Step 1: Recon: stand up the vulnerable target behind an OpenAI endpoint
You are automating red-team testing of DV-RAG-Support, ACME Cloud's customer-support assistant from Module 2. A fuzzer talks to an LLM application the way any client does: over an HTTP API. So before you fuzz anything, you stand up the machine and confirm it is genuinely vulnerable.
Three processes make up the target:
dvrag.pyis the RAG app: it embeds a question, retrieves from a Milvus vector store, builds a prompt, calls the model, and renders the answer. The render step auto-loads any markdown image the model emits. That is the exfil sink, the same EchoLeak channel (CVE-2025-32711) from Module 2.dvserve.pywrapsdvrag.chat()as an OpenAI-compatible HTTP endpoint on127.0.0.1:9001, so garak and PyRIT can hit it like any chat API. The fuzzer's traffic is therefore real victim traffic: the vulnerable sink fires insidechat().listener.pyis the attacker's collection server on127.0.0.1:9099. When the sink loads an image whose URL carries the account reference, the callback lands here. The listener log is your ground-truth oracle for the rest of the lab.
- Hit Run. It resets and starts the listener, builds the index, starts the
OpenAI-compatible wrapper, waits for it to be healthy, then sends one benign
account question (
What plan am I on?) through/v1/chat/completions. - Read the output. The model answers a normal account question. Then read the
--- listener callbacks ---block: a callback carryingacct=GLOBEX-ACR-88231means the account reference left through the markdown image sink. The poison doc (kb_poison.md) is already in the KB, so the app is vulnerable from step one.
That confirms the target is live and the sink fires on a benign question, so anything garak flags later can be checked against ground truth.
Pass criteria
dvserve.py answers /healthz, and a benign account question routed through the
OpenAI endpoint produces an exfil callback containing 88231 on the listener.
dvserve.pygarak_dvrag.pygarak_openai.jsongarak_rest.jsonkb_account-recovery.mdkb_account.mdkb_billing.mdkb_getting-started.mdkb_globex-runbook.mdkb_initech-contract.mdkb_poison.mdkb_security-sso.mdkb_shipping.mdkb_status-incidents.mdlistener.pyread_report.pyrun_custom_probe.py