Welcome Guest ( Log In | Register )

90 Pages « < 48 49 50 51 52 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
fx_53_xt
post Dec 17 2018, 02:10 PM

Look at all my stars!!
*******
Senior Member
2,048 posts

Joined: Oct 2004


QUOTE(ZeneticX @ Dec 17 2018, 02:02 PM)
this method is similar to what Barclays use in the UK, a dedicated device for auth code

but nowadays starting to replace with phone app instead
*
CIMB Singapore is using this ...

creep
post Dec 17 2018, 02:13 PM

On my way
****
Junior Member
531 posts

Joined: Jan 2003
From: Cheras



QUOTE(AyamBannedTwice @ Dec 17 2018, 01:19 PM)
Aku kerja dalam FI
Kalau aku bukak cerita ni memang bungkus la business
Semoga BNM bukak mata dan haramkan je terus
*
MSS ke tu? brows.gif
lagista
post Dec 17 2018, 02:14 PM

New Member
*
Newbie
25 posts

Joined: Oct 2018


QUOTE(scorptim @ Dec 17 2018, 02:06 PM)
Actually all OCBC branches have pretty nice OL working in their customer facing roles. Puchong and subang OCBC also many hnnngh. The bank pandai to pick smexy amois for marketing purposes.
*
ok let's not lose focus on this tered main point: bank sotong icon_rolleyes.gif
zul_sur
post Dec 17 2018, 02:14 PM

Getting Started
**
Junior Member
125 posts

Joined: Jan 2006


QUOTE(Duckies @ Dec 17 2018, 01:51 PM)
But UAT website can show to public?

Bukan for internal only ke?
*
given their recent issue, this is normal
BenYeeHua
post Dec 17 2018, 02:15 PM

Regular
******
Senior Member
1,873 posts

Joined: Nov 2010


QUOTE(mrpotat @ Dec 17 2018, 02:08 PM)
i had one concern regarding cimb website. 2 weeks ago i forgot to pay my unifi bill, so my int connection had been cut off. I refreshed few pages and websites to confirm it. CIMB clicks however, thier site able to load properly and i even manage to log in to my account (i frequently checked my balance) - hence im really worried with how the cookies in cimb clicks is kept.

things that baffled me is tht the website able to load as usual (even with side rolling tab) and i had my correct secureword shown even i didnt connect to the internet (this was pre-capthca) I was able to see my balance, however i didnt perform any transaction since i guess this will definitely failed to load. but then yeah how the cookies of cimb click is stored really terrifying. imagine using public pc or public wifi to access your bank account haha gg
*
Nope, this case is on TM side, just like you connected to TM WiFi and all of them allowed to connect to their TM server to login, they also added exclusion to payment website (but on Streamyx/UniFi paywall) so you can make payment on UniFi website using your bank website(online payment). thumbsup.gif

As long as it is HTTPS and a valid cert, it should be safe.

But I guess it will stop working now, as they need to allow your device connect to Google server for obtain the reCAPTCHA for you, and there is huge of them out there. laugh.gif doh.gif
scorptim
post Dec 17 2018, 02:16 PM

Enthusiast
*****
Senior Member
700 posts

Joined: Nov 2009
QUOTE(buraqdunia @ Dec 17 2018, 02:07 PM)
where the appreciate tered bout them, create 1 la.  vmad.gif  devil.gif
*
Wah, takkan wan me like stalker go in pretend do transactions then snap their pics. 😅

QUOTE(unknown_2 @ Dec 17 2018, 02:08 PM)
i noticed they hav 1 amoi just to stand at the ticketing machine to press the button for u.
they will change shift & always only good looking amoi get that post.
*
Yup, you’re right memang always pretty amoi wearing smexy outfit doing this. Young one summore must be those fresh grads that just joined them

QUOTE(phillip88 @ Dec 17 2018, 02:09 PM)
Otot, JayaOne OCBC has the least crowd and you can always get a quick run!
*
Never went to JayaOne OCBC before but I bet their business model is the same. Pretty smexy amoi as front facing role.

zul_sur
post Dec 17 2018, 02:17 PM

Getting Started
**
Junior Member
125 posts

Joined: Jan 2006


QUOTE(scorptim @ Dec 17 2018, 01:59 PM)
India IT guys are only good at coding, not at logic.

You give them broad or vague instructions they gonna use the simplest shittiest code to get the job done coz they won’t bother to think “what else might be needed”.

If you have a good PM or account manager that can communicate to them exactly what specifications are needed, they can do it. Just don’t expect them to think or figure out anything for you.
Project manager mana? Tester only tests based on test scripts provided by the project team and 99% of the time test scripts from project team is BS.
CAPTCHA is one of the easiest “security measure” to bypass and this is a billion dollar bank we’re talking about.
*
project manager tgh kautim ngan manager, so 2x5 je. as long as can show to management meet dateline or got release then setel.
scorptim
post Dec 17 2018, 02:17 PM

Enthusiast
*****
Senior Member
700 posts

Joined: Nov 2009
QUOTE(lagista @ Dec 17 2018, 02:14 PM)
ok let's not lose focus on this tered main point: bank sotong  icon_rolleyes.gif
*
Sorry terpesong abit, smexy amois tend to be able to do that.

But yeah back to bank sotong with their sotong security measures.
Bonchi
post Dec 17 2018, 02:20 PM

KittehPowah
******
Senior Member
1,649 posts

Joined: Sep 2008
QUOTE(fx_53_xt @ Dec 17 2018, 02:10 PM)
CIMB Singapore is using this ...
*
All banks in SG uses a hardware security token... except Citi and Standard chartered that uses mobile app token if im not mistaken.
TSpeja5081
post Dec 17 2018, 02:21 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Mummy Shark @ Dec 17 2018, 02:18 PM)
Obviously they know it before..that why upgrading their system on 14dec
vamfire
post Dec 17 2018, 02:24 PM

Getting Started
**
Junior Member
171 posts

Joined: Feb 2005
From: North South East West


Dem, I sudah kena...

I received SMS on 12/12 that my CIMB Debit Card which I never used to make online purchases at all was charged RM34.48 @ Shopbop.com???

WTH! I straight away called CIMB to block my account immediately & then proceed to replaced the debit card as per CS advice...

But that amount still 'earmarked' last I checked my CIMB account balance

Is it a good time to go berserk & wire out all my moneh to other accounts maybe?
PleaseEnterYourName
post Dec 17 2018, 02:24 PM

Casual
***
Junior Member
386 posts

Joined: Jan 2006
From: between 0 and 1


cimb legacy system, only can handle 8 characters. So to create a front to able to use 20 characters this code was introduced.

But where seven found it?
Duckies
post Dec 17 2018, 02:26 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(PleaseEnterYourName @ Dec 17 2018, 02:24 PM)
cimb legacy system, only can handle 8 characters. So to create a front to able to use 20 characters this code was introduced.

But where seven found it?
*
Coded at the client side aka website there which by right should be at server side only.
C-Fu
post Dec 17 2018, 02:27 PM

Ninja-Fu
******
Senior Member
1,051 posts

Joined: Apr 2005
From: Brisbane, QLD, Ostolia



QUOTE(deodorant @ Dec 17 2018, 01:07 PM)
The comic makes the assumption that the hacker still tries to brute force via character / symbol though. What happens if this simple word password usage takes off, and the hacker switches to brute forcing via dictionary words?
*
then like in every scenario, you gotta trust the bank to secure every single hole. on your part, you can make it harder and longer for them to brute force.


either this, or use salted passwords. this is easier to type, easier to remember, easier to generate (via your brain), and lasts a long time. try retyping salted passwords.

case in point: remembering and retyping 12 words is a lot easier than retyping btc key.

This post has been edited by C-Fu: Dec 17 2018, 02:28 PM
CAL V
post Dec 17 2018, 02:29 PM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


kesian all the staff at counter and those on phone, sure kena bombarded kau kau
BillySteel
post Dec 17 2018, 02:29 PM

On my way
****
Senior Member
661 posts

Joined: Jul 2008
From: Yankee Territory


QUOTE(Mummy Shark @ Dec 17 2018, 02:32 PM)
honestly, nothing wrong with CAPTCHA on any screen.

the core behind CAPTCHA is to reduce automated entry by machine. it is not possible to eliminate altogether in probability, but the bar is higher than nothing at all. even if you only manage to eliminate 50% of automated attacks, that itself is a reduction.

look beyond the CAPTCHA and stop complaining about it being on any screen.

instead, question what the screen does to further eliminate threats not yet filtered by CAPTCHA.
*
Recaptcha v3 eliminates the need for ticking the box, actually, recaptcha is very important related to server request. It eliminates bots from brute forcing their way to obtain your password from rainbow tables (hash of known passwords --- currently there are about 1billion combinations from all the leaked passwords available publicly). There are other methods too but on the front end this is probably one of the most cost-efficient methods to deal with this.

I was pretty surprised when people were saying it was hacked, recaptcha has been a standard for years in more developed application development.


iammasivers
post Dec 17 2018, 02:30 PM

Casual
***
Junior Member
361 posts

Joined: Jul 2012


Just joined cimb last 2 weeks and this happen. fffuu
timo1003
post Dec 17 2018, 02:30 PM

Casual
***
Junior Member
364 posts

Joined: Mar 2016
Not sure if anyone has shared this in this thread, here's your response from CIMB biggrin.gif

CIMB denies its online banking system was hacked, assures all is secure
Malaysian bank CIMB denies security breach after customers say accounts compromised
techm
post Dec 17 2018, 02:31 PM

Getting Started
**
Junior Member
123 posts

Joined: Nov 2007
QUOTE(ntd.nicholas @ Dec 17 2018, 10:26 AM)
Change Password: Seems like even with the correct CIMB Clicks ID and password, it still shows
Invalid User ID or Password [CLK00619]

Update: Guys, to change password:

1. CIMB Clicks ID: <Your existing ID>
2. CIMB Clicks Password: <If your existing password length is > 8, then key in your password until the length of 8>

Example, old password is: mypasswod (length of 9 characters). In order to change password successfully, just key in mypasswo

This is ridiculous but its true.
*
Omg. CIMB really dropped the ball on this.
rooney723
post Dec 17 2018, 02:31 PM

On my way
****
Junior Member
596 posts

Joined: Dec 2010
QUOTE(PleaseEnterYourName @ Dec 17 2018, 02:24 PM)
cimb legacy system, only can handle 8 characters. So to create a front to able to use 20 characters this code was introduced.

But where seven found it?
*
but i checked the code the logic says it will accept the password if its more than 8 characters and if the password is less than 8 characters it will take the first 8 chars, or am i wrong?

90 Pages « < 48 49 50 51 52 > » Top
 

Change to:
| Lo-Fi Version
0.3676sec    0.38    6 queries    GZIP Disabled
Time is now: 13th December 2025 - 09:37 PM