Welcome Guest ( Log In | Register )

90 Pages « < 20 21 22 23 24 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
UnknownH
post Dec 17 2018, 03:55 AM

Enthusiast
******
Senior Member
1,437 posts

Joined: Mar 2009
From: ME TO YOU



QUOTE(Boy96 @ Dec 17 2018, 03:41 AM)
Great. Now suddenly my CIMB say need to reset password after I tried the password + 123456 trick..

Kenot even login already
*
Sounds like good thing. Imagine if it actually worked. Someone might already took advantage of that.
cant think of a username
post Dec 17 2018, 03:57 AM

Getting Started
**
Junior Member
72 posts

Joined: Apr 2015
20k celery wei

kek
killerjeya
post Dec 17 2018, 04:04 AM

Getting Started
**
Junior Member
80 posts

Joined: Jun 2011


QUOTE(juneong @ Dec 17 2018, 03:22 AM)
my password need 34 thousand year to crack, is that secure ?
*
That site knows your password now, all they need is your username. If only there was a site to check how secure your username is xD

eddie2020
post Dec 17 2018, 04:04 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
*
QUOTE(haimirmaya @ Dec 17 2018, 03:38 AM)
Pukimak fucking thru. Password + 12345678 is working.

I need to disable my clickaccount until this sort out!!!
*
Only through apps? If website working or not
eddie2020
post Dec 17 2018, 04:13 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



I use any character plus 12345678 is not working.. So I am safe?
KuzumiTaiga
post Dec 17 2018, 04:17 AM

Spends too much time with mechanical keyboards
*******
Senior Member
3,317 posts

Joined: Jun 2008
From: Cheras ~ London WC1E 7HU~ Shenzhen



i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
eddie2020
post Dec 17 2018, 04:23 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



QUOTE(KuzumiTaiga @ Dec 17 2018, 04:17 AM)
i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
*
What the issue actually? My acc is new and my password is not 8 characters... So I shouldn't be affected rite? But I see they said those recapcha is other story?
olman
post Dec 17 2018, 04:26 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


Other bank got this problem?
olman
post Dec 17 2018, 04:27 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


QUOTE(KuzumiTaiga @ Dec 17 2018, 04:17 AM)
i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
*
Ur wangs kena ccuri?
See transaksi rekod to where

This post has been edited by olman: Dec 17 2018, 04:28 AM
eddie2020
post Dec 17 2018, 04:35 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



Idk what is the problem after read so long.. How the hack take place? The recapcha ntg, I saw it and I didn't click or do anything.. I just use desktop go website n try simple password my acc still secure till I use my own password I only able login.. So I logged in will my password leak? Lol
lemon5969
post Dec 17 2018, 04:38 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



Lel try login with that exploit using webpage also could work just now..
EatFriesEggs
post Dec 17 2018, 04:43 AM

Getting Started
**
Junior Member
91 posts

Joined: Oct 2018
QUOTE(haimirmaya @ Dec 17 2018, 03:38 AM)
Pukimak fucking thru. Password + 12345678 is working.

I need to disable my clickaccount until this sort out!!!
*
But the hacker has to resolve the "Password" part of the equation first right?
sharpman
post Dec 17 2018, 04:44 AM

Veteran LYN Forumer
******
Senior Member
1,110 posts

Joined: Jan 2003



After i changed my password to complex password now I cannot login with the password trick anymore.

Still considering moving my money out of CIMB for now
DuitNow
post Dec 17 2018, 04:49 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
Can explain more on the above? blink.gif

QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
For me i noticed now transfer money also no need any tac for verification. Crazy. So if they masuk someone acc and no need tac verify... Thats it
*
Which bank can do that? blink.gif

QUOTE(hor @ Dec 17 2018, 02:14 AM)
My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only

*roll out*

4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
*
laugh.gif laugh.gif laugh.gif

QUOTE(teehk_tee @ Dec 17 2018, 02:22 AM)
Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this.

Not allow 8char + whatever shit to login.
*
Maybank actually do this a couple of months ago, I was force to change my password a couple of times. Probably kena... hmm.gif

QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
*
What! blink.gif Password : 12345678 can log into your accounts? doh.gif
leymahn
post Dec 17 2018, 04:50 AM

Getting Started
**
Junior Member
150 posts

Joined: Mar 2008


can someone uodate the first post regarding what to do with this case. wake up 4.30am and read all this shit up.
sharpman
post Dec 17 2018, 04:54 AM

Veteran LYN Forumer
******
Senior Member
1,110 posts

Joined: Jan 2003



QUOTE(leymahn @ Dec 17 2018, 04:50 AM)
can someone uodate the first post regarding what to do with this case. wake up 4.30am and read all this shit up.
*
TLDR: if your password is a simple password, change to complex password (UPPER CASE + lower case + NUMBER + special character) then your login is safe

leymahn
post Dec 17 2018, 04:55 AM

Getting Started
**
Junior Member
150 posts

Joined: Mar 2008


QUOTE(sharpman @ Dec 17 2018, 04:54 AM)
TLDR: if your password is a simple password, change to complex password (UPPER CASE + lower case + NUMBER + special character) then your login is safe
*
okay thanx
nxfx
post Dec 17 2018, 05:18 AM

Enthusiast
*****
Senior Member
979 posts

Joined: Jan 2003


from my what i understand.
CIMB put limit of 8 characters long password, but on their login page their password text box can input more than 8.
So when people key in their password + random characters, they still can login.
BUT technically correct cos the system only check the first 8 characters which is their password.
BUT logically is wrong cos anything you key in is not the same as your password EVEN with extra character is considered wrong.
eg,
apple123 is not the same as apple123456

imma rite????



facktura
post Dec 17 2018, 05:39 AM

Regular
******
Senior Member
1,566 posts

Joined: Jun 2013


wanna log in via browser but already ask to click captcha, sked to proceed.

so how now to change log in and change new password???
:3mushy:3
post Dec 17 2018, 05:42 AM

<--~(--+<[o]>+--)~-->
*******
Senior Member
4,723 posts

Joined: Apr 2008
QUOTE(red1982 @ Dec 17 2018, 02:46 AM)
For those who wants to know whether your password are secure .. test it here  https://howsecureismypassword.net/
*
It would take a computer about

93 TRILLION YEARS

Kek

90 Pages « < 20 21 22 23 24 > » Top
 

Change to:
| Lo-Fi Version
0.0166sec    0.44    6 queries    GZIP Disabled
Time is now: 13th December 2025 - 01:01 PM