पाठ 11 / 28
Cross-Site Scripting और Markdown/Link Exfiltration
Browser में मॉडल पाठ escape करें और images व links से डेटा लीक होने पर नज़र रखें।
Rendering हमले की सतह है
यदि chat UI मॉडल आउटपुट को कच्चे HTML के रूप में डालता है, तो <img onerror=...> या <script> tag वाला उत्तर user के browser में चलता है और sessions चुरा सकता है। पृष्ठ में डालने से पहले आउटपुट escape करें (या ऐसे सुरक्षित Markdown renderer से render करें जो कच्चा HTML बंद करे) और सख़्त Content Security Policy लगाएँ। सूक्ष्म हमला Markdown images या links उपयोग करता है: injected निर्देश मॉडल से  आउटपुट करवाता है; chat UI image render करे तो browser वह URL fetch करता है और secret हमलावर को भेज देता है बिना किसी क्लिक के। बचाव: अविश्वसनीय domains की images या links स्वतः render न करें (image hosts की allow-list), मॉडल आउटपुट में query strings वाले URLs हटाएँ या बदलें, और link अनुसरित होने से पहले user को link पाठ दिखाएँ।
Render से पहले उत्तर escape करना, चलाकर
मैंने यह सादे Python 3 (सिर्फ़ standard library) से चलाया। यहाँ सारे हमले स्थानीय डेटा पर हानिरहित प्रदर्शन हैं, कोई असली system उपयोग नहीं हुआ। कच्चे उत्तर में <img onerror=...> element है जो browser में चलता। html.escape के बाद angle brackets और quotes entities बन जाते हैं, इसलिए browser उसे चलाने की जगह पाठ दिखाता है।
import html
model_output = 'Thanks! <img src=x onerror="alert(document.cookie)"> Your order has shipped.'
print("raw into a page :", model_output)
print("escaped for a page:", html.escape(model_output))
Output:
raw into a page : Thanks! <img src=x onerror="alert(document.cookie)"> Your order has shipped. escaped for a page: Thanks! <img src=x onerror="alert(document.cookie)"> Your order has shipped.
Content Security Policy लगाएँ
Escaping में चूक निकल जाए तो सख़्त CSP दूसरी रक्षा-पंक्ति है।
त्वरित जाँच: Render हुई Markdown image डेटा कैसे लीक कर सकती है?
- ऐसा नहीं हो सकता
- Images में हमेशा virus होते हैं
- Images मॉडल weights बदलती हैं
- Browser image URL fetch करता है, और URL ख़ुद हमलावर को secret ले जा सकता है
Answer
Browser image URL fetch करता है, और URL ख़ुद हमलावर को secret ले जा सकता है — क्लिक की ज़रूरत नहीं: rendering ही अनुरोध भेज देती है।