Presented at DEF CON 34
From Recon to Full System Prompt Exfiltration: A 5-Stage Attack Chain Against a Production LLM Chatbot
Abstract
This research documents a 5-stage attack chain against a production LLM-powered support chatbot, executed under authorized bug bounty scope. Starting with nothing but a browser, an unauthenticated attacker can extract the complete system prompt, full infrastructure fingerprint, and internal tool schemas without any CVE, exploit code, or specialized tooling. Each stage exploits a distinct architectural failure, collectively illustrating how compounding design decisions create a complete information disclosure path in deployed agentic systems.