Outline ·
[ Standard ] ·
Linear+
Chat CIMB kena hack?
|
Supreme1394
|
Dec 16 2018, 10:46 PM
|
|
QUOTE(feiraron @ Dec 16 2018, 10:45 PM) OP dude the link you post got nothing to do with the capthcha thing, not even a mention there?? looks to me like their debit card is registered and linked with paypal and some sort of exploit there Good point, TS pls explain.
|
|
|
|
|
|
MANUTD676767
|
Dec 16 2018, 10:48 PM
|
|
So what is the problem with the captchcha thing?
|
|
|
|
|
|
Quantum Geist
|
Dec 16 2018, 10:48 PM
|
Getting Started

|
QUOTE(feiraron @ Dec 16 2018, 10:45 PM) OP dude the link you post got nothing to do with the capthcha thing, not even a mention there?? looks to me like their debit card is registered and linked with paypal and some sort of exploit there Then got card numbers leak?
|
|
|
|
|
|
howszat
|
Dec 16 2018, 10:48 PM
|
|
reCaptcha is already quite a common thing, lah.
|
|
|
|
|
|
TSpeja5081
|
Dec 16 2018, 10:49 PM
|
Getting Started

|
QUOTE(feiraron @ Dec 16 2018, 10:45 PM) OP dude the link you post got nothing to do with the capthcha thing, not even a mention there?? looks to me like their debit card is registered and linked with paypal and some sort of exploit there https://m.facebook.com/story.php?story_fbid...100000339018919Original post..that one i post is feedback from other case.but similar
|
|
|
|
|
|
klaxoon.my
|
Dec 16 2018, 10:49 PM
|
New Member
|
|
|
|
|
|
|
se7en
|
Dec 16 2018, 10:50 PM
|
resistance is futile
|
ok, ran through their page, apart from the recaptcha, nothing else to worry about.
and for the record, using recaptcha on a bank login page is plain dumb.
|
|
|
|
|
|
GOPI56
|
Dec 16 2018, 10:51 PM
|
|
QUOTE(peja5081 @ Dec 16 2018, 11:49 PM) https://m.facebook.com/story.php?story_fbid...100000339018919Original post..that one i post is feedback from other case.but similar Recently a exploit involving Paypal payment gateway was shown in some videos.
|
|
|
|
|
|
Cookie101
|
Dec 16 2018, 10:52 PM
|
|
QUOTE(Quantum Geist @ Dec 16 2018, 10:48 PM) Then got card numbers leak? Either their data is compromised by their own carelessness on website or data breach at seller side like the Starwood issue. But many water fish just blame it on banks and make malicious fitnahs. This shows the general public lack of common sense to determine the reliability of the information and knowledge of the basic issue. #donedakwah
|
|
|
|
|
|
TSpeja5081
|
Dec 16 2018, 10:52 PM
|
Getting Started

|
QUOTE(se7en @ Dec 16 2018, 10:50 PM) ok, ran through their page, apart from the recaptcha, nothing else to worry about. and for the record, using recaptcha on a bank login page is plain dumb. Ok.maybe nothing to do we recaptcha.but many report unauthorized usage from paypal
|
|
|
|
|
|
ketaros
|
Dec 16 2018, 10:52 PM
|
Getting Started

|
one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself
|
|
|
|
|
|
Quantum Geist
|
Dec 16 2018, 10:53 PM
|
Getting Started

|
QUOTE(se7en @ Dec 16 2018, 10:50 PM) ok, ran through their page, apart from the recaptcha, nothing else to worry about. and for the record, using recaptcha on a bank login page is plain dumb. plus the weird placement of recaptcha is kinda throwing people off
|
|
|
|
|
|
DarkAeon
|
Dec 16 2018, 10:54 PM
|
|
QUOTE(ketaros @ Dec 16 2018, 10:52 PM) one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself really? someone is so fired
|
|
|
|
|
|
jimmyktp
|
Dec 16 2018, 10:54 PM
|
Getting Started

|
QUOTE(se7en @ Dec 16 2018, 10:50 PM) ok, ran through their page, apart from the recaptcha, nothing else to worry about. and for the record, using recaptcha on a bank login page is plain dumb. Yup. Also, CIMB limiting their password to only 8 characters, it's plain dumb. Other countries already using 2FA for banking transaction, but Malaysian banks still use Mobile Number authentication. Just a ticking timebomb considering how easy it is to hijack a number..
|
|
|
|
|
|
Shanks
|
Dec 16 2018, 10:56 PM
|
Getting Started

|
Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit.
|
|
|
|
|
|
stupiak07
|
Dec 16 2018, 10:57 PM
|
|
QUOTE(Shanks @ Dec 16 2018, 10:56 PM) Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit. Number is legit but alot number spoofer using this number
|
|
|
|
|
|
ihavenoidea
|
Dec 16 2018, 10:58 PM
|
|
the person must have had link his bank info to paypal and had his paypal info hacked or something. you dont need tac if you are paying using paypal
|
|
|
|
|
|
party
|
Dec 16 2018, 10:58 PM
|
|
QUOTE(Cookie101 @ Dec 16 2018, 10:52 PM) Either their data is compromised by their own carelessness on website or data breach at seller side like the Starwood issue. But many water fish just blame it on banks and make malicious fitnahs. This shows the general public lack of common sense to determine the reliability of the information and knowledge of the basic issue. #donedakwah But seems only C*** is always being affected? I dun see other banks kena that much.
|
|
|
|
|
|
feiraron
|
Dec 16 2018, 10:59 PM
|
Getting Started

|
most likely leak card info but how do they get around the registration of card into paypal is another story, as far as i know, paypal charge you with a code number in the description, and you can only get that code via your statement. after input the code only can link. QUOTE(ketaros @ Dec 16 2018, 10:52 PM) one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself its not that you can input any text after your pass, most people didnt realize this but before this cimb only can input 8 character as password, really dumb but i think since this month only they allow for more characters as password. made me scratched my head a bit when it happen, last2 i just input first 8 character then walla. all this while i thought it was capturing my full password even during regeistration This post has been edited by feiraron: Dec 16 2018, 11:01 PM
|
|
|
|
|
|
jimmyktp
|
Dec 16 2018, 10:59 PM
|
Getting Started

|
QUOTE(Shanks @ Dec 16 2018, 10:56 PM) Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit. Instead of recaptcha, they should follow what UK banks doing. 2FA. But problem is that could be too complicated for users to set up the first time. Recaptcha is to identify bots. What about real humans? I don't think recaptcha is relevant for a banking website. I'm using HSBC UK's 2FA. Really powerful. But is a pain to set up for the first time. This post has been edited by jimmyktp: Dec 16 2018, 11:00 PM
|
|
|
|
|