OpenAI's ChatGPT crawler can be tricked into DDoSing sites, answering your queries
ID: 9182ac45-9542-53b8-86a6-a8d6fc0829fe
STIX ID: report--9182ac45-9542-53b8-86a6-a8d6fc0829fe
Feed Name: The Register (Security)
A security researcher disclosed that OpenAI's ChatGPT crawler (via the attributions API) can be abused as an unauthenticated reflective DDoS amplifier: by supplying many slightly different URLs that resolve to the same site, a single API call causes the crawler to issue dozens to thousands of requests to the victim, potentially overwhelming it. The advisory highlights missing URL deduplication and limits, possible prompt-injection risks, and states the reporter contacted OpenAI/Microsoft with no acknowledged remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
