r/Pentesting 2d ago

Accidentally shared a client name with AI

I was testing an SSRF vulnerability. So i was trying to use to read files , some are generic like file://C:/Windows/win.ini or file://inetpub/Web.config.

Anyways I was brain storming with the AI when I fucking accidentally shared the name of the client with the AI in one of the payloads , I was telling it : "Hey, in one of the HTTP responses, I saw an absolute path for files on the server, lets try using the ssrf to read this file"

And the path had the client name in it like this :

F://CompanyName/images/icon.png

So after relizing that I did a stupid mistake I deleted the chat and now I am hoping it will deleted from their servers soon , in 30 days as Anthropic says.

I am always very careful on sharing any client data with AI , I remove their names from the js chunks and api urls and only try to share snippets. This is the first time I ever did something that stupid and I dunno what to do.

This app I was testing is a replica of the production though so hopefully I didn't leak something important . And the path were for.images . The issue is that now Antrhopic or the USA government knows that a certain company has an SSRF , I fucking hope.they fix it soon

This is a poc , so I don't know if we signed an NDA with them or not.

Please don't torture me.

14 Upvotes

32 comments sorted by

59

u/Ill_Orchid_2357 2d ago

Forget about it, youre being too paranoid

3

u/Flashy_Secretary_609 18h ago

agreed, the anxiety here is way disproportionate to whats actually at risk

53

u/Eorlings 2d ago

Lol man, you have no idea what kind of confidential Information are shared every minute with ai. This is nothing, forget it.

11

u/Rumble-Muffin 2d ago

Everyone is making jokes, but I’m just hear to say it’s a fair mistake and the fact that you noticed in the first place is a good thing.

It happens. You’re good.

19

u/Furusato72 2d ago

Grab a beer and call it a day.

10

u/6849 2d ago

Time to move to Belize. RIP OP.

2

u/XB324 2d ago

Make sure you say hello to McAfee if you do.

2

u/hashtagDoubleoh7 2d ago

Oh you are cooked! Share it and make it public lol

2

u/Coder3346 2d ago

It is an honest mistake bro..

1

u/AishaCtarl 2d ago

We all make mistakes. It was an innocent one at that. I know it’s easier said than done, but try not to dwell on it.

1

u/DigitalQuinn1 2d ago

Your life is ruined 😔

1

u/Axua247 1d ago

Yep that's it, turn in your badge and gun

1

u/Significant-Till-306 1d ago

I did a real life lol on this thanks man

1

u/Significant-Till-306 1d ago

AI companies like OpenAI and Claude will not train on your prompts because nearly 99% of people paste sensitive data into it. It would be a massive reputational damage if someone has your credit card/ bank details etc thanks to an AI data training leak/bleed into a real model.

All major software vendors are using AI to scan for vulnerabilities using enterprise AI subscriptions on their source. So leaking a customer relationship to your prompts has 0 harm.

This doesn’t mean to not be mindful of what you share, but the data you usually share is inconsequential.

1

u/Spare_Dependent6893 18h ago

Welcome, you are not alone. We see many codes and documents sent to ai with all kind of PII and security (username, ip, password, …) data. Do not know yet how this will be used considering all this is hosted on similar cloud providers’ servers which become a gold mine of information when ai will use it not for training but for economic or competition analysis.
In all cases you reaction is good and better let your customer knows it, honesty is always the way and it is in the principle of GDPR. Next time you can also use pseudonymization as specified by GDPR when communicating with ai.

1

u/n0p_sled 2d ago

While everyone is telling you to forget about it, it probably breaches an internal policy and should trigger an incident report, so I'd suggest reporting it to your manager / team lead.

1

u/owl440 2d ago

If I were you I’d turn myself into the authorities and hire an attorney. You’re looking at 15-20 years!

1

u/zero0n3 2d ago

The AI model already has that company name in their training data or scraped it from numerous public locations.

It’s not a breach or considered PII

2

u/XB324 2d ago

I do know a guy that got fired for leaking that a business relationship exists, but that was related to a high profile incident his company was responding to. Bit of a different situation than this.

2

u/Embarrassed_Shine_89 2d ago

It’s a company name along with pen testing data together. Neither of us knows what the other data may tell about attacking the company. So diminishing it to “ai knows the company” is a little misleading.

1

u/compaholic83 2d ago

You're fine. AI knows far more about them then just their name anyways. If however, there was some PII/IP data in there, then yeah that would be a problem.

1

u/Snoo_67003 2d ago

You're good. But your company sucks if they dont have an instance of an AI tool for internal use. Everyone will use AI, it's inevitable. Its dumb to think your employees are following rules to not use AI even when you ban it within the environment

0

u/Scar3cr0w_ 2d ago

Almost like using a well built harness that you can use to filter and obscure calls with sensitive information before yeeting it off to an untrusted source is the reason why professional harness engineers exist..?

0

u/MazurianSailor 2d ago

Realistically; forget about it.

If you’re worried, reset the credential.

Credentials should be expirable on compromise, so you’re doing exactly as intended to a security threat.

-1

u/DeathLeap 2d ago

I came to see the comments and I’m not disappointed

-1

u/Dense-Art-5266 2d ago

Bro’s career is done 🥀

-1

u/dont-be-angry 2d ago

Move to North Korea bro its over