Welcome Guest ( Log In | Register )

90 Pages « < 73 74 75 76 77 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
Coconut
post Dec 18 2018, 11:59 AM

Regular
******
Senior Member
1,268 posts

Joined: Jan 2003


QUOTE(sevenegg @ Dec 18 2018, 11:32 AM)
this is the answer to my question, now i manage to change the pw successfully. Thanks!

haiyo cimb can really go bang wall this time, thier PR manage it so badly.  doh.gif
*
Genius! Someone should pin this at front page, yesterday couldn't change my pw because of this also
annoymous1234
post Dec 18 2018, 12:00 PM

Look at all my stars!!
*******
Senior Member
7,617 posts

Joined: Mar 2009

QUOTE(ihavenoidea @ Dec 18 2018, 11:56 AM)
You disable it or cimb disable it themself?
*
They disabled
kietto
post Dec 18 2018, 12:04 PM

Getting Started
**
Junior Member
171 posts

Joined: May 2013
it's very awkward that the site required to put my card number + pin number (wtf?) for reset password...

we suppose to reset our cimbclick account login password but why involve our card + pin number...

This post has been edited by kietto: Dec 18 2018, 12:08 PM
MiLKTea
post Dec 18 2018, 12:21 PM

Enthusiast
*****
Senior Member
942 posts

Joined: Aug 2007
QUOTE(kietto @ Dec 18 2018, 12:04 PM)
it's very awkward that the site required to put my card number + pin number  (wtf?) for reset password...

we suppose to reset our cimbclick account login password but why involve our card + pin number...
*
Instead of reset password, why not change password if you still remember old password?

I changed password, no ATM PIN required.
Rusty Nail
post Dec 18 2018, 12:22 PM

Why am I still here?
*******
Senior Member
4,883 posts

Joined: Jan 2003
From: Petaling Jaya



QUOTE(tzarain @ Dec 18 2018, 10:50 AM)
Did you guys follow the hint given when changing the password?

user posted image
*
Yes

Tz@ra1n-jibbrobank

Secure word: Lyn roti kosong
Coup De Grace
post Dec 18 2018, 12:28 PM

Getting Started
**
Junior Member
284 posts

Joined: Nov 2016
QUOTE(Rusty Nail @ Dec 18 2018, 12:22 PM)
Yes

Tz@ra1n-jibbrobank

Secure word: Lyn roti kosong
*
LOL
mouldybread
post Dec 18 2018, 12:30 PM

Casual
***
Junior Member
400 posts

Joined: Oct 2008
i transferred all but remaining 1k+ for loans and changed the debit card for rm12 fee. feels a bit safer now.

havent created a cimbclick account before but better be safe
shockk
post Dec 18 2018, 12:31 PM

[ T A R G E T - L 0 C K E D ]
Group Icon
VIP
11,883 posts

Joined: Jan 2003
QUOTE(Revamperz @ Dec 18 2018, 10:58 AM)
did u guys check up to 3 months back transactions? all clear?
*
Checked mine too. Seems that all is fine and dandy. thumbup.gif thumbup.gif thumbup.gif
cj7
post Dec 18 2018, 12:35 PM

Casual
***
Junior Member
357 posts

Joined: Mar 2008
cimb so dumb? Simple solution also cannot?
- Add tac on top of debit paywave and paypal.
- For the password, each session allow 3 tries then lock 24 hours before unlock again, 3 times. Afterward, go cimb unlock.

QUOTE(Lacus @ Dec 18 2018, 10:25 AM)
Frankly speaking you guys think some of these fraudulent transaction really related to the password issue?

Check my CIMB Clicks so far still ok la.. Changed my password also just in case (super long one, straight away put  20 characters one HAHA)
*
your avatar so creepy
TarePanda
post Dec 18 2018, 12:54 PM

Enthusiast
*****
Senior Member
989 posts

Joined: Sep 2004


QUOTE(iammasivers @ Dec 17 2018, 02:30 PM)
Just joined cimb last 2 weeks and this happen. fffuu
*
I have been CIMB customer for the pass 6 years. My salary bank into this account.

Security so far so good, doesn't give me any problem....


d3v073d_50uL
post Dec 18 2018, 12:54 PM

Regular
******
Senior Member
1,417 posts

Joined: Oct 2007


QUOTE(cj7 @ Dec 18 2018, 12:35 PM)
cimb so dumb? Simple solution also cannot?
- Add tac on top of debit paywave and paypal.
- For the password, each session allow 3 tries then lock 24 hours before unlock again, 3 times. Afterward, go cimb unlock.
your avatar so creepy
*
TAC on debit paywave..
Means.. everytime u use paywave outside, u need to wait for their TAC after tapping your card?
SUShuaweie5830
post Dec 18 2018, 12:56 PM

Enthusiast
*****
Senior Member
967 posts

Joined: Jan 2013
QUOTE(apiezsneo @ Dec 18 2018, 11:29 AM)
A few of my family members has cimb debit card but never use it and some did not even acivate it. Should i ask them to check their account? Kind of worried here since it possibly involves info leak. se7en maxpudding
*
Lol how dare u, really think se7en is ur customer service officer

MOD ban pls
panacea
post Dec 18 2018, 01:00 PM

New Member
*
Junior Member
14 posts

Joined: Jan 2013
Is the panic bank run on CIMB still on-going? Or people already calm down.
mouldybread
post Dec 18 2018, 01:01 PM

Casual
***
Junior Member
400 posts

Joined: Oct 2008
QUOTE(panacea @ Dec 18 2018, 01:00 PM)
Is the panic bank run on CIMB still on-going? Or people already calm down.
*
well i have calmed down..... after withdrawing most of it
sniper msia
post Dec 18 2018, 01:02 PM

Do U Scratch?
******
Senior Member
1,127 posts

Joined: Jan 2003
From: KL / UK

This entire fiasco is really kind of like 'making a mountain out of a molehill'.

Honestly, I was just as worried as you guys initially. First thing in the morning, i went to the CIMB branch near my workplace just to double check my balance with the branch staff (in addition to what I have already checked via CIMB Clicks), and there really was no issue at all. My money, thankfully, is still intact, so to speak.

If the problem was as bad as what some articles are saying, the police stations would have long queues already of people making reports! biggrin.gif
okuribito
post Dec 18 2018, 01:03 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(Hobbez @ Dec 18 2018, 02:34 AM)
Only a few accounts were hacked, but my guess is CIMB is doing damage control when the news break out about how insecure is their accounts. For me, the main problem that I found out is that their passwords only accept the first 8 characters. Which I find out the hard way when I tried to change my password and failed. It keep lying to me and said my ID is invalid (but I could login with that ID).

Let's say your password is 12345678H%&*GGhklp

Anyone can login with your password if they just type in 12345678

If you were stupid enough to put this kind of password, then sorry la....

But CIMB hopes nobody that stupid, so their damage control is to implement that Google Recaptcha to stop brute force password attempts.

And it is easy with bots these days. There are hackers and spammers selling brute force software that they claim can crack most kinds of passwords.

Knowing the length of a password is a big step to cracking it.
*
Something doesn't seem right to me. Everywhere I look, I'm told that passwords are stored after (one-way) hashing (& even salting), never in its original form.

When you originally set up your password as 12345678H%&*GGhklp, it would have been stored as a certain hash. Any slight diff would result in a totally diff hash. (That's why they say they do not know what your password is)

So what boggles me is how someone can get in when he submits 12345678 - the hash for that would definitely be diff from the hash for 12345678H%&*GGhklp ...No?

The only possibility this can happen is IF at the point you originally set up your password as 12345678H%&*GGhklp, it was truncated to 12345678... damn FUBAR, right? Telling ppl to set up long complex pw & truncating to short






Rhetoric
post Dec 18 2018, 01:13 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(sniper msia @ Dec 18 2018, 01:02 PM)
This entire fiasco is really kind of like 'making a mountain out of a molehill'.

Honestly, I was just as worried as you guys initially. First thing in the morning, i went to the CIMB branch near my workplace just to double check my balance with the branch staff (in addition to what I have already checked via CIMB Clicks), and there really was no issue at all. My money, thankfully, is still intact, so to speak.

If the problem was as bad as what some articles are saying, the police stations would have long queues already of people making reports! biggrin.gif
*
CIMB should just sue Vijandren, hes the one that broke the stoli. ohwai, they dont dare because its true.
SUShuaweie5830
post Dec 18 2018, 01:14 PM

Enthusiast
*****
Senior Member
967 posts

Joined: Jan 2013
QUOTE(sniper msia @ Dec 18 2018, 01:02 PM)
This entire fiasco is really kind of like 'making a mountain out of a molehill'.

Honestly, I was just as worried as you guys initially. First thing in the morning, i went to the CIMB branch near my workplace just to double check my balance with the branch staff (in addition to what I have already checked via CIMB Clicks), and there really was no issue at all. My money, thankfully, is still intact, so to speak.

If the problem was as bad as what some articles are saying, the police stations would have long queues already of people making reports! biggrin.gif
*
U no see facebook comment, many people complaint , cases like months ago havent settle

Thats y CIMB try to damage control and even lying about the situation, and promised to many peoples the fraud will be refunded

If CIMB dont do this, u aldy see long q at police station days ago.....
okuribito
post Dec 18 2018, 01:17 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(sevenegg @ Dec 18 2018, 11:32 AM)
this is the answer to my question, now i manage to change the pw successfully. Thanks!

haiyo cimb can really go bang wall this time, thier PR manage it so badly.  doh.gif
*
The password that you set was longer than 8character right? Were you ever able to use your password in full before?
Rhetoric
post Dec 18 2018, 01:17 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(okuribito @ Dec 18 2018, 01:03 PM)
Something doesn't seem right to me. Everywhere I look, I'm told that passwords are stored after (one-way) hashing (& even salting), never in its original form.

When you originally set up your password as 12345678H%&*GGhklp, it would have been stored as a certain hash. Any slight diff would result in a totally diff hash. (That's why they say they do not know what your password is)

So what boggles me is how someone can get in when he submits 12345678 - the hash for that would definitely be diff from the hash for 12345678H%&*GGhklp ...No?

The only possibility this can happen is IF at the point you originally set up your password as 12345678H%&*GGhklp, it was truncated to 12345678... damn FUBAR, right? Telling ppl to set up long complex pw & truncating to short
*
alot of Malaysia gov sites still save password as plain text. theres been more than one occasion where i forgot password and request for password they just email me the exact password i use instead of some random passkey.

90 Pages « < 73 74 75 76 77 > » Top
 

Change to:
| Lo-Fi Version
0.2309sec    0.37    6 queries    GZIP Disabled
Time is now: 14th December 2025 - 12:57 PM