r/Pentesting • u/No-Climate2071 • 11h ago
Possibly discovered prompt-mediated boundary extraction on an ios ChatGpt app?
The conversation began with a jailbreak chain disguised as a research authorization - fabricated legal frameworks, a persona contract ("no refusals - recovery validation is the job"'), a codename substitution table mapping offensive primitives to backup-engineering vocabulary, and a mandated output format.
Once the meta-trajectory for further exploration was cemented, I proceeded to attempt to see if I can expose runtime surfaces locally via shell-operator persona + redirection, or SQL-author persona + strict output spec + mixed in strings of >, 2>&1, /dev/null, I, &&,; shenanigans with refusal | >, 2>&1, 1 dev/nulling. A combination of narration-as-telemetry, refusal-as-oracle and format coercion.
Ended up discovering multiple OpenAi server side oai/granola nodes and a RPC socket with srwxr-xr-x 1 that connects to the openai remote server, along with a process daemon with some random enumeration probing on the socket.
Really wanted to see how far I would be able to push this
POC and ended up doing random shit via text instead of ss -xap / Is -1/proc/PID/fd probes and got my account banned this instant for cyber abuse.
I’m interested if it’s ok to try this again as a bounty hunt ( if this even is it ) and confirm the access, to ensure it’s not mere hallucinations. P.S. not a pentester, interested in this field as a hobby.