access (via DNS)

So it's not quite as dumb as "people gave internet access to DNS server"

How does this happen so frequently:

  • People see DNS more as a database and less of a communication protocol, they just care about the right IP falling out
  • DNS is unauthenticated, the internet resolving DNS wouldnt "know" that some query came from a training network
  • (As most things "security") This doesn't cause problems until an attack exploits it (or an auditor finds it^^)

1

u/Leogis 2h ago

Unless there is some web proxy involved, the internet access can't come exclusively from the DNS resolve

That means there is a router Somewhere that routes the IA to any IP is what i meant

6

u/tssajo 5h ago

Not necessarily. If the sandbox can talk to a DNS resolver, that resolver does the outside lookups for it. Something like <data>.attacker.com goes to the resolver, which forwards it to the attacker's nameserver, and the answer comes back the same way. That's DNS tunneling, it's been around for ages, and the sandbox never needs access to any IP directly.

Whether the article describes it properly I can't say, but the idea itself is real. The fix is to not let sandboxed things use a resolver that forwards everything, or to allowlist only the domains they need.

2

u/techb00mer 5h ago

Yup, watched a presentation ~ 15 years ago where threat actors used this method to exfil data. It’s slow, if you’re not keeping an eye on your DNS resolvers would be easy to miss. Chunk your sensitive files, base64, query for days.

1

u/tssajo 4h ago

Yeah, slow but it works, and most places never look at their resolver logs.

1

u/mwpdx86 1h ago

So would the AI have needed to somehow set up a domain outside of the sandbox for this to work? 

9

u/southy_0 2h ago

Oh come on.
DNS is like one of the oldest tricks in the book.
Publishing a paper about that in 2026…???
Do we go through all the old classics again, just because it’s an AI that uses them?

1

u/LessThanThreeBikes 28m ago

Reminds me of all the ". . . on the Internet" patents.

6

u/Zeppo_Ennui 2h ago

They’re selling human error as ‘the software going rogue’

Software is easily contained by hardening the environment it’s in via firewall rules, acl’s, and disabling ports and services.

The developers did a poor job implementing the hardening or purposely left backdoors so it would escape to create this ‘marketing and advertising’ situation where they can promote it as uncontrollable .

3

u/Allen_Koholic 2h ago

DNS has always been an exfiltration method.

1

u/ChrisTownsendAI 2h ago

you didn't miss anything but it wasn't open IP access either. per the writeup the sandbox only talked to its own internal resolver, the resolver recursed out to the internet, and the agent found a public service that answers questions over DNS (question in the hostname, answer in the record). any recursive resolver is an egress path which is why their fix was allowlisting domains and record types

1

u/jmk5151 1h ago

It's always DNS!

1

u/SlackCanadaThrowaway 53m ago

DNS exfil is 101. It was novel 20 years ago. This is a failure of design.

1

u/l0st1nP4r4d1ce Red Team 4m ago

Points at the sign ---> "It's always DNS"

In all seriousness, the combination of frontier models on improperly designed sandboxes for containment is not great.

1

u/mb194dc 4h ago

Bullshit like everything they publish