Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
Duckies
post Dec 17 2018, 02:44 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(rooney723 @ Dec 17 2018, 02:43 PM)
ahh ic, got it got it, before dis i thought their backend can only accept 8 chars MAX regardless of special chars n the logic doesnt make sense to me
*
Example if your password is 123456789 without special characters, the stupid logic will take the first 8 characters and log you in. That is why any characters after the first 12345678 does not matter.

Example if your password is 123456789!@, then the system still logs you in because it has special characters, so the length can be up to 20 as long as it has special characters.
Duckies
post Dec 17 2018, 02:50 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(rooney723 @ Dec 17 2018, 02:48 PM)
yup, that means their backend got 2 types of verification, 1 for legacy 8 chars pass and the other for newer pass wif special chars, they should reject pass >8 chars n no special chars instead of substring  doh.gif
*
Yep doh.gif

 

Change to:
| Lo-Fi Version
0.0443sec    0.84    7 queries    GZIP Disabled
Time is now: 12th December 2025 - 09:27 AM