Welcome Guest ( Log In | Register )

90 Pages « < 75 76 77 78 79 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
O-haiyo
post Dec 18 2018, 02:16 PM

Enthusiast
*****
Senior Member
857 posts

Joined: Jan 2005
From: Mlk, Klang


QUOTE(boonhan @ Dec 18 2018, 02:05 PM)
So much for PIDM protection.
Those paypal charged transaction took away saving which needed for loan repayment, expenses.

Now cimb required 2 to 4 weeks for investigation and refund.
*
lol what?
penew
post Dec 18 2018, 02:18 PM

Casual
***
Junior Member
393 posts

Joined: Apr 2006
I think there's 2 different issue but both seems to "happened" at the same time...

A) cimb card & CVV data breach
this related to the news of hacker managed to get card data and looking for partner to monetize..so they use card data to perform direct card transactions on PayPal merchants (direct transactions doesn't require PayPal account to be created nor require CimbClicks login) - PayPal call this DCC transactions (non PayPal account transactions made to PayPal merchants)..noticed the transactions were made to "digital wallet" merchants like gambling, game etc where they can store certain value before monetizing it later..


B) cimb password issue
panic customers affected by "A" login to CimbClicks to check their account. Some managed to login, some stuck due to new password policy..due to too much traffic surge, cimb thought it's abuse/hack so introduced captcha..at the same time, some users noticed they can login even with wrong password which reveals cimb security flaw

This post has been edited by penew: Dec 18 2018, 02:24 PM
boonhan
post Dec 18 2018, 02:20 PM

Reader
******
Senior Member
1,934 posts

Joined: Jul 2009


QUOTE(kleren @ Dec 18 2018, 02:08 PM)
Since when PIDM protect your duit hilang kene hack? Go re-educate yourself www.pidm.gov.my
*
Ya. They protek bank bankrupt.
Duit hilang is to bank..
Need find pulis report cimb steal money.
apiezsneo
post Dec 18 2018, 02:20 PM

Joined: Today, 01:05 AM
***
Junior Member
333 posts

Joined: Oct 2008


QUOTE(huaweie5830 @ Dec 18 2018, 02:15 PM)
Dun know dun care
*
smile.gif
SUShuaweie5830
post Dec 18 2018, 02:25 PM

Enthusiast
*****
Senior Member
967 posts

Joined: Jan 2013
Cimb educating people on the edge markets, about scam transactions......

http://www.theedgemarkets.com/article/fast...ctions-—-cimb

Irony nya

Or they aldy found out something not right with the password system ?

SUShuaweie5830
post Dec 18 2018, 02:28 PM

Enthusiast
*****
Senior Member
967 posts

Joined: Jan 2013
Lol saw this on FB

Is this even normal ?


Attached Image
brkli
post Dec 18 2018, 02:29 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
QUOTE(okuribito @ Dec 18 2018, 02:13 PM)
Thx bro, saw that & thinking thru the implications. How does CIMB store passwords? As Is? or after hashing?

If after hashing, old passwords longer than 8char should not be able to get in if just key in first 8 chars. Why? becos the hash would be diff. No? Only way can get in is IF the old password was stored As Is. Wonder if that makes sense  hmm.gif
*
no, the code snippet does not prove anything on how they store the password. it only shows thier 'lazy' development to do not want to change backend API, so they convert/translate those inputs (for this case password) as front end.
MiLKTea
post Dec 18 2018, 02:32 PM

Enthusiast
*****
Senior Member
942 posts

Joined: Aug 2007
QUOTE(Seng89 @ Dec 18 2018, 02:14 PM)
I would say dont just believe everything you read online.

With this hot issue now, many web admins and bloggers would take advantage to increase their page traffic eventhough they know nuts anout IT.
MiLKTea
post Dec 18 2018, 02:33 PM

Enthusiast
*****
Senior Member
942 posts

Joined: Aug 2007
QUOTE(huaweie5830 @ Dec 18 2018, 02:28 PM)
Lol saw this on FB

Is this even normal ?
Attached Image
*
I believe they key in old password + random characters.

This is known issue already

sevenegg
post Dec 18 2018, 02:35 PM

Getting Started
**
Junior Member
91 posts

Joined: Jan 2013


QUOTE(okuribito @ Dec 18 2018, 01:17 PM)
The password that you set  was longer than 8character right? Were you ever able to use your password in full before?
*
yes, initial pw is >8 characters, and I can login as usual everytime. nvr try to purposely key in wrong pw to testing. for me, since everything is safe for me, just change new pw only la, not need kpkb so much. of coz i wont say this if im the victim of this loophole. whistling.gif
Seng89
post Dec 18 2018, 02:37 PM

Look at all my stars!!
*******
Senior Member
2,687 posts

Joined: Sep 2012
QUOTE(sevenegg @ Dec 18 2018, 02:35 PM)
yes, initial pw is >8 characters, and I can login as usual everytime. nvr try to purposely key in wrong pw to testing. for me, since everything is safe for me, just change new pw only la, not need kpkb so much. of coz i wont say this if im the victim of this loophole. whistling.gif
*
So u pindah ke tak?
brkli
post Dec 18 2018, 02:38 PM

On my way
****
Junior Member
592 posts

Joined: Oct 2018
since this tread people so intreasted on the login process. you can just open developer tools -> console. you can learn abit there...

This post has been edited by brkli: Dec 18 2018, 02:38 PM


Attached thumbnail(s)
Attached Image
sevenegg
post Dec 18 2018, 02:40 PM

Getting Started
**
Junior Member
91 posts

Joined: Jan 2013


QUOTE(Seng89 @ Dec 18 2018, 02:37 PM)
So u pindah ke tak?
*
tak, change new pw, limit transaction limit only.
budi1413
post Dec 18 2018, 02:40 PM

Regular
******
Senior Member
1,607 posts

Joined: Aug 2013


its been some time i no login. huhuh. later check balance @ atm.

no sms notification so far.

This post has been edited by budi1413: Dec 18 2018, 02:42 PM
unknown_2
post Dec 18 2018, 02:46 PM

On my way
****
Junior Member
572 posts

Joined: Mar 2012


QUOTE(sevenegg @ Dec 18 2018, 02:35 PM)
yes, initial pw is >8 characters, and I can login as usual everytime. nvr try to purposely key in wrong pw to testing. for me, since everything is safe for me, just change new pw only la, not need kpkb so much. of coz i wont say this if im the victim of this loophole. whistling.gif
*
still not fix their coding?
i tried mine cant be exploit through this loophole.
cj7
post Dec 18 2018, 02:53 PM

Casual
***
Junior Member
357 posts

Joined: Mar 2008
QUOTE(d3v073d_50uL @ Dec 18 2018, 12:54 PM)
TAC on debit paywave..
Means.. everytime u use paywave outside, u need to wait for their TAC after tapping your card?
*
convenience come at a price in first place. In this case, it's security.

Also, i'm sure that they can do something to improve it if they wanted to.
heinlein
post Dec 18 2018, 03:29 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
user posted image
Instant transfer to bank rakyat disabled. other bank interbank transfer still work at the moment

This post has been edited by heinlein: Dec 18 2018, 03:30 PM
TarePanda
post Dec 18 2018, 03:32 PM

Enthusiast
*****
Senior Member
989 posts

Joined: Sep 2004


QUOTE(apiezsneo @ Dec 18 2018, 11:29 AM)
A few of my family members has cimb debit card but never use it and some did not even acivate it. Should i ask them to check their account? Kind of worried here since it possibly involves info leak. se7en maxpudding
*
No one can use your inactivate debit or credit card....

You can ask your family to check thier bank account if you are worried.

FYI, police stated no one reported lost their money
https://www.lowyat.net/2018/175119/pdrm-cci...ort-not-yet-in/
heinlein
post Dec 18 2018, 03:36 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
QUOTE(TarePanda @ Dec 18 2018, 03:32 PM)
No one can use your inactivate debit or credit card....

You can ask your family to check thier bank account if you are worried.

FYI, police stated no one reported lost their money
https://www.lowyat.net/2018/175119/pdrm-cci...ort-not-yet-in/
*
we all know report police no use
OldSchoolJoke
post Dec 18 2018, 03:36 PM

Getting Started
**
Junior Member
285 posts

Joined: Mar 2010
QUOTE(okuribito @ Dec 18 2018, 02:13 PM)
Thx bro, saw that & thinking thru the implications. How does CIMB store passwords? As Is? or after hashing?

If after hashing, old passwords longer than 8char should not be able to get in if just key in first 8 chars. Why? becos the hash would be diff. No? Only way can get in is IF the old password was stored As Is. Wonder if that makes sense  hmm.gif
*
hashed/salted or not i no idea.

good question you asked.
but probably, with old format of password, CIMB also only takes in 8 character.

e.g:
you create account with password abc1234567890,
before inserting into database, it only takes in abc12345 and hash/salt it.

this is to my assumption only. i got no idea how they work on the password.
if it stored as plain text then doh.gif .

90 Pages « < 75 76 77 78 79 > » Top
 

Change to:
| Lo-Fi Version
0.0157sec    0.90    6 queries    GZIP Disabled
Time is now: 11th December 2025 - 08:16 PM