Welcome Guest ( Log In | Register )

90 Pages « < 43 44 45 46 47 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
GPKGB
post Dec 17 2018, 01:19 PM

New Member
*
Newbie
14 posts

Joined: Aug 2010
QUOTE(Rhetoric @ Dec 17 2018, 01:17 PM)
if this is coding issue, what this got anthing to do with the CAPTCHA people talking about?.
*
Stop brute force
Duckies
post Dec 17 2018, 01:19 PM

Rubber Ducky
*******
Senior Member
9,804 posts

Joined: Jun 2008
From: Rubber Duck Pond


This is because when they changed the password policy to include special characters, they didn't force everyone to change their password.

Therefore they have to cater logic for old password logic and also new password logic.

But to implement it in this half ass way is plain stupid. This is not some wordpress blog yo. This is a fucking bank.

#programmingtalk
AyamBannedTwice
post Dec 17 2018, 01:19 PM

Getting Started
**
Junior Member
130 posts

Joined: Feb 2015


QUOTE(ZeneticX @ Dec 17 2018, 01:06 PM)
or cheap programmers from a certain country. dn wanna mention here if not later racing
*
Aku kerja dalam FI
Kalau aku bukak cerita ni memang bungkus la business
Semoga BNM bukak mata dan haramkan je terus
marma88
post Dec 17 2018, 01:20 PM

New Member
*
Newbie
14 posts

Joined: Feb 2008
From: melaka,malaysia


QUOTE(marma88 @ Dec 17 2018, 01:16 PM)
They keep on denying...wtf..  user posted image
*
Now can change password to Max 20 characters
Duckies
post Dec 17 2018, 01:20 PM

Rubber Ducky
*******
Senior Member
9,804 posts

Joined: Jun 2008
From: Rubber Duck Pond


Also, not sure if somebody mentioned before...using Google captcha...which genius thought of that way to do it? Limit the times of failed transaction or use phone secure SMS or TAC la adui.

This post has been edited by Duckies: Dec 17 2018, 01:20 PM
GPKGB
post Dec 17 2018, 01:20 PM

New Member
*
Newbie
14 posts

Joined: Aug 2010
QUOTE(lagista @ Dec 17 2018, 01:17 PM)
it means any password will do?

i prefer combination of jav code n actress + secret kangkang style name...aint nobody can crack it rite ??
*
Means no matter what u put , it will masuk with the first 8 character, instead of reject and jump out from the function
JohnLai
post Dec 17 2018, 01:20 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
QUOTE(marma88 @ Dec 17 2018, 01:16 PM)
They keep on denying...wtf..  user posted image
*
Must be learning from Najib.

"You are not being fair to me!!" whistling.gif
zul_sur
post Dec 17 2018, 01:21 PM

Getting Started
**
Junior Member
125 posts

Joined: Jan 2006


naise, untung dev dia, public is saying cimb got hacked, but the truth is code like monkey.
Duckies
post Dec 17 2018, 01:21 PM

Rubber Ducky
*******
Senior Member
9,804 posts

Joined: Jun 2008
From: Rubber Duck Pond


So head siapa yang akan roll on the ground? Sure somebody kena eat the dead cat and take the blame. Head of IT?
OldSchoolJoke
post Dec 17 2018, 01:22 PM

Getting Started
**
Junior Member
289 posts

Joined: Mar 2010
QUOTE(puchongite @ Dec 17 2018, 01:16 PM)
Not the same thing lar.

This is login password.

The backend has been doing 8 characters password all the time mah. Sending extra characters over to back end also useless.
*
once encrypted, it will be different alot.
even you plainly compare the password also different already
zul_sur
post Dec 17 2018, 01:22 PM

Getting Started
**
Junior Member
125 posts

Joined: Jan 2006


QUOTE(GPKGB @ Dec 17 2018, 01:20 PM)
Means no matter what u put , it will masuk with the first 8 character, instead of reject and jump out from the function
*
should rejek altogether, this logic aaa, wait, part of the password is correct, let him in la, no need to check others
linkinstreet
post Dec 17 2018, 01:22 PM

Red Bull Addict
Group Icon
Moderator
9,277 posts

Joined: Jan 2005
From: KL. Best place in Malaysia. Nuff said

QUOTE(Rhetoric @ Dec 17 2018, 01:17 PM)
if this is coding issue, what this got anthing to do with the CAPTCHA people talking about?.
*
Some people were using bots to bruteforce password, since CIMB has no failed login limits. The CAPTCHA was supposed to slow the bots down
Quantum Geist
post Dec 17 2018, 01:23 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(puchongite @ Dec 17 2018, 01:04 PM)
Not IT savvy. What's the problem with the code ?
*
those checks are supposed to be checked at server side, when kantoi client side it will give ideas to malicious people as to how the system in the back works.
linkinstreet
post Dec 17 2018, 01:23 PM

Red Bull Addict
Group Icon
Moderator
9,277 posts

Joined: Jan 2005
From: KL. Best place in Malaysia. Nuff said

QUOTE(Duckies @ Dec 17 2018, 01:21 PM)
So head siapa yang akan roll on the ground? Sure somebody kena eat the dead cat and take the blame. Head of IT?
*
Bukan ke their IT guy sudah lompat suicide?
metaloid
post Dec 17 2018, 01:24 PM

konpeko~
******
Senior Member
1,972 posts

Joined: Jan 2008
I hope they start introducing Fingerprint authorization like Maybank app.
Duckies
post Dec 17 2018, 01:25 PM

Rubber Ducky
*******
Senior Member
9,804 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(Mummy Shark @ Dec 17 2018, 01:23 PM)
sebab itu diorang gunakan kelemahan CIMB

DAN

paypal.

sebab paypal memang tak support TAC, 3D Secure, whatever.
asalkan boleh lepas card number DAN optional CVV paypal will keep on charging when requested.
*
So how did they managed to hack into user in the first place? Memang brute force password ke? Even though with that, they still need the USER ID.
incubus_skj
post Dec 17 2018, 01:25 PM

oh mai gotto
******
Senior Member
1,750 posts

Joined: Feb 2009


QUOTE(se7en @ Dec 17 2018, 12:36 PM)
guys, those of you who got charged on your debit card, reported to CIMB, and was refunded, did CIMB also issue you with a new card after the incident?
*
my mom punya kena last week, same case unauthorised Paypal transaction, then she went to the bank and they replaced her ATM debit card FOC.

This post has been edited by incubus_skj: Dec 17 2018, 01:25 PM
Duckies
post Dec 17 2018, 01:25 PM

Rubber Ducky
*******
Senior Member
9,804 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(linkinstreet @ Dec 17 2018, 01:23 PM)
Bukan ke their IT guy sudah lompat suicide?
*
Wa kesian, kena suicide to redeem himself/herself. Bukan as usual play the blame game ke?
lagista
post Dec 17 2018, 01:25 PM

New Member
*
Newbie
25 posts

Joined: Oct 2018


QUOTE(GPKGB @ Dec 17 2018, 01:20 PM)
Means no matter what u put , it will masuk with the first 8 character, instead of reject and jump out from the function
*
sounds really stupid n reckless system !!

wonder why with billions profits bank kenot hire proper IT people ??
JohnLai
post Dec 17 2018, 01:26 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
QUOTE(metaloid @ Dec 17 2018, 01:24 PM)
I hope they start introducing Fingerprint authorization like Maybank app.
*
But some people don't have fingerprint (no hand or leg), how leh? Discrimination for the disabled people!!!

90 Pages « < 43 44 45 46 47 > » Top
 

Change to:
| Lo-Fi Version
0.0279sec    0.55    6 queries    GZIP Disabled
Time is now: 20th December 2025 - 05:49 AM