• Home
  • News
  • Apps
  • Gadgets
  • Cryptocurrency
  • Gaming
  • How To
  • IT Enterprise
tech in news > IT Enterprise > The ChatGPT Account Takeover Vulnerability Allows Hackers To Gain Access To Online Accounts of Users 
IT EnterpriseNews

The ChatGPT Account Takeover Vulnerability Allows Hackers To Gain Access To Online Accounts of Users 

Rithika Biswas
Rithika Biswas April 19, 2023
Updated 2023/04/21 at 11:53 AM
Share
SHARE

Nagli (@naglinagli), a prominent security analyst and bug hunter, recently discovered a significant security issue in ChatGPT. A threat actor might quickly exploit the vulnerability and obtain complete control of any ChatGPT user’s account with a single click. As a result, allowing attackers access to sensitive data allows them to carry out unauthorised acts; this is known as “Account Take Over.” Account takeover is a clever cyber attack in which an attacker or hacker gains unauthorised access to one account by either exploiting a flaw in the system or stealing one’s login credentials.

After gaining access to a target system or device, an attacker can engage in a number of nefarious behaviours, including theft of personal information, fraudulent transactions, and virus distribution. The attacker uses a web cache deception vulnerability to get access to the victim’s ChatGPT account. This ChatGPT Account Take Over flaw allowed a remote attacker to compromise any user’s account and totally take over the account with a single click.

Take Over Bug Attack Flow with ChatGPT Account. A web cache deception vulnerability is a cunning security issue that allows attackers to fool web servers’ caching algorithms and get access to user accounts. This type of vulnerability can occur when a website’s server cache is configured or used inappropriately. Hackers can exploit the ChatGPT account and take control of vulnerability to alter cached web pages or generate bogus ones in order to deceive users.

Hacking ChatGPT: 'The Dark Web's Hottest Topic' -- Virtualization Review

This data might then be used to make a request to  “https://chat.openai.com/api/auth/session/victim.css.” Regardless of whether the victim’s “.css” file was on the server, the server would reply with the same information as “/api/auth/session.” Because of the “.css” extension, the server would cache a CSS file and record the victim’s session content, data, and access tokens in the process.

To be successful, the CF-Cache-Status answer must confirm a cached “HIT.” This implies that the data was cached and will be served to the next request within the same region. If an attacker manipulates the Load Balancer into caching their request on a customised path, an attacker can extract sensitive data from the cached response.

When Nagli noticed the problem, he took prompt and responsible action by reporting it to the ChatGPT team. In doing so, he contributed to preventing potential harm and the sustained safety of ChatGPT users. Despite the fact that the researcher received no monetary compensation for his efforts, he stated that he is glad to have contributed to the improved security of the unique product. 

Web cache deception is a serious issue that is quite simple to attack. However, there are numerous solutions to this problem, which we have listed below:- The cache server should function based on the cache-control headers of the application. Cache files only if HTTP caching headers permit it. Files should be cached based on their Content-Type header, not merely their file extension. For non-existent files, return HTTP errors such as 404 or 302.

 

For more such updates keep reading techinnews

TAGGED: AI, chatgpt, chatgpt account hacked, cyberbulling, cybercrime, cybersecurity, Hackers
Rithika Biswas April 19, 2023
Share this Article
Facebook TwitterEmail Print

Categories

  • Apps646
  • Cryptocurrency137
  • Gadgets894
  • Gaming83
  • How To169
  • IT Enterprise451
  • News3,117
  • Streaming148
  • Tech1,313

You Might Also Like

AppsNewsTech

Threads will roll out Profile and other tools in the Search Bar

November 29, 2024
AppsNewsTech

Gemini Mobile App is now available for Google Workspace Users

November 29, 2024
AppsNewsTech

WhatsApp is testing sticker sharing feature

November 29, 2024
GadgetsNews

Google Pixel 9 AI features may soon be available on older models

November 28, 2024
  • Review
  • Best Product
  • Reading List
  • Customize Interests

We publish interesting developments and news stories from and about people who work in and use technology. We’re interested in what’s happening, what’s different, and what’s meaningful today in developing technology and how people integrate and improve their lives — and their businesses — with it.

Copyright © 2022 tech in news.  All Rights Reserved.

socials@techinnews.com

Follow us on Socials

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?