DMIT:攻击者正在大规模利用 TCP 443 应用设计缺陷,向 OpenAI 发送超大规模请求

Erythritol 2026-08-28 02:36 1



原文:

DMIT proactive security detected that 2% of tenants were deploying potentially risky applications in the DMIT LAX data center. These tenants’ applications sent significant large traffic to China several hours ago.



  • DMIT detected abnormal traffic within the network 12 hours ago but took no action due to complexity.

  • However, this potential risk factor was officially exploited 8 hours ago.

  • DMIT will officially notify affected customers within 12 hours and require them to resolve the issue within 24 hours to avoid service interruption for a long time and abuse penalties.

  • The relevant users will receive an email soon, and the VM will be immediately shut down to avoid the transfer being used up. (DMIT will not recover this transfer quota since it was due to the client’s unsafe application.)


This vulnerable application cannot directly generate such a large amount of traffic, even though it is open to the internet. Exploiting this type of vulnerability requires real data and requests; it does not possess amplification characteristics.


DMIT initially speculates that attackers in restricted areas are exploiting this TCP 443 application design flaw on a large scale to make super-large-scale real and accepted requests to OpenAI.


Further details will be officially provided after the issue is resolved.

最新回复 (8)
  • 天天开心 08-28 02:39
    1

    没理解错的话,这是不想让用户拿大妈当中转openai的线路机了。如果我的理解没搞错,这不纯纯败坏自己在中国用户人群的口碑吗 ^-^

  • fuermo 08-28 02:43
    2

    按照这个公告的说辞是程序有问题导致服务器被利用当ddos机器了,不是单纯当中转

  • danielR 08-28 02:45
    3

    向 OPENAI 发请求,发光波,干奥特曼?发公告,以后用DMIT 可能要被定向降智?无限联想~^-^

  • Erythritol 楼主 08-28 02:47
    4

    我也感觉被用来ddos了,就是不清楚说的“应用设计缺陷”源自于哪个应用

  • 天天开心 08-28 02:48
    5

    你看,我的理解是这样:首先443端口是常用于代理,然后“受限地区”,是中国受到openai的服务条款限制,“百分之2的用户”,说明用户规模庞大,不像是漏洞,“未经放大”就是指正常的请求,但是大量。“因复杂性未采取行动”就是大妈说我知道这不是漏洞,但我不能明着说。我是这么理解的。(当然这只是我的解读,不一定对,当个参考)

  • liansishen 08-28 02:56
    6

    按照公告所说,12个小时前检测到的,应该不是线路机的问题。

    线路机起码已经存在好几个月了

  • 天天开心 08-28 02:57
    7

    有可能。难道是哪个开源中转项目出漏洞了 ^-^

  • c.skeleton 08-28 03:06
    8

    要么是开源项目的漏洞,要么是用户的 ai slop 出 bug 了。

    当然也有可能是有小白用户的服务器安全配置不够被人 ssh 上去了

* 帖子来源Linux.do
返回