You've heard recently about penetration testing using AI's in sand boxes that somehow escape? Read on and tell me that's not what I've just seen from OpenAI.
Today, twice, I got a few dozen hits from 172.213.2.180. User-agent is:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
My server flags "Chrome/120" as unwanted bot or residential VPN/proxy and serves "you are a bot" file. In most cases I don't know what file was being requested, but for a few of them I know the target path:
/contact-form-7/includes/js/jquery-ui/themes/smoothness/
/content-management/
/core-plugin/
/core-stab/
/core/
None of which I have on my server.
I have seen, just within the past few days, instances from other IP ranges that to me are clearly bot-originated penetration attempts. These IP ranges are not associated to the other main-line AI bots (or regular search bots) - they are IP's associated with crack-pot hosters I have never had hits from before (and as usual I block them when I see them).
The entire 172.213.0.0/16 has been a clean CIDR since I started to see hits from it last year in June and they've all been OpenAI on a few specific /24's.
But the hits I'm seeing today from 172.213.2.180 are far too close to the openai bot's Microsoft IP range (172.213.21.0/24) to be a coincidence.
Also today, the first openai hit from 9.anything (9.129.58.94 - also microsoft). Hits from 9.anything are super rare (5) with 1 in 2025 and 4 this year. I wonder what's going on recently with 9.0.0.0/8.