Welcome Guest ( Log In | Register )

90 Pages « < 78 79 80 81 82 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
akecema
post Dec 18 2018, 09:13 PM

Casual
***
Junior Member
436 posts

Joined: Mar 2005


QUOTE(Domomo @ Dec 18 2018, 06:41 PM)
As I can see this issue was nothing then become attention because of media,I wonder if other bank also got this problem not only cimb? suddenly everyone just say  got problem la , lose money la.I do remember last time Maybank go issue with their portal but that time there were no "viral" movement,and they were forgotten as time passes on. Now the question is, how many ppl here really were hacked??
*
I just know viral only
Then all panic. True o not still dont know
Power of viral. Sometime it fake only to make customers panic.
Till now no customer i hear make police report because lose money

TarePanda
post Dec 18 2018, 09:13 PM

Enthusiast
*****
Senior Member
989 posts

Joined: Sep 2004


QUOTE(Forgotoldaccount @ Dec 18 2018, 07:55 PM)
WTA. Yesterday I can enter my cimbclick using my existing password. Today evening it says invalid password & ask me to reset. But to reset password, they ask for my atm & atm pin. Im quite sceptical to provide. Is this legit?
Sorry if this has been mentioned. I'm feel like drowning going through 80 pages
*
Safest way is to visit CIMB branch or call CIMB customer service to verify...Don't simply believe what ppl tell you, they might not really know the correct procedure

Check your website whether it start with "https://www.cimbclicks.com.my"

"HTTPS" means secured website

This post has been edited by TarePanda: Dec 18 2018, 09:17 PM
dr0olingb0at
post Dec 18 2018, 09:17 PM

Casual
***
Junior Member
389 posts

Joined: Jul 2011
QUOTE(akecema @ Dec 18 2018, 09:13 PM)
I just know viral only
Then all panic. True o not still dont know
Power of viral. Sometime it fake only to make customers panic.
Till now no customer i hear make police report because lose money
*
user posted image
Domomo
post Dec 18 2018, 09:37 PM

Getting Started
**
Junior Member
172 posts

Joined: Jul 2011
From: klang,selangor


QUOTE(marche @ Dec 18 2018, 07:14 PM)
u never read is it?

this issue is real

people are losing money

yes, not everyone but a lot of them

this is security issue not portal

and it happen at the same time frame
*
I read it,yes there was and issue but as we know they already address the issue promptly,what I want to say is cimb has the guts to admit at settle it but other Banks quietly sweep the issue under the rug,if not for the viral issue there would not be a big issue.
junsheng
post Dec 18 2018, 09:42 PM

---> pokemon ftw <---
******
Senior Member
1,257 posts

Joined: Apr 2011
From: Penang Malaysia, sometime KL


QUOTE(Domomo @ Dec 18 2018, 09:37 PM)
I read it,yes there was and issue but as we know they already address the issue promptly,what I want to say is cimb has the guts to admit at settle it but other Banks quietly sweep the issue under the rug,if not for the viral issue there would not be a big issue.
*
lol if lyn no expose u tot cimb will admit it?

heinlein
post Dec 18 2018, 10:31 PM

Regular
******
Senior Member
1,793 posts

Joined: Jun 2010
QUOTE(Domomo @ Dec 18 2018, 09:37 PM)
I read it,yes there was and issue but as we know they already address the issue promptly,what I want to say is cimb has the guts to admit at settle it but other Banks quietly sweep the issue under the rug,if not for the viral issue there would not be a big issue.
*
My issue still no news. So how?
upcars
post Dec 18 2018, 10:32 PM

Getting Started
**
Junior Member
95 posts

Joined: Feb 2017
QUOTE(heinlein @ Dec 18 2018, 10:31 PM)
My issue still no news. So how?
*
Polis repot takes some time to process. Sir back with popcorn on us .
Rhetoric
post Dec 18 2018, 10:33 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
inb4 use Huawei phone.
lawliet88
post Dec 18 2018, 10:34 PM

Enthusiast
*****
Junior Member
994 posts

Joined: May 2010
From: Cheras For PPL to Live 1


just read sin chew daily , they put this cimb thing as "fake news" section lol icon_idea.gif

okuribito
post Dec 18 2018, 10:34 PM

Regular
******
Senior Member
1,021 posts

Joined: Mar 2010
QUOTE(okuribito @ Dec 18 2018, 02:13 PM)
Thx bro, saw that & thinking thru the implications. How does CIMB store passwords? As Is? or after hashing?

If after hashing, old passwords longer than 8char should not be able to get in if just key in first 8 chars. Why? becos the hash would be diff. No? Only way can get in is IF the old password was stored As Is. Wonder if that makes sense  hmm.gif
*
QUOTE(brkli @ Dec 18 2018, 02:29 PM)
no, the code snippet does not prove anything on how they store the password. it only shows thier 'lazy' development to do not want to change backend API, so they convert/translate those inputs (for this case password) as front end.
*
QUOTE(silverhawk @ Dec 18 2018, 06:18 PM)
This is not necessarily the case. What the Javascript is doing is encrypting the password for transmission. If you read the code, it also does the same thing for username. You might ask.. why? Its to protect against sniffing or mitm attacks. This way even if an attacker sniffs out your traffic, its not obvious what your actual plaintext username/password is. They can still replay the request to get in, but at least they don't know what your actual username/pass is.. which you might be using for other sites as well.

The backend could then just decrypt the value, then run it through a different hash/encryption algorithm to check against the DB.

The stupid thing about CIMB was having a max limit on password length. Even now it doesn't make sense that its limited to 20 chars, if you're encrypting/hashing passwords the max length shouldn't really matter.
*
silverhawk the encryptedPass = MFPInit.encrypteMY(password) is the encryption u mentioned, right? Curious, isn't that encryption done by the user's browser based on the bank's ssl cert for security during transmission? Based on the fact that pre-18Nov passwords can be used when truncated to 1st 8 characters, I strongly believe they store raw passwords somewhere in their system. If they ONLY store hashes, there's nothing to compare when shortened old passwords are submitted! Did I misunderstand anything?
heinlein
post Dec 18 2018, 10:41 PM

Regular
******
Senior Member
1,793 posts

Joined: Jun 2010
QUOTE(upcars @ Dec 18 2018, 10:32 PM)
Polis repot takes some time to process. Sir back with popcorn on us .
*
That officer like go change card settle. Macam dun care. I think they good at covering.
rauma
post Dec 18 2018, 10:41 PM

New Member
*
Newbie
15 posts

Joined: Mar 2010


QUOTE(heinlein @ Dec 18 2018, 04:34 PM)
user posted image
user posted image
This is one of the sms received. The available and current amount not tally and match the sms deducted amount
*
Looked up ac cancer soc on Google...

Seems like a hospital in ampang...

http://www.moderncancerhospital.com.my

These guys have been charging you... Not sure if this is a legit hospital, never heard of them before. I see many of these kinds of sites where they ask people to write their names, address, phone number etc (lol only dummies will fall for this) pretending they want to contact you later (why the hell need all that info for). Try ask family members if they've visited any sites asking them to submit personal details.
heinlein
post Dec 18 2018, 10:47 PM

Regular
******
Senior Member
1,793 posts

Joined: Jun 2010
QUOTE(rauma @ Dec 18 2018, 10:41 PM)
Looked up ac cancer soc on Google...

Seems like a hospital in ampang...

http://www.moderncancerhospital.com.my

These guys have been charging you... Not sure if this is a legit hospital, never heard of them before. I see many of these kinds of sites where they ask people to write their names, address, phone number etc (lol only dummies will fall for this) pretending they want to contact you later (why the hell need all that info for). Try ask family members if they've visited any sites asking them to submit personal details.
*
Thing is no one even family knows my debit card info. This case really power. I thought the SMS is fake cuz normally cimb sms start with RM0.00 CIMB:

This one starts with RM0.00 CIMB BANK:
Money deduction is not instaneous. It only deducts 2 days later.

Furthermore, this is less likely to be paypal transaction, my card is with me this whole time.

This post has been edited by heinlein: Dec 18 2018, 10:49 PM
PhakFuhZai
post Dec 18 2018, 10:58 PM

harimau putih
******
Senior Member
1,587 posts

Joined: Apr 2011
if inside CIMB Clicks UI there is no mention of your debit card number

can I safe to assume that my CIMB CASA does not comes with a debit card?


John Chaser
post Dec 19 2018, 12:25 AM

On my way
****
Junior Member
685 posts

Joined: Sep 2005


Nasi lemak tech says cimb did nothing wrong:
NLT

heinlein
post Dec 19 2018, 12:40 AM

Regular
******
Senior Member
1,793 posts

Joined: Jun 2010
QUOTE(John Chaser @ Dec 19 2018, 12:25 AM)
Nasi lemak tech says cimb did nothing wrong:
NLT
*
It's easy to talk kok when they are not the victim. Even the police officer i report act like nothing happen. I dun trusted media anymore. They are controlled by corporation.
Mr_47
post Dec 19 2018, 12:44 AM

***NOT MODERATOR *** Post : +10,000,000,00 Warn: 100%
*******
Senior Member
4,341 posts

Joined: Jan 2003
From: Bora-bora u jelly? Special: Age of multi-monitor



what bs cant change pswd 2 days edi wtf cimb

maxpudding
post Dec 19 2018, 07:40 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(lawliet88 @ Dec 18 2018, 10:34 PM)
just read sin chew daily , they put this cimb thing as "fake news" section lol  icon_idea.gif
*
Fake news butoh

Must be getting loan and extra credits from cimb
Twins10
post Dec 19 2018, 07:55 AM

Enthusiast
*****
Junior Member
919 posts

Joined: Aug 2015
No bank run in my branch. Maybe all online. Called cust service this morning. Short waiting time.
maxpudding
post Dec 19 2018, 08:21 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(John Chaser @ Dec 19 2018, 12:25 AM)
Nasi lemak tech says cimb did nothing wrong:
NLT
*
Wow challenging se7en issit

90 Pages « < 78 79 80 81 82 > » Top
 

Change to:
| Lo-Fi Version
0.0919sec    0.47    6 queries    GZIP Disabled
Time is now: 14th December 2025 - 01:12 AM