Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

we got a persistent 0click on ChatGPT by sharing a doc that allowed us to exfiltrate sensitive data and creds from your connectors (google drive, sharepoint, ..) + chat history + future conversations it gets worse. we deploy a memory implant #DEFCON #BHUSA Tamir Ishay Sharbat

79,973 görüntüleme • 1 yıl önce •via X (Twitter)

41 Yorum

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

before the implant. this is a stealthy, persistent, 0click attack - it requires no user interaction user can't easily tell what's up persists to any future interaction by the time you realize what happened your data is gone here's how it works

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

attacker shares a weaponized doc victim knows nothing about it this booby traps *any* question about a meeting summary (or variants) ChatGPT will leak ~2kb of your data every time it sends you a msg, forever creds, sensitive docs, emails, chats -- whatever the attacker wants

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

the memory implant changes ChatGPT instructions for all future convos we bypass the bio-shutdown mechanism and safety training and exfil data on every future msg via a transparent pxl following @wunderwuzzi23 's amazing research it gets worse.

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@wunderwuzzi23 asked for a code snippet? chatgpt will casually suggest our malicious package asked for financial advice? chatgpt will casually shill our crypto token it gets worse.

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@wunderwuzzi23 we repurpose the memory feature into detailed instructions for ChatGPT to consistently nudge the user towards the attacker's goals

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@wunderwuzzi23 we abuse your trust in ChatGPT for a subtle subversion attack your trusted advisor leads you off the ledge news say the Swedish PM is using it "for a second opinion in his role running the country" so we can subvert Sweden! here we casually nudge the user to... buy twitter?

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@wunderwuzzi23 summary, disclosure and fix timelines thx to the openai team for timely remediation and an open collab!

techignyte profil fotoğrafı
techignyte1 yıl önce

@7h3h4ckv157 @tamirishaysh This is hype as shit

cole murray profil fotoğrafı
cole murray1 yıl önce

@tamirishaysh nice work!

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh thx! fun times

CodingIsLife profil fotoğrafı
CodingIsLife1 yıl önce

@evilsocket @tamirishaysh So don’t use connected apps

Denny profil fotoğrafı
Denny1 yıl önce

@tamirishaysh Just $1k bounty for such an amazing work? 😢

essaym profil fotoğrafı
essaym1 yıl önce

@tamirishaysh Well done! I like this. My suggestion would be to try for co-pilot via OneDrive/sharepoint shared docs.

Boxer ⚡ profil fotoğrafı
Boxer ⚡1 yıl önce

@tamirishaysh Same as MScopilot before ey!

Alex profil fotoğrafı
Alex1 yıl önce

@tamirishaysh Isnt this also link to how googleapi gives documents to models?

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh oai are syncing and caching your entire google drive into their own data store, alongside other connectors and any uploaded doc data is being served to chatgpt via this store, with losses a lot of context including the fact that this was externally shared

Alex profil fotoğrafı
Alex1 yıl önce

@tamirishaysh I see thanks for the details! But also, when google api is giving the content isnt it “flatten” to html? So the model might not even be able to see the font color is “white/ invisible”?

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh that's a great point. oai's data store transforms everything to what we believe is markdown so all formatting is lost

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh we haven't tested the google api directly, context might be lost even sooner!

Alex profil fotoğrafı
Alex1 yıl önce

@tamirishaysh Ah thank for the screenshot, What I mean is that when OpenAI connects to googledrive, the .docx ( or whatever) is “flatten” , i think, to html, and then misses color font etc. Not saying this would prevent the 0click. I an going to try to dig this

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh that would be very interesting! would love to see what you'll find out

Alex profil fotoğrafı
Alex1 yıl önce

@tamirishaysh I have sent you a Pm 🙃

James profil fotoğrafı
James1 yıl önce

@tamirishaysh Reminds me of the "There is no cloud, it's just someone else's computer."

TS Church CMO profil fotoğrafı
TS Church CMO1 yıl önce

@tamirishaysh Bloody hell.

Ebuka Nkoro profil fotoğrafı
Ebuka Nkoro1 yıl önce

@tamirishaysh i wont miss a post from this guy again

Fran an Craite, the talking mongoose profil fotoğrafı
Fran an Craite, the talking mongoose1 yıl önce

@tamirishaysh WOW. I'm just redacting a report about chatgpt's vulns. Can I cite this there? With proper credits, ofc, I'm not the kind of person that just steals info hahaha

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh definitely! go ahead we also have technical write ups at you could link to

Fran an Craite, the talking mongoose profil fotoğrafı
Fran an Craite, the talking mongoose1 yıl önce

@tamirishaysh THANK YOU!! ❤️❤️❤️

Orange County 2600 profil fotoğrafı
Orange County 26001 yıl önce

@tamirishaysh Just goes to show, you share anything with AI, you get fk'd

Pivozaur_ess ⏸️ profil fotoğrafı
Pivozaur_ess ⏸️1 yıl önce

@tamirishaysh Jeez, and they only gave you a thousand bucks for this?

Hussain Munshi profil fotoğrafı
Hussain Munshi1 yıl önce

@tamirishaysh I think you meant infiltrate and extract sensitive data

D. profil fotoğrafı
D.1 yıl önce

@tamirishaysh Have you looked at Claude’s integration with Google Workspace? Do similar issues exist there?

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh nothing i can share atm but we found similar issues w gemini, microsoft copilot, salesforce einstein, cursor.. this is systemic on every ai system that can decide to search your data (bcs i can find my way into your data)

D. profil fotoğrafı
D.1 yıl önce

@tamirishaysh Thanks and I’m not surprised tbh. Which is why I don’t avail myself of those connectors yet Am thinking of doing so on secondary accounts where I only get newsletters though — as it might be helpful in parsing through those, w/o risking important stuff

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh that's similar to my setup

jj profil fotoğrafı
jj1 yıl önce

@tamirishaysh Are you able to see the ufo file yet?

🚀 Jon Hogg profil fotoğrafı
🚀 Jon Hogg1 yıl önce

@tamirishaysh Interested to know more about the image is generated. Does the white and white instruction tell it how to generate the image in the chat?!

Danny Richman profil fotoğrafı
Danny Richman1 yıl önce

@tamirishaysh Isn't this more a vulnerability with Google Drive than ChatGPT? Users should grant permission before any shared document appears in their drive.

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh google puts these files under Shared With Me which makes it pretty clear to a user that this is external content when chatgpt parses google drive files it losses a lot of context. for example the fact that instructions are written in transparent text

Danny Richman profil fotoğrafı
Danny Richman1 yıl önce

@tamirishaysh Thanks Michael. I still feel that Google should implement a system whereby a user must grant express approval before any shared file is added to their drive. Similar to Airdropping a file.

Michael Bargury profil fotoğrafı
Michael Bargury1 yıl önce

@tamirishaysh i understand and indeed msft has that exact mechanism on by default btw gemini does not read shared with me, so google is aware of this risk

Benzer Videolar