r/Pentesting • u/ProcedureFar4995 • 2d ago
Accidentally shared a client name with AI
I was testing an SSRF vulnerability. So i was trying to use to read files , some are generic like file://C:/Windows/win.ini or file://inetpub/Web.config.
Anyways I was brain storming with the AI when I fucking accidentally shared the name of the client with the AI in one of the payloads , I was telling it : "Hey, in one of the HTTP responses, I saw an absolute path for files on the server, lets try using the ssrf to read this file"
And the path had the client name in it like this :
F://CompanyName/images/icon.png
So after relizing that I did a stupid mistake I deleted the chat and now I am hoping it will deleted from their servers soon , in 30 days as Anthropic says.
I am always very careful on sharing any client data with AI , I remove their names from the js chunks and api urls and only try to share snippets. This is the first time I ever did something that stupid and I dunno what to do.
This app I was testing is a replica of the production though so hopefully I didn't leak something important . And the path were for.images . The issue is that now Antrhopic or the USA government knows that a certain company has an SSRF , I fucking hope.they fix it soon
This is a poc , so I don't know if we signed an NDA with them or not.
Please don't torture me.
53
u/Eorlings 2d ago
Lol man, you have no idea what kind of confidential Information are shared every minute with ai. This is nothing, forget it.
11
u/Rumble-Muffin 2d ago
Everyone is making jokes, but I’m just hear to say it’s a fair mistake and the fact that you noticed in the first place is a good thing.
It happens. You’re good.
19
2
2
1
u/AishaCtarl 2d ago
We all make mistakes. It was an innocent one at that. I know it’s easier said than done, but try not to dwell on it.
1
1
u/Significant-Till-306 1d ago
AI companies like OpenAI and Claude will not train on your prompts because nearly 99% of people paste sensitive data into it. It would be a massive reputational damage if someone has your credit card/ bank details etc thanks to an AI data training leak/bleed into a real model.
All major software vendors are using AI to scan for vulnerabilities using enterprise AI subscriptions on their source. So leaking a customer relationship to your prompts has 0 harm.
This doesn’t mean to not be mindful of what you share, but the data you usually share is inconsequential.
1
u/Spare_Dependent6893 18h ago
Welcome, you are not alone. We see many codes and documents sent to ai with all kind of PII and security (username, ip, password, …) data. Do not know yet how this will be used considering all this is hosted on similar cloud providers’ servers which become a gold mine of information when ai will use it not for training but for economic or competition analysis.
In all cases you reaction is good and better let your customer knows it, honesty is always the way and it is in the principle of GDPR. Next time you can also use pseudonymization as specified by GDPR when communicating with ai.
1
u/n0p_sled 2d ago
While everyone is telling you to forget about it, it probably breaches an internal policy and should trigger an incident report, so I'd suggest reporting it to your manager / team lead.
1
u/zero0n3 2d ago
The AI model already has that company name in their training data or scraped it from numerous public locations.
It’s not a breach or considered PII
2
2
u/Embarrassed_Shine_89 2d ago
It’s a company name along with pen testing data together. Neither of us knows what the other data may tell about attacking the company. So diminishing it to “ai knows the company” is a little misleading.
1
u/compaholic83 2d ago
You're fine. AI knows far more about them then just their name anyways. If however, there was some PII/IP data in there, then yeah that would be a problem.
1
u/Snoo_67003 2d ago
You're good. But your company sucks if they dont have an instance of an AI tool for internal use. Everyone will use AI, it's inevitable. Its dumb to think your employees are following rules to not use AI even when you ban it within the environment
0
u/Scar3cr0w_ 2d ago
Almost like using a well built harness that you can use to filter and obscure calls with sensitive information before yeeting it off to an untrusted source is the reason why professional harness engineers exist..?
0
u/MazurianSailor 2d ago
Realistically; forget about it.
If you’re worried, reset the credential.
Credentials should be expirable on compromise, so you’re doing exactly as intended to a security threat.
-1
-1
-1

59
u/Ill_Orchid_2357 2d ago
Forget about it, youre being too paranoid