Welcome Guest ( Log In | Register )

90 Pages « < 74 75 76 77 78 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
kiasunkiasi
post Dec 18 2018, 01:18 PM

On my way
****
Senior Member
597 posts

Joined: Nov 2007


QUOTE(Rhetoric @ Dec 18 2018, 01:13 PM)
CIMB should just sue Vijandren, hes the one that broke the stoli. ohwai, they dont dare because its true.
*
next Tuesday lah
kietto
post Dec 18 2018, 01:19 PM

Getting Started
**
Junior Member
171 posts

Joined: May 2013
QUOTE(MiLKTea @ Dec 18 2018, 12:21 PM)
Instead of reset password, why not change password if you still remember old password?

I changed password, no ATM PIN required.
*
trueeeeeeeeeeeeee

really have no idea what the decision makers thinking when apply this kind of user experience....


Domomo
post Dec 18 2018, 01:20 PM

Getting Started
**
Junior Member
172 posts

Joined: Jul 2011
From: klang,selangor


too many in panic mode,all bank transaction need authorization right ,so without u authorization can go through,malaysian always like to join bandwagon ,people said banned this boikot this semua ikut,last2 see no problem what so ever.
Rusty Nail
post Dec 18 2018, 01:23 PM

Why am I still here?
*******
Senior Member
4,883 posts

Joined: Jan 2003
From: Petaling Jaya



QUOTE(Domomo @ Dec 18 2018, 01:20 PM)
too many in panic mode,all bank transaction need authorization right ,so without u authorization can go through,malaysian always like to join bandwagon ,people said banned this boikot this semua ikut,last2 see no problem what so ever.
*
not all, especially paypal

https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/
okuribito
post Dec 18 2018, 01:25 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(Rhetoric @ Dec 18 2018, 01:17 PM)
alot of Malaysia gov sites still save password as plain text. theres been more than one occasion where i forgot password and request for password they just email me the exact password i use instead of some random passkey.
*
hahaha not surprised- gomen dept smile.gif CIMB is a bank ler. If true they store password in original form then BNM should withdraw their licence IMHO. For that matter doesn't BNM do IT system audit on licensed FI's ?
yahiko
post Dec 18 2018, 01:26 PM

Regular
******
Senior Member
1,215 posts

Joined: Jul 2009
From: Penang Island


not only paypal does not need TAC code. even when i use Expedia there is no TAC code as well..
Faidzal
post Dec 18 2018, 01:29 PM

Getting Started
**
Junior Member
240 posts

Joined: Aug 2008
From: From JB to KL!
QUOTE(skyblu3 @ Dec 17 2018, 09:32 PM)
But now change password have to enter ATM CARD number and PIN for verification?
I'm not comfortable about this.
*
strange.

I did not have to do this step though
boonhan
post Dec 18 2018, 01:30 PM

Reader
******
Senior Member
1,934 posts

Joined: Jul 2009


QUOTE(okuribito @ Dec 18 2018, 01:17 PM)
The password that you set  was longer than 8character right? Were you ever able to use your password in full before?
*
I have old password with more than 8 character.

It will still login as long as 8 character infont valid. Hahaha. How nice.
KingArthurVI
post Dec 18 2018, 01:30 PM

BWOAHHHH
******
Senior Member
1,126 posts

Joined: Feb 2011
From: Penang



Just change CIMB Clicks password and go get your debit card replaced, done
Hobbez
post Dec 18 2018, 01:43 PM

Regular
******
Senior Member
1,231 posts

Joined: Dec 2009
QUOTE(okuribito @ Dec 18 2018, 01:25 PM)
hahaha not surprised- gomen dept  smile.gif  CIMB is a bank ler. If true they store password in original form then BNM should withdraw their licence IMHO. For that matter doesn't BNM do IT system audit on licensed FI's ?
*
I doubt it. Local bank wholly owned by bumiputra, means they get a "special" card. If they are ever in trouble, govt will bail them out and protek them instead.
okuribito
post Dec 18 2018, 01:44 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(boonhan @ Dec 18 2018, 01:30 PM)
I have old password with more than 8 character.

It will still login as long as 8 character infont valid. Hahaha. How nice.
*
so let's say your old pw was 12345678H%&*GGhklp ...

1. before 18 nov, were you able to get in with just 12345678? with 12345678H? or only with 12345678H%&*GGhklp?

2. After 18 nov, were you able to get in with just 12345678? with 12345678H? or only with 12345678H%&*GGhklp?

curious to figure out what cimb is doing tongue.gif
okuribito
post Dec 18 2018, 01:49 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(Hobbez @ Dec 18 2018, 01:43 PM)
I doubt it. Local bank wholly owned by bumiputra, means they get a "special" card. If they are ever in trouble, govt will bail them out and protek them instead.
*
hahaha let's not go down that road ler. anything that happen to one bank can reverberate throughout the entire system. I'm sure bnm folks realise and understand that

OldSchoolJoke
post Dec 18 2018, 01:54 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
QUOTE(okuribito @ Dec 18 2018, 01:44 PM)
so let's say your old pw was  12345678H%&*GGhklp    ...

1. before 18 nov, were you able to get in with just 12345678?  with 12345678H? or only with 12345678H%&*GGhklp?

2. After 18 nov, were you able to get in with just 12345678?  with 12345678H? or only with 12345678H%&*GGhklp?

curious to figure out what cimb is doing  tongue.gif
*
yesterday se7en got post the code script.
the checking is:-

if got no special characters and >= 8 characters (means new format of password), you will require to type exactly your password
else (old password password), you only need to be correct on the first 8 characters.

meaning if old format of password, any characters behind after 8th characters, if user type in wrongly, user will still be logged in
apiezsneo
post Dec 18 2018, 02:01 PM

Joined: Today, 01:05 AM
***
Junior Member
333 posts

Joined: Oct 2008


QUOTE(huaweie5830 @ Dec 18 2018, 12:56 PM)
Lol how dare u, really think se7en is ur customer service officer

MOD ban pls
*
And if i ask the cso what do u think the answer given?
boonhan
post Dec 18 2018, 02:03 PM

Reader
******
Senior Member
1,934 posts

Joined: Jul 2009


QUOTE(okuribito @ Dec 18 2018, 01:44 PM)
so let's say your old pw was  12345678H%&*GGhklp    ...

1. before 18 nov, were you able to get in with just 12345678?  with 12345678H? or only with 12345678H%&*GGhklp?

2. After 18 nov, were you able to get in with just 12345678?  with 12345678H? or only with 12345678H%&*GGhklp?

curious to figure out what cimb is doing  tongue.gif
*
Not exactly remember. But i think there are times that i mistake typo at the last character and manage login.

I always thought i typed correctly somehow. Yeah. Now this news come out.
boonhan
post Dec 18 2018, 02:05 PM

Reader
******
Senior Member
1,934 posts

Joined: Jul 2009


So much for PIDM protection.
Those paypal charged transaction took away saving which needed for loan repayment, expenses.

Now cimb required 2 to 4 weeks for investigation and refund.
kleren
post Dec 18 2018, 02:08 PM

New Member
*
Junior Member
38 posts

Joined: Mar 2007
QUOTE(boonhan @ Dec 18 2018, 02:05 PM)
So much for PIDM protection.
Those paypal charged transaction took away saving which needed for loan repayment, expenses.

Now cimb required 2 to 4 weeks for investigation and refund.
*
Since when PIDM protect your duit hilang kene hack? Go re-educate yourself www.pidm.gov.my
okuribito
post Dec 18 2018, 02:13 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(OldSchoolJoke @ Dec 18 2018, 01:54 PM)
yesterday se7en got post the code script.
the checking is:-

if got no special characters and >= 8 characters (means new format of password), you will require to type exactly your password
else (old password password), you only need to be correct on the first 8 characters.

meaning if old format of password, any characters behind after 8th characters, if user type in wrongly, user will still be logged in
*
Thx bro, saw that & thinking thru the implications. How does CIMB store passwords? As Is? or after hashing?

If after hashing, old passwords longer than 8char should not be able to get in if just key in first 8 chars. Why? becos the hash would be diff. No? Only way can get in is IF the old password was stored As Is. Wonder if that makes sense hmm.gif





Seng89
post Dec 18 2018, 02:14 PM

Look at all my stars!!
*******
Senior Member
2,687 posts

Joined: Sep 2012
https://www.apakes.com/sotong-betullah-cimb...-nak-gaji-esok/

Real or fake ?

This post has been edited by Seng89: Dec 18 2018, 02:15 PM


Attached thumbnail(s)
Attached Image
SUShuaweie5830
post Dec 18 2018, 02:15 PM

Enthusiast
*****
Senior Member
967 posts

Joined: Jan 2013
QUOTE(apiezsneo @ Dec 18 2018, 02:01 PM)
And if i ask the cso what do u think the answer given?
*
Dun know dun care



90 Pages « < 74 75 76 77 78 > » Top
 

Change to:
| Lo-Fi Version
0.0173sec    0.70    6 queries    GZIP Disabled
Time is now: 10th December 2025 - 07:22 AM