Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
briantwj
post Dec 17 2018, 01:50 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(mambangafro @ Dec 17 2018, 01:48 AM)
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
*
Boleh kut. Ni more like masalah login authorisation je for cimbclicks. Naik grab je bruh. Atau suruh si Wanni jadi mamat je
briantwj
post Dec 17 2018, 01:52 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(veron4best @ Dec 17 2018, 01:50 AM)
how to change password?

only by call customer servic?
*
Login to cimbclicks. But can’t change if u login via webpage on android. I guna IPad only can change. Bottom left settings icon.
briantwj
post Dec 17 2018, 01:53 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(maxpudding @ Dec 17 2018, 01:52 AM)
Besok masuk kerja lambat

Blame cimb

Lulz

Luckily my time is flexible
*
Kerja apa bang
briantwj
post Dec 17 2018, 01:55 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(maxpudding @ Dec 17 2018, 01:54 AM)
Pekebun berjaya
*
Fun Berjaya. Got ur hint bruh. brows.gif
briantwj
post Dec 17 2018, 01:56 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(JimbeamofNRT @ Dec 17 2018, 01:55 AM)
suddenly feel uneasy to do that lol

god knows maybe the captcha shit is a trojan ... KNNCCB NOW I AM PARANOID
what if the captcha shit already record all the login and pwd... waiting for the right time to strike?
*
I don’t think captcha works that way...
briantwj
post Dec 17 2018, 02:00 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Hmm. Just my guess. Maybe there are still a lot of ppl that didn’t change their password to cimb latest policy, a lot still on the 8 character password policy.

And recently a lot of brute force on user login. So they implement the captcha thing.

Doing my best making up setoli. Lol
briantwj
post Dec 17 2018, 02:07 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(teehk_tee @ Dec 17 2018, 02:04 AM)
can confirm.. once change pw is ok.

but this dent in trust, i cannot accept.
*
Plus the sudden captcha implementation. I never see bank industry use captcha for ebanking before. LOL.

It’s like, they know there are scripts trying to brute force. But captcha? Seriously?

This post has been edited by briantwj: Dec 17 2018, 02:08 AM
briantwj
post Dec 17 2018, 02:09 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Wasted 2 hours of sleep for this shit
briantwj
post Dec 17 2018, 02:17 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
Chrome? Tap the 3 dot icon on the top right. It should be there. Something like request desktop site
briantwj
post Dec 17 2018, 02:19 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Headline tmr:

We have updated password policy and send notice. However users are still on old policy. Hence we implemented captcha as additional security measure.

To those who are still using the old password policy. Please update to our new password policy. Thanks.

Lol
briantwj
post Dec 17 2018, 07:13 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Wadapak. I already reset my password B4 I sleep. Now.j login. It ask me to reset again????

Anyone facing same issue?
briantwj
post Dec 17 2018, 08:33 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Feck.. mine acting weird. I reset my password y'day B4 I sleep. Now I login. It ask me to update password again. Hmm. Fishy.
briantwj
post Dec 17 2018, 09:19 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(linkinstreet @ Dec 17 2018, 09:16 AM)
Last night new password can be more than 8 chars + you need a special char too. A bit too late if you ask me tho
*
They already announce new password policy earlier this year if I rmb correctly. Just they did not force all users to update. They just put an announcement in their website.

So yg x update policy all kena this exploit. Those that have updated password prior to this, should not be affected.

And guys. About those that keep asking if ur affected. If u have a cimbclicks account and is still on the old 8 character password policy, then yes, you are affected.
briantwj
post Dec 17 2018, 10:39 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(wilsonjay @ Dec 17 2018, 10:31 AM)
but i saw the complaints, most of them complain that the transactions are done using debit card via paypal, so its their debit cards that's compromised not their accounts -__-

cause i kena that paypal thing before
*
coz ppl are adding things up.

first is the recaptcha thing. Then it's the password 8 characters thing. Then the paypal direct debit things. Basically ppl are just stringing stuff together. lul.

But still, using captcha on e-banking is just.... plain stupid. Shows how weak is their security. And the password thing, I do recall they have announcement with new password policy, but they just let users know, they didn do a hard reset, asking all users to reset. So it's partly their fault / users' fault.

With the captcha thing deployed over the weekend, ppl just adding stuffs together.
briantwj
post Dec 17 2018, 11:35 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(se7en @ Dec 17 2018, 11:32 AM)
6. The time it takes to crack a 8 digit password is under 5 minutes. Throw in characters and it takes closer to an hour. The problem here is that CIMB doesn't block login failures. And instead of blocking login failures, they implement a reCaptcha. Stupid smart.
*
Does this mean even at 3 failed login attempt, it will use the captcha and not block the account? hmm.gif
briantwj
post Dec 17 2018, 11:43 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(kcchong2000 @ Dec 17 2018, 11:41 AM)
May i ask those that didn't do transactions this weekend, will they kena?!? Or those who click the captcha thing?
*
as long as u have a cimbclicks login account, u are affected.
briantwj
post Dec 17 2018, 01:31 PM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


No wonder starting last month I start seeing ppl say, if ppl ask for u tac, don't give. Must be that time already got ppl exploiting. But they need the TAC to buy stuff or transfer. So they msg ppl to get TAC.
briantwj
post Dec 17 2018, 05:13 PM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


transferred my funds to UK bank dah. lul
briantwj
post Dec 17 2018, 05:25 PM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(upcars @ Dec 17 2018, 05:24 PM)
Statements released that no one was hacked by both cimb web and thestar. In here I read ppl losing money through this hack. Mana Satu cerita yang betui ni ?
*
losing money is due to the paypal, not due to the password.
briantwj
post Jan 2 2019, 04:13 PM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


something wrong with their bizchannel today. just fyi. laugh.gif

anyone that runs business and using cimb as payroll got issue iinm.

3 Pages < 1 2 3 >Top
 

Change to:
| Lo-Fi Version
0.0614sec    0.89    7 queries    GZIP Disabled
Time is now: 13th December 2025 - 09:22 AM