Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
TSpeja5081
post Dec 17 2018, 02:41 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(macyhouse @ Dec 17 2018, 02:36 PM)
https://www.cimbclicks.com.my/pdf/201812-Cl...-Public-FAQ.pdf
sorry on mobile .. boleh tolong screenshot and upload
*
Thanks..i put in front page
TSpeja5081
post Dec 17 2018, 03:21 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(maxpudding @ Dec 17 2018, 03:15 PM)
The tweet about the leak of cimb data is a major issue

Why cimb is not addressing that
*
U want their stock to crumble?admit mistake or fix silently like nothing happen.
Anyway,this is wakeup call for bank to safeguard their user data.
TSpeja5081
post Dec 17 2018, 03:43 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(heinlein @ Dec 17 2018, 03:29 PM)
Because of the news, I login check, lose RM49.04. No missing card, no TAC, no MSOS. The transfer can be made. Call paypal support found out both of my CIMB cards is linked to unknown paypal account holder. Requested permanent freeze at paypal and wait the missing money to be refunded from paypal. Waiting....

ps: cimb is not helping much, robot copy and paste to me only.
*
Confirm PayPal use?when it happen?if k kena mean this is broad issues..oh pls cancel the card also..mean u card data in their hand now

This post has been edited by peja5081: Dec 17 2018, 03:44 PM
TSpeja5081
post Dec 17 2018, 03:48 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(heinlein @ Dec 17 2018, 03:47 PM)
yes, confirm is paypal cuz cimb transaction details got paypal info which I dun understand. Should happen on 4 dec but only deducted on 6 dec 2018. On 4 dec, I did check my cimb and nothing deducted that time so I thought is some scammer tactic to prank me to be panic.
*
For PayPal u can dispute within 10 days.they will give back your money.
TSpeja5081
post Dec 17 2018, 07:44 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(huaweie5830 @ Dec 17 2018, 07:17 PM)
So seeing some people complaint here, incident upto few months ago

Does it means CIMB been neglected on this security issue for so long ?

They didnt aware so many fraud complaint this few months ?
*
I think they already aware..even mention and urge user to change password and be vigilant with fraud case but not mention anything about data breach.just urge user to change better password
TSpeja5081
post Dec 17 2018, 07:57 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(okuribito @ Dec 17 2018, 07:54 PM)
I guess this code snippet was lifted off the net today? ie current code, right?

Haven't read all posts here, but remember reading something about a recent change by CIMB to allow longer pw & with special characters?

And because some incompetent coder wrote the above snippet, hence the exploit was created?

Help me understand the logic...

if PW is at least 8char long, and includes special chars, then the entire pw string is passed to encryption function

if PW is at least 8char long, and dun include special chars, then the long pw is truncated & the front 8char string is passed to encryption function

if PW is < 8char long eg 7char or less, irrespective got special characters or not, then what happens? Won't password = password.substring(0, 8) evaluate to #error? Previously, wasn't there a minimum # of characters for passwords ie 8?

PS: i dunno coding. only trying to make sense of the if-then-else which is also used in excel tongue.gif
*
https://www.lowyat.net/2018/175102/what-cim...you-but-should/

Se7en already explained here.
TSpeja5081
post Dec 19 2018, 10:07 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(sanosizo @ Dec 19 2018, 09:55 AM)
if cimb not wrong then how come only cimb kena

is there other bank kena same attack?
*
See how they putar..unauthorized transaction not related with cimb click - which is correct.but not mention unauthorized transaction of stolen data..they said unauthorized transaction is still low and under control

This post has been edited by peja5081: Dec 19 2018, 10:09 AM
TSpeja5081
post Dec 20 2018, 03:40 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(heinlein @ Dec 20 2018, 03:28 PM)
suddenly cimb so keen to solve the problem even send me dispute pdf file to sign for blocking the card and investigate. Something happen?
*
Too many people cash out?
TSpeja5081
post Dec 21 2018, 03:23 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(nasiayam @ Dec 21 2018, 03:16 PM)
iirc, most of those that kena the debit card fraud say they don't have paypal oso
*
Ofcoz.more easier people dont have paypal to be xploit.if you have paypal and link to your own paypal account you wont kena.
TSpeja5081
post Dec 21 2018, 03:24 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Kcee @ Dec 21 2018, 03:23 PM)
What has compromised debit cards have to do with changing Cimb clicks password?
*
Nothing.its just happen to be at same time people notice it.
TSpeja5081
post Dec 21 2018, 03:32 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(allanlee89 @ Dec 21 2018, 03:31 PM)
Here's mine, after noticed, quickly call Cimb CS, indeed got money transferred out from my account, have to go cimb branch fill up form to claim back the money, such nuisance...
[attachmentid=10142718]
*
3 dec?
TSpeja5081
post Apr 4 2020, 07:49 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
Apparently attack has begun

 

Change to:
| Lo-Fi Version
0.0489sec    1.13    7 queries    GZIP Disabled
Time is now: 16th December 2025 - 02:26 PM