QUOTE(lawliet88 @ Dec 18 2018, 10:34 PM)
Well, that is because they got the information from CIMB official statement.Chat CIMB kena hack?
Chat CIMB kena hack?
|
|
Dec 19 2018, 08:34 AM
|
![]()
Newbie
11 posts Joined: Aug 2014 |
|
|
|
|
|
|
Dec 19 2018, 08:35 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
7,044 posts Joined: Nov 2007 |
QUOTE(Mr_47 @ Dec 19 2018, 12:44 AM) there's been a few shares earlier on...likely your password was still using the old policy which is only 8 chars. try this: * when changing password, just use the first 8 chars of old password as your old password * use complex password for the new password |
|
|
Dec 19 2018, 08:46 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,341 posts Joined: Jan 2003 From: Bora-bora u jelly? Special: Age of multi-monitor |
QUOTE(mydragoon @ Dec 19 2018, 08:35 AM) there's been a few shares earlier on... dang thats workslikely your password was still using the old policy which is only 8 chars. try this: * when changing password, just use the first 8 chars of old password as your old password * use complex password for the new password thanks mate |
|
|
Dec 19 2018, 08:51 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,144 posts Joined: Jan 2003 From: Republik Of Kelantanese |
QUOTE(mydragoon @ Dec 19 2018, 08:35 AM) there's been a few shares earlier on... 4KlsgiwwRkmXzUzejwCufy4HMQO5bN7LERoNwzCBX5o7AqULFX7VOg8oOQmthXOpqvrfVdc5C4UMKJpwDMQHHFTqoso1LF5NivnClikely your password was still using the old policy which is only 8 chars. try this: * when changing password, just use the first 8 chars of old password as your old password * use complex password for the new password |
|
|
Dec 19 2018, 08:54 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
7,044 posts Joined: Nov 2007 |
|
|
|
Dec 19 2018, 09:26 AM
|
![]()
Junior Member
17 posts Joined: Jan 2003 |
QUOTE(heinlein @ Dec 18 2018, 10:47 PM) Thing is no one even family knows my debit card info. This case really power. I thought the SMS is fake cuz normally cimb sms start with RM0.00 CIMB: Wow, your case is different. May I know if you use CIMB app for mobile phone OR just CIMB clicks website? Did the transaction ask any SMS tag?This one starts with RM0.00 CIMB BANK: Money deduction is not instaneous. It only deducts 2 days later. Furthermore, this is less likely to be paypal transaction, my card is with me this whole time. |
|
|
|
|
|
Dec 19 2018, 09:35 AM
Show posts by this member only | IPv6 | Post
#1607
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,794 posts Joined: Jun 2010 |
QUOTE(tonywonghs @ Dec 19 2018, 09:26 AM) Wow, your case is different. May I know if you use CIMB app for mobile phone OR just CIMB clicks website? Did the transaction ask any SMS tag? Only use cimbclick website. Got sms but check no deduction so thought is scammer's prank to cause panic. Who knows really money gone after 2 days. Only found out after lowyat news say possible cimb hacked. I no day day open cimbclick check my acc balance habit. |
|
|
Dec 19 2018, 09:47 AM
|
![]() ![]()
Junior Member
74 posts Joined: Jan 2013 |
Similar deduction thing happened to me early this year but with MOLPAY, not sure how it was charged to my debit card. I went to CIMB, changed my card and disabled Debit as a precautionary measures. Thankfully, CIMB reimbursed my money
|
|
|
Dec 19 2018, 09:54 AM
|
![]() ![]() ![]()
Junior Member
431 posts Joined: Aug 2012 |
QUOTE(John Chaser @ Dec 19 2018, 12:25 AM) They did mention did nothing wrong @ cimb clicksother all wrong did not mention too. |
|
|
Dec 19 2018, 09:55 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
4,553 posts Joined: Jan 2003 From: Shah Alam |
if cimb not wrong then how come only cimb kena
is there other bank kena same attack? |
|
|
Dec 19 2018, 10:07 AM
|
![]() ![]()
Junior Member
291 posts Joined: Sep 2007 |
QUOTE(sanosizo @ Dec 19 2018, 09:55 AM) See how they putar..unauthorized transaction not related with cimb click - which is correct.but not mention unauthorized transaction of stolen data..they said unauthorized transaction is still low and under controlThis post has been edited by peja5081: Dec 19 2018, 10:09 AM |
|
|
Dec 19 2018, 12:10 PM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,021 posts Joined: Mar 2010 |
QUOTE(okuribito @ Dec 18 2018, 10:34 PM) silverhawk the encryptedPass = MFPInit.encrypteMY(password) is the encryption u mentioned, right? Curious, isn't that encryption done by the user's browser based on the bank's ssl cert for security during transmission? Based on the fact that pre-18Nov passwords can be used when truncated to 1st 8 characters, I strongly believe they store raw passwords somewhere in their system. If they ONLY store hashes, there's nothing to compare when shortened old passwords are submitted! Did I misunderstand anything? With the benefit of the nasilemakTech rebuttal, they say the truncation to 8 chars is not an issue at all because ALL old passwords are 8chars long anyway. IF that's true, yeah it's a non issue. But why need slice with substring(0, 8) ?? BUT I asked here and some people said that their old passwords were longer than 8 chars. In which case, logic says that CIMB must have the passwords stored As Is somewhere in their system So which is it? Were old passwords pre 18Nov exactly 8 chars OR minimum 8 chars (ie longer also got) ?? PS: those who kena unauthorised transactions should flood nasilemak tech with proof / police reports etc (where's the batu api smiley PPS: just saw the latest version of se7en's article ... This post has been edited by okuribito: Dec 19 2018, 12:20 PM |
|
|
Dec 19 2018, 12:14 PM
|
![]() ![]() ![]()
Junior Member
431 posts Joined: Aug 2012 |
QUOTE(sanosizo @ Dec 19 2018, 09:55 AM) once facebook saw from maybank debit card by paypal also,but then only 1 not sure some people try to gain attraction or what la. Cimb mean nothing wrong in CIMB@Clicks but other part of CIMB all gone wrong. |
|
|
|
|
|
Dec 19 2018, 12:18 PM
Show posts by this member only | IPv6 | Post
#1614
|
![]() ![]()
Junior Member
95 posts Joined: Feb 2017 |
|
|
|
Dec 19 2018, 01:18 PM
|
![]() ![]()
Junior Member
173 posts Joined: Mar 2015 |
|
|
|
Dec 19 2018, 03:06 PM
|
![]() ![]()
Junior Member
78 posts Joined: Jul 2013 |
lol no wonder najib brother jump out of ship,he already knew this shit gonna happened
https://www.thestar.com.my/business/busines...zak-steps-down/ |
|
|
Dec 19 2018, 03:10 PM
|
![]() ![]() ![]()
Junior Member
404 posts Joined: Dec 2008 |
Want to see if BNM take action or not.
|
|
|
Dec 19 2018, 03:41 PM
|
|
Elite
4,956 posts Joined: Jan 2003 |
QUOTE(okuribito @ Dec 19 2018, 12:10 PM) BUT I asked here and some people said that their old passwords were longer than 8 chars. In which case, logic says that CIMB must have the passwords stored As Is somewhere in their system From what I understand, there were 3 steps to this1. Passwords were allowed to be 8 or more characters 2. Rules changed, passwords allowed MAX 8 characters 3. Rules changed again, passwords allowed 8-20 characters So if you had a password in (1) that was longer than 8 chars, it was truncated. Maybe the passwords were stored encrypted instead of hashed, so was possible to work out the original password and truncate it for (2). QUOTE(okuribito @ Dec 19 2018, 12:10 PM) With the benefit of the nasilemakTech rebuttal, they say the truncation to 8 chars is not an issue at all because ALL old passwords are 8chars long anyway. They likely need to slice it because the backend does not know if this is a new/old password format. By right, backend should not care about such things. The fact that they slice says nothing about whether the passwords were stored as hashes or not. IF that's true, yeah it's a non issue. But why need slice with substring(0, 8) ?? So which is it? Were old passwords pre 18Nov exactly 8 chars OR minimum 8 chars (ie longer also got) ?? PS: those who kena unauthorised transactions should flood nasilemak tech with proof / police reports etc (where's the batu api smiley PPS: just saw the latest version of se7en's article ... Lets say your very old password was: "lowyatisthebest" Then CIMB stupidly changed their rules that passwords must only be 8 characters long, so your password now is: "lowyatis" They can hash this value, and since they hash it they will always need the 8 character version of your password to compare with the DB. They don't have to store it as plaintext. Its very unlikely that they are storing passwords in plaintext, wouldn't be able to pass any form of certification/audit if that were the case. |
|
|
Dec 19 2018, 03:51 PM
|
![]() ![]() ![]() ![]() ![]()
Senior Member
857 posts Joined: Jan 2005 From: Mlk, Klang |
QUOTE(heinlein @ Dec 19 2018, 09:35 AM) Only use cimbclick website. Got sms but check no deduction so thought is scammer's prank to cause panic. Who knows really money gone after 2 days. Only found out after lowyat news say possible cimb hacked. I no day day open cimbclick check my acc balance habit. but all online transaction must use TAC rite? |
|
|
Dec 19 2018, 04:06 PM
|
![]() ![]()
Junior Member
191 posts Joined: Aug 2010 From: Town of Eureka |
» Click to show Spoiler - click again to hide... « NLT has amended the two articles in question and added a note in the first paragraph for clarity. https://nasilemaktech.com/cimb-did-nothing-...al-explanation/ https://nasilemaktech.com/debunking-mainstr...never-happened/ |
| Change to: | 0.0174sec
0.53
6 queries
GZIP Disabled
Time is now: 15th December 2025 - 07:46 PM |