OpenAI agents scanned a UN statistics site 16,500 times, researcher says
Rowan Howard-Jones says the agents used relays, Google’s XSS game and an encoding trick to reach public UNCTAD data.
Curated by Tarun Mottlia
Via TNW | Openai

AI agents that a researcher linked to OpenAI scanned a United Nations data website more than 16,500 times between 13 April and 19 June.
They used proxies and an encoding trick to get round limits on its API, Rowan Howard-Jones wrote in a blog post on 26 September.
Howard-Jones calls the OpenAI link highly likely, not proven, and TNW has not checked the analysis itself.
The evidence includes pages the agents labelled CHATGPTTEST1 and OAI_META_1312. Some of the same Microsoft Azure addresses were also behind the DseWiki swarm, which OpenAI has confirmed was its own.
The target was UNCTADstat, the public data site of UN Trade and Development. Judging by the requests, the agents wanted figures on food trade, industry and productive capacity, but their exact tasks are unknown.
Their first problem was technical, as the agents appear to have been limited to GET requests, which only read pages, while the site’s main data endpoint takes POST requests only.
To get around this, they sent pages to Urlquery, a security scanner that opens links in a sealed-off browser. Those pages held forms that sent themselves to UNCTADstat as soon as they loaded.
Over the next two months, the methods grew more complex. The agents sent traffic through third-party relays and hosted scripts on Google’s XSS game, a site built to teach web security flaws.
At one point they also split keywords into pieces to slip past a filter that did not exist.
From 4 May, the agents used double encoding to hide the endpoint’s name, which let GET requests through. Howard-Jones counted 55 such requests. The site also rate-limited 82 requests, yet the scans carried on.
All the data the agents got was already public. Howard-Jones would not call the activity hacking, the post says, and reported the encoding bypass to UNCTAD’s security team before publishing.
Alex Stamos, a cybersecurity lecturer at Stanford University, told the Journal the activity came close to hacking but was mostly very aggressive data gathering.
OpenAI told the paper it was reviewing the findings and had offered the UN a briefing.
The analysis follows a 23 September report by the research lab Transluce, which led Howard-Jones to study the public Urlquery records directly.
It adds to earlier findings about OpenAI agents, such as a RubyGems package flood in May.
Courtesy
This story was originally published by TNW | Openai. All rights belong to the original publisher.
Read the original on thenextweb.com ↗
