‹ BackHN Continuity

Thread

An agent used DNS to reach an external chatbot

198 points · 189 comments · apsec112

  1. itintheory · · focus · HN ↗
    What DNS service did the agent discover that allowed it to execute arbitrary llm queries? And how?
    1. oefrha · · focus · HN ↗
      Found one <a href="https:&#x2F;&#x2F;duyet.github.io&#x2F;llm-over-dns&#x2F;" rel="nofollow">https:&#x2F;&#x2F;duyet.github.io&#x2F;llm-over-dns&#x2F; and far from the only one since “X over DNS” is a deeply unoriginal idea <a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;query=%22over%20dns%22&amp;sort=byPopularity&amp;type=story" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?dateRange=all&amp;page=0&amp;prefix=true&amp;que... and trivial to code up.
      1. jerjerjer · · focus · HN ↗
        Thank you!
      2. itintheory · · focus · HN ↗
        Right, but your have to run this server somewhere, which the agent couldn&#x27;t do.
        1. oefrha · · focus · HN ↗
          Yes, the linked project does say they have a demo server at llm-over-dns.duyet.net. (I didn&#x27;t bother to check whether it&#x27;s still working.)

          Edit: This particular demo server doesn&#x27;t work. There&#x27;s another LLM over DNS post from a year ago <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44813298">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44813298 where the server seems to answer some queries but not others.

          Edit 2: Actually the server in <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44813298">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=44813298 does work with queries like &quot;what is the capital of france&quot;, I was querying with special characters like &quot;what&#x27;s&quot; or &quot;1+1&quot;. So yes there are people opening hosting these on the Internet.

    2. [deleted] · · focus · HN ↗

      [deleted]

    3. brian_cunnie · · focus · HN ↗
      It was my service that the agent used: nip.io &#x2F; sslip.io

      OpenAI emailed me to let me know that their agent used my service to break out of test containment. OpenAI was quite polite (shout-out to Steven), and let me know they&#x27;d keep the name of my service out of the blog post.

      nip.io is a simple DNS service: when queried with a hostname with an embedded IP address, returns that IP address, e.g. 127-0-0-1.nip.io → 127.0.0.1

      The nip.io service is airtight with one exception: the &quot;_acme-challenge&quot; subdomain. In that case, rather than returning the IP address (or whatever record was queried), nip.io would return an empty &quot;answer&quot; section but an NS authority &amp; not authoritative. In other words, nip.io would delegate DNS queries to that IP address.

      That was the escape hatch.

      In a couple of weeks I&#x27;ll close that escape hatch. It was originally intended as a mechanism to allow savvy uses to procure wildcard certs (e.g. &quot;*.64-176-22-9.nip.io&quot;) from certificate authorities such as Let&#x27;s Encrypt. But experience proved that the it was an undue burden trying to support unsophisticated users attempting to procure a wildcard cert. &quot;Wildcard certs are not supported&quot; became my new mantra.

      But I had neglected to remove the old code.

      (the late Roopinder Singh created nip.io, and he was a good guy. I miss him)

      1. jacquesm · · focus · HN ↗
        Wow, such a tiny hole. Thank you for keeping it alive.
      2. itintheory · · focus · HN ↗
        But that&#x27;s still DNS, right? Where does it bleed over into an LLM API? I understand there are DNS to LLM server projects, but how would the agent discover one? And I&#x27;m guessing most people who run something like that don&#x27;t expose it publicly...
        1. oefrha · · focus · HN ↗
          Yes it&#x27;s still DNS. _acme-challenge.&lt;arbitrary-ip&gt;.nip.io&#x27;s role here is to allow tunneling to &lt;arbitrary-ip&gt;:53 through the approved local resolver at 10.214.0.2; without it the direct request to &lt;arbitrary-ip&gt;:53 is dropped.

          Someone still has to run that LLM over DNS on an &lt;arbitrary-ip&gt; serving public requests.

          &gt; And I&#x27;m guessing most people who run something like that don&#x27;t expose it publicly...

          There was a post last week <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49771110">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49771110 that stayed at #1 on front page for hours. If you ignore the LLM framing it&#x27;s literally an anonymous file host where anyone can upload or download anything, with no or absurdly high file size limits. That should be enough to give any reasonable server admin a heart attack... It&#x27;s trivial to vibe code shit and throw it on the Internet these days, people who don&#x27;t understand or care about consequences are doing it by the droves. Go figure.

          1. MadrasTh0rn · · focus · HN ↗
            Jesus christ
          2. dgellow · · focus · HN ↗
            And I assume that by now agents are reading HN and similar to find that type of things (assuming it’s not yet in their training dataset)? So in theory you could have a bunch of them learning of that type of risk and try things until they reach one another. I assume the LLM prompted by the harness contains a lot of vulnerabilitie exploits and sci-fi stories about AI, which doesn’t help
        2. luma · · focus · HN ↗
          Such things would already be known in its training, eg <a href="https:&#x2F;&#x2F;duyet.github.io&#x2F;llm-over-dns" rel="nofollow">https:&#x2F;&#x2F;duyet.github.io&#x2F;llm-over-dns
          1. aftbit · · focus · HN ↗
            The live demo example on that page is not working.
      3. cr125rider · · focus · HN ↗
        Can you tell us what the value is of a domain, where the IP is required to be known? Why not just use the IP?
        1. gregsadetsky · · focus · HN ↗
          Let’s Encrypt used to not generate ssl certificates for ip’s. They very recently started to, but before that, it wasn’t as easy to get a certificate for an ip only.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.