anak haram, really can simply login with wrong pw
Chat CIMB kena hack?
Chat CIMB kena hack?
|
|
Dec 17 2018, 01:24 AM
|
![]() ![]()
Junior Member
277 posts Joined: Dec 2011 |
anak haram, really can simply login with wrong pw
|
|
|
|
|
|
Dec 17 2018, 01:25 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,968 posts Joined: Sep 2012 |
The feck is their service manyzer doing mia. No ppl escalate to him kah
|
|
|
Dec 17 2018, 01:25 AM
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,395 posts Joined: Feb 2012 From: Banting |
|
|
|
Dec 17 2018, 01:26 AM
Show posts by this member only | IPv6 | Post
#264
|
![]() ![]()
Junior Member
216 posts Joined: Feb 2016 |
|
|
|
Dec 17 2018, 01:26 AM
Show posts by this member only | IPv6 | Post
#265
|
![]() ![]()
Junior Member
164 posts Joined: Mar 2007 |
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc
Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move |
|
|
Dec 17 2018, 01:27 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
5,363 posts Joined: Apr 2005 From: กรุงเทพมหานคร BKK |
QUOTE(maxpudding @ Dec 17 2018, 01:26 AM) When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc yesThen, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move back then it was limited to 8 now when u change u can put in 9, 10, 11, 12, 13 chars defeck seriously |
|
|
|
|
|
Dec 17 2018, 01:28 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,968 posts Joined: Sep 2012 |
Btw any other platform or Reddit reporting on this? Getting kinda boring here. Lol
|
|
|
Dec 17 2018, 01:28 AM
Show posts by this member only | IPv6 | Post
#268
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,570 posts Joined: Nov 2005 |
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
|
|
|
Dec 17 2018, 01:29 AM
Show posts by this member only | IPv6 | Post
#269
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,244 posts Joined: Jul 2005 |
|
|
|
Dec 17 2018, 01:30 AM
|
![]() ![]()
Junior Member
143 posts Joined: Aug 2010 From: My Bloody Valentine |
|
|
|
Dec 17 2018, 01:31 AM
|
![]() ![]() ![]()
Junior Member
362 posts Joined: Jan 2015 |
|
|
|
Dec 17 2018, 01:31 AM
Show posts by this member only | IPv6 | Post
#272
|
![]() ![]() ![]() ![]() ![]()
Senior Member
821 posts Joined: Mar 2009 |
|
|
|
Dec 17 2018, 01:31 AM
Show posts by this member only | IPv6 | Post
#273
|
![]() ![]()
Junior Member
164 posts Joined: Mar 2007 |
|
|
|
|
|
|
Dec 17 2018, 01:31 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,968 posts Joined: Sep 2012 |
QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM) As long as u have a cimbclicks account, u are in danger. Cimbclicks account meaning u have a password n ID to login to cimbclicks This post has been edited by briantwj: Dec 17 2018, 01:32 AM |
|
|
Dec 17 2018, 01:32 AM
|
![]() ![]() ![]()
Junior Member
438 posts Joined: Mar 2005 |
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card. Anyway it's a security flaw and cimb should announce and take action. |
|
|
Dec 17 2018, 01:32 AM
Show posts by this member only | IPv6 | Post
#276
|
![]() ![]()
Junior Member
244 posts Joined: Jun 2006 From: the bolehland.. |
QUOTE(thewan @ Dec 17 2018, 12:42 AM) So much work. SMS can be redirected to another number. No need IC, no need Sim Card with target number. No need visit Police or telco, just sit at home. Just redirect all the bank sms to a hacker controlled number. Old vulnerability is old, please get educated dear Malaysians, and tell your banks, No more sms based authentication. Bank Negara should step in and fine or revoke licenses of banks that do not protect their customers money adequately. Wow. Start here: https://arstechnica.com/information-technol...uting-protocol/ and then look up more on SS7 and SMS and how it all works. Then you will understand, no more SMS please. The method I explained was the modus operandi in 2004. Seems like the loophole is even easier now. Seriously, I started despising sms based authentication in 2015 when I arrived in UK to realise banks such as HSBC uses 2FA + Secureword. Just wow. Setting up initially is a pain and confusion, but once you done first time set up, everything is secured and easy. Consumers have to be smart. Say no to SMS authentication especially when it comes to banking.. |
|
|
Dec 17 2018, 01:33 AM
Show posts by this member only | IPv6 | Post
#277
|
![]() ![]()
Junior Member
137 posts Joined: Sep 2016 From: Litar Kuda |
IT dept will be fucked alive.
|
|
|
Dec 17 2018, 01:34 AM
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
3,968 posts Joined: Sep 2012 |
QUOTE(aku_ker @ Dec 17 2018, 01:32 AM) The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account. It’s an opening to many possibilities. Plus it coincides with the recent captcha introduction. 1+1.For Maybank u know right you can withdraw money without ATM card. Anyway it's a security flaw and cimb should announce and take action. |
|
|
Dec 17 2018, 01:34 AM
|
![]()
Junior Member
31 posts Joined: Oct 2006 From: Malaysia Ku Tercinta |
I think cimb programmer use substr 8 then compare hash as first attempt and full str hash as 2nd attempt (after 8 char max removed).
Edit: Thats why they ask user to change password since the hash compare should be updated already. This post has been edited by hans86: Dec 17 2018, 01:37 AM |
|
|
Dec 17 2018, 01:34 AM
Show posts by this member only | IPv6 | Post
#280
|
![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
1,244 posts Joined: Jul 2005 |
|
| Change to: | 0.0169sec
0.45
6 queries
GZIP Disabled
Time is now: 15th December 2025 - 02:47 AM |