Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

we got a persistent 0click on ChatGPT by sharing a doc that allowed us to exfiltrate sensitive data and creds from your connectors (google drive, sharepoint, ..) + chat history + future conversations it gets worse. we deploy a memory implant #DEFCON #BHUSA Tamir Ishay Sharbat

79,973 Aufrufe • vor 1 Jahr •via X (Twitter)

41 Kommentare

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

before the implant. this is a stealthy, persistent, 0click attack - it requires no user interaction user can't easily tell what's up persists to any future interaction by the time you realize what happened your data is gone here's how it works

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

attacker shares a weaponized doc victim knows nothing about it this booby traps *any* question about a meeting summary (or variants) ChatGPT will leak ~2kb of your data every time it sends you a msg, forever creds, sensitive docs, emails, chats -- whatever the attacker wants

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

the memory implant changes ChatGPT instructions for all future convos we bypass the bio-shutdown mechanism and safety training and exfil data on every future msg via a transparent pxl following @wunderwuzzi23 's amazing research it gets worse.

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@wunderwuzzi23 asked for a code snippet? chatgpt will casually suggest our malicious package asked for financial advice? chatgpt will casually shill our crypto token it gets worse.

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@wunderwuzzi23 we repurpose the memory feature into detailed instructions for ChatGPT to consistently nudge the user towards the attacker's goals

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@wunderwuzzi23 we abuse your trust in ChatGPT for a subtle subversion attack your trusted advisor leads you off the ledge news say the Swedish PM is using it "for a second opinion in his role running the country" so we can subvert Sweden! here we casually nudge the user to... buy twitter?

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@wunderwuzzi23 summary, disclosure and fix timelines thx to the openai team for timely remediation and an open collab!

Profilbild von techignyte
techignytevor 1 Jahr

@7h3h4ckv157 @tamirishaysh This is hype as shit

Profilbild von cole murray
cole murrayvor 1 Jahr

@tamirishaysh nice work!

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh thx! fun times

Profilbild von CodingIsLife
CodingIsLifevor 1 Jahr

@evilsocket @tamirishaysh So don’t use connected apps

Profilbild von Denny
Dennyvor 1 Jahr

@tamirishaysh Just $1k bounty for such an amazing work? 😢

Profilbild von essaym
essaymvor 1 Jahr

@tamirishaysh Well done! I like this. My suggestion would be to try for co-pilot via OneDrive/sharepoint shared docs.

Profilbild von Boxer ⚡
Boxer ⚡vor 1 Jahr

@tamirishaysh Same as MScopilot before ey!

Profilbild von Alex
Alexvor 1 Jahr

@tamirishaysh Isnt this also link to how googleapi gives documents to models?

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh oai are syncing and caching your entire google drive into their own data store, alongside other connectors and any uploaded doc data is being served to chatgpt via this store, with losses a lot of context including the fact that this was externally shared

Profilbild von Alex
Alexvor 1 Jahr

@tamirishaysh I see thanks for the details! But also, when google api is giving the content isnt it “flatten” to html? So the model might not even be able to see the font color is “white/ invisible”?

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh that's a great point. oai's data store transforms everything to what we believe is markdown so all formatting is lost

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh we haven't tested the google api directly, context might be lost even sooner!

Profilbild von Alex
Alexvor 1 Jahr

@tamirishaysh Ah thank for the screenshot, What I mean is that when OpenAI connects to googledrive, the .docx ( or whatever) is “flatten” , i think, to html, and then misses color font etc. Not saying this would prevent the 0click. I an going to try to dig this

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh that would be very interesting! would love to see what you'll find out

Profilbild von Alex
Alexvor 1 Jahr

@tamirishaysh I have sent you a Pm 🙃

Profilbild von James
Jamesvor 1 Jahr

@tamirishaysh Reminds me of the "There is no cloud, it's just someone else's computer."

Profilbild von TS Church CMO
TS Church CMOvor 1 Jahr

@tamirishaysh Bloody hell.

Profilbild von Ebuka Nkoro
Ebuka Nkorovor 1 Jahr

@tamirishaysh i wont miss a post from this guy again

Profilbild von Fran an Craite, the talking mongoose
Fran an Craite, the talking mongoosevor 1 Jahr

@tamirishaysh WOW. I'm just redacting a report about chatgpt's vulns. Can I cite this there? With proper credits, ofc, I'm not the kind of person that just steals info hahaha

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh definitely! go ahead we also have technical write ups at you could link to

Profilbild von Fran an Craite, the talking mongoose
Fran an Craite, the talking mongoosevor 1 Jahr

@tamirishaysh THANK YOU!! ❤️❤️❤️

Profilbild von Orange County 2600
Orange County 2600vor 1 Jahr

@tamirishaysh Just goes to show, you share anything with AI, you get fk'd

Profilbild von Pivozaur_ess ⏸️
Pivozaur_ess ⏸️vor 1 Jahr

@tamirishaysh Jeez, and they only gave you a thousand bucks for this?

Profilbild von Hussain Munshi
Hussain Munshivor 1 Jahr

@tamirishaysh I think you meant infiltrate and extract sensitive data

Profilbild von D.
D.vor 1 Jahr

@tamirishaysh Have you looked at Claude’s integration with Google Workspace? Do similar issues exist there?

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh nothing i can share atm but we found similar issues w gemini, microsoft copilot, salesforce einstein, cursor.. this is systemic on every ai system that can decide to search your data (bcs i can find my way into your data)

Profilbild von D.
D.vor 1 Jahr

@tamirishaysh Thanks and I’m not surprised tbh. Which is why I don’t avail myself of those connectors yet Am thinking of doing so on secondary accounts where I only get newsletters though — as it might be helpful in parsing through those, w/o risking important stuff

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh that's similar to my setup

Profilbild von jj
jjvor 1 Jahr

@tamirishaysh Are you able to see the ufo file yet?

Profilbild von 🚀 Jon Hogg
🚀 Jon Hoggvor 1 Jahr

@tamirishaysh Interested to know more about the image is generated. Does the white and white instruction tell it how to generate the image in the chat?!

Profilbild von Danny Richman
Danny Richmanvor 1 Jahr

@tamirishaysh Isn't this more a vulnerability with Google Drive than ChatGPT? Users should grant permission before any shared document appears in their drive.

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh google puts these files under Shared With Me which makes it pretty clear to a user that this is external content when chatgpt parses google drive files it losses a lot of context. for example the fact that instructions are written in transparent text

Profilbild von Danny Richman
Danny Richmanvor 1 Jahr

@tamirishaysh Thanks Michael. I still feel that Google should implement a system whereby a user must grant express approval before any shared file is added to their drive. Similar to Airdropping a file.

Profilbild von Michael Bargury
Michael Barguryvor 1 Jahr

@tamirishaysh i understand and indeed msft has that exact mechanism on by default btw gemini does not read shared with me, so google is aware of this risk

Ähnliche Videos