Welcome Guest ( Log In | Register )

90 Pages « < 12 13 14 15 16 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
CAL V
post Dec 17 2018, 01:24 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


anak haram, really can simply login with wrong pw

briantwj
post Dec 17 2018, 01:25 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


The feck is their service manyzer doing mia. No ppl escalate to him kah
Snoe II
post Dec 17 2018, 01:25 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


QUOTE(Neo8663 @ Dec 17 2018, 01:16 AM)
ya, rhb better...long time no use cimb
*
Will start using RHB from now. The only thing is RHB app sucks big time 🤦🏻‍♂️🤦🏻‍♂️
Captain Coco
post Dec 17 2018, 01:26 AM

Getting Started
**
Junior Member
216 posts

Joined: Feb 2016
QUOTE(Omgf @ Dec 17 2018, 01:22 AM)
Login CIMB IOS app via touch ID, money still there.
*
TouchID is an easy login by recognizing your fingerprint and phone will assist to login using your username and password.. means yours are also compromised..
maxpudding
post Dec 17 2018, 01:26 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc

Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move
teehk_tee
post Dec 17 2018, 01:27 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(maxpudding @ Dec 17 2018, 01:26 AM)
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc

Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move
*
yes

back then it was limited to 8

now when u change u can put in 9, 10, 11, 12, 13 chars

defeck seriously
briantwj
post Dec 17 2018, 01:28 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Btw any other platform or Reddit reporting on this? Getting kinda boring here. Lol
ashburn98
post Dec 17 2018, 01:28 AM

Runaway train
******
Senior Member
1,570 posts

Joined: Nov 2005
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
Neo8663
post Dec 17 2018, 01:29 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(Snoe II @ Dec 17 2018, 01:25 AM)
Will start using RHB from now. The only thing is RHB app sucks big time 🤦🏻‍♂️🤦🏻‍♂️
*
but their website , i feels more user friendly
Zanei Gundan
post Dec 17 2018, 01:30 AM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
QUOTE(briantwj @ Dec 17 2018, 01:28 AM)
Btw any other platform or Reddit reporting on this? Getting kinda boring here. Lol
*
amanz
Higgsboson8888
post Dec 17 2018, 01:31 AM

Casual
***
Junior Member
362 posts

Joined: Jan 2015


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
Interested in knowing too
Muhammad Syukri
post Dec 17 2018, 01:31 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(Neo8663 @ Dec 17 2018, 01:29 AM)
but their website , i feels more user friendly
*
it feel early 2000's website
maxpudding
post Dec 17 2018, 01:31 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
Baca la

Short answer: nope, you are still farked

This post has been edited by maxpudding: Dec 17 2018, 01:31 AM
briantwj
post Dec 17 2018, 01:31 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
As long as u have a cimbclicks account, u are in danger.

Cimbclicks account meaning u have a password n ID to login to cimbclicks

This post has been edited by briantwj: Dec 17 2018, 01:32 AM
aku_ker
post Dec 17 2018, 01:32 AM

Casual
***
Junior Member
438 posts

Joined: Mar 2005



The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
jimmyktp
post Dec 17 2018, 01:32 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(thewan @ Dec 17 2018, 12:42 AM)
So much work. SMS can be redirected to another number. No need IC, no need Sim Card with target number. No need visit Police or telco, just sit at home. Just redirect all the bank sms to a hacker controlled number. Old vulnerability is old, please get educated dear Malaysians, and tell your banks, No more sms based authentication. Bank Negara should step in and fine or revoke licenses of banks that do not protect their customers money adequately.

Start here: https://arstechnica.com/information-technol...uting-protocol/ and then look up more on SS7 and SMS and how it all works. Then you will understand, no more SMS please.
*
Wow.

The method I explained was the modus operandi in 2004. Seems like the loophole is even easier now. Seriously, I started despising sms based authentication in 2015 when I arrived in UK to realise banks such as HSBC uses 2FA + Secureword. Just wow. Setting up initially is a pain and confusion, but once you done first time set up, everything is secured and easy. Consumers have to be smart. Say no to SMS authentication especially when it comes to banking..
NotYourKuda
post Dec 17 2018, 01:33 AM

Getting Started
**
Junior Member
137 posts

Joined: Sep 2016
From: Litar Kuda

IT dept will be fucked alive.
briantwj
post Dec 17 2018, 01:34 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
It’s an opening to many possibilities. Plus it coincides with the recent captcha introduction. 1+1.
hans86
post Dec 17 2018, 01:34 AM

New Member
*
Junior Member
31 posts

Joined: Oct 2006
From: Malaysia Ku Tercinta



I think cimb programmer use substr 8 then compare hash as first attempt and full str hash as 2nd attempt (after 8 char max removed).

Edit: Thats why they ask user to change password since the hash compare should be updated already.

This post has been edited by hans86: Dec 17 2018, 01:37 AM
Neo8663
post Dec 17 2018, 01:34 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
best way is transfer to other bank

90 Pages « < 12 13 14 15 16 > » Top
 

Change to:
| Lo-Fi Version
0.0169sec    0.45    6 queries    GZIP Disabled
Time is now: 15th December 2025 - 02:47 AM