Welcome Guest ( Log In | Register )

90 Pages « < 76 77 78 79 80 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
zacx
post Dec 18 2018, 03:48 PM

New Member
*
Junior Member
27 posts

Joined: Jul 2005


i have question here related to Paypal transaction fraud....

Can we disable "non 3D transaction" (the one that doesn't require OTP like paypal) on our debit card to prevent case like this???
apiezsneo
post Dec 18 2018, 03:53 PM

Joined: Today, 01:05 AM
***
Junior Member
333 posts

Joined: Oct 2008


QUOTE(TarePanda @ Dec 18 2018, 03:32 PM)
No one can use your inactivate debit or credit card....

You can ask your family to check thier bank account if you are worried.

FYI, police stated no one reported lost their money
https://www.lowyat.net/2018/175119/pdrm-cci...ort-not-yet-in/
*
Good to know that. Thanks bro. But still, remember the time when it was compulsory to change all normal card to debit card. I think if we did not tell them to deactivate the debit card feature, it will automatically activated once we changed it right?
BenYeeHua
post Dec 18 2018, 03:56 PM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(zacx @ Dec 18 2018, 03:48 PM)
i have question here related to Paypal transaction fraud....

Can we disable "non 3D transaction" (the one that doesn't require OTP like paypal) on our debit card to prevent case like this???
*
One of my friend had tie his debit card to Google for verification half of year ago, CIMB did blocked it and sms inform whether enable non TAC transaction or not.

So ya, it should have disabled long ago, but somehow they enabled it back as default? hmm.gif sweat.gif

Or it could be the Paypal payment gateway at MY, so CIMB enable/allow by default, which causing this issues.
zemega
post Dec 18 2018, 04:02 PM

Enthusiast
*****
Junior Member
723 posts

Joined: Jul 2008
QUOTE(heinlein @ Dec 18 2018, 03:36 PM)
we all know report police no use
*
No use since police usually don't do anything. That's mostly correct to most people

But many agency still needs the police report done to build up the statistics. If only you can make police report online.

In the end, BNM said, no police report, nothing had happened, no one lost their money. For agency like BNM to actually make an official report saying CIMB screwed up in 2018, they need to be based on something, like the police report, the MCMC report, the TTPM cases, etc.

So make those police reports. Then, next year BNM can publish official report, CIMB screwed up in 2018. This much CIMB customers/account holders lost this much money. Also this much customers confirm/testify can login with incorrect password. In order for agency like BNM to acknowledge that CIMB screwed up is official reports by customers, that is police reports and the likes.

Even though bank customers knows they have been wronged by the bank, without official reports, BNM can only say officially no customer has been wronged by bank, because no reports were filed by the customers.

No official report, nothing had happened according to government agency. You know how Malaysia is, sometimes they are too rigid and fixated on formalities.
TarePanda
post Dec 18 2018, 04:03 PM

Enthusiast
*****
Senior Member
989 posts

Joined: Sep 2004


QUOTE(apiezsneo @ Dec 18 2018, 03:53 PM)
Good to know that. Thanks bro. But still, remember the time when it was compulsory to change all normal card to debit card. I think if we did not tell them to deactivate the debit card feature, it will automatically activated once we changed it right?
*
You need to set pin in order to activate it. It's compulsory for debit and credit card, any bank.
TarePanda
post Dec 18 2018, 04:05 PM

Enthusiast
*****
Senior Member
989 posts

Joined: Sep 2004


QUOTE(heinlein @ Dec 18 2018, 03:36 PM)
we all know report police no use
*
We do what we think is right...

For me, police might or might not able to help but there is a higher chance to recover or backup if you report to police for any fraud case.
apiezsneo
post Dec 18 2018, 04:12 PM

Joined: Today, 01:05 AM
***
Junior Member
333 posts

Joined: Oct 2008


QUOTE(TarePanda @ Dec 18 2018, 04:03 PM)
You need to set pin in order to activate it. It's compulsory for debit and credit card, any bank.
*
Thanks for the clarification. You've been most helpful. 👍
heinlein
post Dec 18 2018, 04:18 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
user posted image
You want police report, i give you later
heinlein
post Dec 18 2018, 04:19 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
QUOTE(TarePanda @ Dec 18 2018, 04:05 PM)
We do what we think is right...

For me, police might or might not able to help but there is a higher chance to recover or backup if you report to police for any fraud case.
*
At police station now
heinlein
post Dec 18 2018, 04:34 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
user posted image
user posted image
This is one of the sms received. The available and current amount not tally and match the sms deducted amount
PleaseEnterYourName
post Dec 18 2018, 05:37 PM

Casual
***
Junior Member
386 posts

Joined: Jan 2006
From: between 0 and 1


QUOTE(heinlein @ Dec 18 2018, 04:34 PM)
user posted image
user posted image
This is one of the sms received. The available and current amount not tally and match the sms deducted amount
*
yea bro, make police report then go cimb change debit card. your card is being circulated among cyber criminal. show cimb staff the police report and ask for free change.

heinlein
post Dec 18 2018, 05:44 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
QUOTE(PleaseEnterYourName @ Dec 18 2018, 05:37 PM)
yea bro, make police report then go cimb change debit card. your card is being circulated among cyber criminal. show cimb staff the police report and ask for free change.
*
Just finish police report, yesterday transfer all available amount to other bank. Wait refund and will close the acc for good
lawliet88
post Dec 18 2018, 05:45 PM

Enthusiast
*****
Junior Member
993 posts

Joined: May 2010
From: Cheras For PPL to Live 1


btw did this go to other paper n tv media?
as far as I know astro news never mention this at all
heinlein
post Dec 18 2018, 05:45 PM

Regular
******
Senior Member
1,789 posts

Joined: Jun 2010
QUOTE(PleaseEnterYourName @ Dec 18 2018, 05:37 PM)
yea bro, make police report then go cimb change debit card. your card is being circulated among cyber criminal. show cimb staff the police report and ask for free change.
*
Just finish police report, yesterday transfer all available amount to other bank. Wait refund and will close the acc for good
kerolzarmyfanboy
post Dec 18 2018, 06:10 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
i have no fckin idea why i'm still getting Invalid User ID or Password [CLK00619] every single time try to change pw

already adhere to their instructions
- >8 characters
- alphanumeric, 1 upper, 1 lower, 1 special character
- not userID or secureword
- no consecutive number/character

i'm fckin pissed.. changed my own acc pw so easy, but for my mum's dunno y so hard
silverhawk
post Dec 18 2018, 06:18 PM

Eyes on Target
Group Icon
Elite
4,956 posts

Joined: Jan 2003


QUOTE(brkli @ Dec 18 2018, 02:29 PM)
no, the code snippet does not prove anything on how they store the password. it only shows thier 'lazy' development to do not want to change backend API, so they convert/translate those inputs (for this case password) as front end.
*
This is not necessarily the case. What the Javascript is doing is encrypting the password for transmission. If you read the code, it also does the same thing for username. You might ask.. why? Its to protect against sniffing or mitm attacks. This way even if an attacker sniffs out your traffic, its not obvious what your actual plaintext username/password is. They can still replay the request to get in, but at least they don't know what your actual username/pass is.. which you might be using for other sites as well.

The backend could then just decrypt the value, then run it through a different hash/encryption algorithm to check against the DB.

The stupid thing about CIMB was having a max limit on password length. Even now it doesn't make sense that its limited to 20 chars, if you're encrypting/hashing passwords the max length shouldn't really matter.
mydragoon
post Dec 18 2018, 06:27 PM

Look at all my stars!!
*******
Senior Member
7,044 posts

Joined: Nov 2007


QUOTE(kerolzarmyfanboy @ Dec 18 2018, 06:10 PM)
i have no fckin idea why i'm still getting Invalid User ID or Password [CLK00619] every single time try to change pw

already adhere to their instructions
- >8 characters
- alphanumeric, 1 upper, 1 lower, 1 special character
- not userID or secureword
- no consecutive number/character

i'm fckin pissed.. changed my own acc pw so easy, but for my mum's dunno y so hard
*
could it be existing password issue? friends had similar issue and they said if existing PW longer than 8 chars, when changing password, try using only first 8 chars
jesserider223
post Dec 18 2018, 06:30 PM

Getting Started
**
Junior Member
173 posts

Joined: Mar 2015


QUOTE(kerolzarmyfanboy @ Dec 18 2018, 06:10 PM)
i have no fckin idea why i'm still getting Invalid User ID or Password [CLK00619] every single time try to change pw

already adhere to their instructions
- >8 characters
- alphanumeric, 1 upper, 1 lower, 1 special character
- not userID or secureword
- no consecutive number/character

i'm fckin pissed.. changed my own acc pw so easy, but for my mum's dunno y so hard
*
calm down first bro, old password put only front first 8 characters

own acc passed xmungkin other cannot hmm.gif


MiLKTea
post Dec 18 2018, 06:34 PM

Enthusiast
*****
Senior Member
942 posts

Joined: Aug 2007
QUOTE(kerolzarmyfanboy @ Dec 18 2018, 06:10 PM)
i have no fckin idea why i'm still getting Invalid User ID or Password [CLK00619] every single time try to change pw

already adhere to their instructions
- >8 characters
- alphanumeric, 1 upper, 1 lower, 1 special character
- not userID or secureword
- no consecutive number/character

i'm fckin pissed.. changed my own acc pw so easy, but for my mum's dunno y so hard
*
I changed yesterday and today tak ada masalah pun.

Any sample of the password you intend to change to?
kerolzarmyfanboy
post Dec 18 2018, 06:37 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
QUOTE(mydragoon @ Dec 18 2018, 06:27 PM)
could it be existing password issue? friends had similar issue and they said if existing PW longer than 8 chars, when changing password, try using only first 8 chars
*
QUOTE(jesserider223 @ Dec 18 2018, 06:30 PM)
calm down first bro, old password put only front first 8 characters

own acc passed xmungkin other cannot  hmm.gif
*
Thanks you two! thumbup.gif

oh man.. been trying to change the pw since yesterday.. why cimb never mentioned need to put first 8 character only in the old password box doh.gif doh.gif

90 Pages « < 76 77 78 79 80 > » Top
 

Change to:
| Lo-Fi Version
0.0228sec    0.87    6 queries    GZIP Disabled
Time is now: 12th December 2025 - 02:42 AM