Welcome Guest ( Log In | Register )

4 Pages  1 2 3 > » Bottom

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
TSpeja5081
post Dec 16 2018, 10:20 PM, updated 6y ago

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
Update from cimb
https://www.thestar.com.my/news/nation/2018...-all-is-secure/

Update from lowyat.com
https://www.lowyat.net/2018/175102/what-cim...you-but-should/


CIMB Clicks ‘kena hacked’ concern: Here are 4 things you need to know
Cimb Faq about recaptcha:
https://www.cimbclicks.com.my/pdf/201812-Cl...-Public-FAQ.pdf
QUOTE(HolySatan @ Dec 17 2018, 02:42 PM)
user posted image

user posted image

user posted image
*
Hack story
https://m.facebook.com/story.php?story_fbid...100000746122106

https://m.facebook.com/story.php?story_fbid...100000339018919

People lost money .someone hack and use to transfer through paypal


user posted image

user posted image

https://pokde.net/news/cimb-clicks-facing-m...security-flaws/
Update:cimb use recaptha to slow hacking process
Update from pokde. Basically u can login with wrong password
Update source:
https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/
Quote for the lol
QUOTE(se7en @ Dec 17 2018, 12:55 PM)
will just leave this here for now

user posted image
*
This post has been edited by peja5081: Dec 17 2018, 07:58 PM
se7en
post Dec 16 2018, 10:33 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

something is definitely wrong with the cimb clicks login page. we are investigating.
Zaryl
post Dec 16 2018, 10:34 PM

Hardcore Casual Gamer
******
Senior Member
1,709 posts

Joined: Jan 2003
From: Kedah Khap Khoun Khap (4K)



QUOTE(se7en @ Dec 16 2018, 10:33 PM)
something is definitely wrong with the cimb clicks login page. we are investigating.
*
Oh shit!

Pls do keep us updated se7en.

Thanks.
asparagsu
post Dec 16 2018, 10:35 PM

Getting Started
**
Junior Member
82 posts

Joined: Jan 2010


tried it, app no recaptcha image.. but i tried on chrome pc, and chrome ipong, got that recaptcha image.. changed my password, never login again
Zanei Gundan
post Dec 16 2018, 10:35 PM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
PSA: move out all of your $$$
powerbarr
post Dec 16 2018, 10:38 PM

New Member
*
Junior Member
49 posts

Joined: Jun 2016
QUOTE(asparagsu @ Dec 16 2018, 10:35 PM)
tried it, app no recaptcha image.. but i tried on chrome pc, and chrome ipong, got that recaptcha image.. changed my password, never login again
*
using safari on iphone. got recaptcha too
SUSwilsonjay
post Dec 16 2018, 10:39 PM

6 Stars Social Justice Warrior
******
Senior Member
1,605 posts

Joined: Feb 2006


the web site one captcha, damn wtf is cimb doing?
Zaryl
post Dec 16 2018, 10:39 PM

Hardcore Casual Gamer
******
Senior Member
1,709 posts

Joined: Jan 2003
From: Kedah Khap Khoun Khap (4K)



Is this only happens on android phones?

My iphone never got show this recaptcha thing.
feiraron
post Dec 16 2018, 10:39 PM

Getting Started
**
Junior Member
236 posts

Joined: Nov 2009


can confirm those recaptcha shows up on chrome desktop, didnt even proceed to put in user id
Supreme1394
post Dec 16 2018, 10:40 PM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


Oh shit,,I login via the app yesterday, it prompted the captcha "click all the images containing traffic lights". So I did, should I be worried? Bank account still same balance.
olman
post Dec 16 2018, 10:40 PM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


QUOTE(wilsonjay @ Dec 16 2018, 10:39 PM)
the web site one captcha, damn wtf is cimb doing?
*
Incomprehensible
Quantum Geist
post Dec 16 2018, 10:40 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


Looking at the page network traffic it's all going to either cimb server or google (for captcha most probably)

But I don't dare login with a real id
juzmafia
post Dec 16 2018, 10:41 PM

On my way
****
Junior Member
562 posts

Joined: Oct 2012
From: Out of the world...





This post has been edited by juzmafia: Dec 16 2018, 10:42 PM
powerbarr
post Dec 16 2018, 10:41 PM

New Member
*
Junior Member
49 posts

Joined: Jun 2016
QUOTE(Supreme1394 @ Dec 16 2018, 10:40 PM)
Oh shit,,I login via the app yesterday, it prompted the captcha "click all the images containing traffic lights". So I did, should I be worried? Bank account still same balance.
*
better change password or withdraw ur money just to be safe
Cookie101
post Dec 16 2018, 10:41 PM

Regular
******
Senior Member
1,616 posts

Joined: Jul 2016
Good fitnah attempt for unwanted purchase that cannot get refund.

Gonna use this reason as purchases haven’t arrive.

Ohwaiii
Artak
post Dec 16 2018, 10:43 PM

Getting Started
**
Junior Member
62 posts

Joined: May 2016


i justt checkked aaaatt tthe cimb wbsitet fater ii read tthiis threaad. yes, theres a recappcha tthing doown on bottom rightt.
SUSEdBaaBaa
post Dec 16 2018, 10:44 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
Tried on mobile site, has that recaptcha thingy
Supreme1394
post Dec 16 2018, 10:44 PM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(powerbarr @ Dec 16 2018, 10:41 PM)
better change password or withdraw ur money just to be safe
*
Crap, but how to change password? The captcha logo is still on cimbclicks website, later login change password also no use because website is still hacked. Tomolo I go withdraw all my balance then, thanks.
feiraron
post Dec 16 2018, 10:45 PM

Getting Started
**
Junior Member
236 posts

Joined: Nov 2009


OP dude the link you post got nothing to do with the capthcha thing, not even a mention there??

looks to me like their debit card is registered and linked with paypal and some sort of exploit there
Zanei Gundan
post Dec 16 2018, 10:46 PM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
can we get a quick rundown of what supposed to be done?

and how not to be targeted
Supreme1394
post Dec 16 2018, 10:46 PM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(feiraron @ Dec 16 2018, 10:45 PM)
OP dude the link you post got nothing to do with the capthcha thing, not even a mention there??

looks to me like their debit card is registered and linked with paypal and some sort of exploit there
*
Good point, TS pls explain.
MANUTD676767
post Dec 16 2018, 10:48 PM

Casual
***
Junior Member
347 posts

Joined: Jun 2017


So what is the problem with the captchcha thing?
Quantum Geist
post Dec 16 2018, 10:48 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(feiraron @ Dec 16 2018, 10:45 PM)
OP dude the link you post got nothing to do with the capthcha thing, not even a mention there??

looks to me like their debit card is registered and linked with paypal and some sort of exploit there
*
Then got card numbers leak?
howszat
post Dec 16 2018, 10:48 PM

Look at all my stars!!
*******
Senior Member
2,932 posts

Joined: Sep 2007
reCaptcha is already quite a common thing, lah.
TSpeja5081
post Dec 16 2018, 10:49 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(feiraron @ Dec 16 2018, 10:45 PM)
OP dude the link you post got nothing to do with the capthcha thing, not even a mention there??

looks to me like their debit card is registered and linked with paypal and some sort of exploit there
*
https://m.facebook.com/story.php?story_fbid...100000339018919
Original post..that one i post is feedback from other case.but similar
klaxoon.my
post Dec 16 2018, 10:49 PM

New Member
*
Newbie
31 posts

Joined: Aug 2017
user posted image
se7en
post Dec 16 2018, 10:50 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
GOPI56
post Dec 16 2018, 10:51 PM

Regular
******
Senior Member
1,494 posts

Joined: Dec 2012
QUOTE(peja5081 @ Dec 16 2018, 11:49 PM)
https://m.facebook.com/story.php?story_fbid...100000339018919
Original post..that one i post is feedback from other case.but similar
*
Recently a exploit involving Paypal payment gateway was shown in some videos.
Cookie101
post Dec 16 2018, 10:52 PM

Regular
******
Senior Member
1,616 posts

Joined: Jul 2016
QUOTE(Quantum Geist @ Dec 16 2018, 10:48 PM)
Then got card numbers leak?
*
Either their data is compromised by their own carelessness on website or data breach at seller side like the Starwood issue.

But many water fish just blame it on banks and make malicious fitnahs.

This shows the general public lack of common sense to determine the reliability of the information and knowledge of the basic issue.

#donedakwah
TSpeja5081
post Dec 16 2018, 10:52 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
Ok.maybe nothing to do we recaptcha.but many report unauthorized usage from paypal
ketaros
post Dec 16 2018, 10:52 PM

Getting Started
**
Junior Member
117 posts

Joined: Apr 2010
one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself
Quantum Geist
post Dec 16 2018, 10:53 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
plus the weird placement of recaptcha is kinda throwing people off
DarkAeon
post Dec 16 2018, 10:54 PM

Enthusiast
*****
Senior Member
774 posts

Joined: Nov 2010
QUOTE(ketaros @ Dec 16 2018, 10:52 PM)
one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself
*
really? someone is so fired
jimmyktp
post Dec 16 2018, 10:54 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
Yup. Also, CIMB limiting their password to only 8 characters, it's plain dumb.

Other countries already using 2FA for banking transaction, but Malaysian banks still use Mobile Number authentication. Just a ticking timebomb considering how easy it is to hijack a number..
Shanks
post Dec 16 2018, 10:56 PM

Getting Started
**
Junior Member
182 posts

Joined: Jan 2003
From: KL
Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit.
stupiak07
post Dec 16 2018, 10:57 PM

Casual
***
Junior Member
397 posts

Joined: Oct 2007
From: broken heart land, single forever~
QUOTE(Shanks @ Dec 16 2018, 10:56 PM)
Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit.
*
Number is legit but alot number spoofer using this number
ihavenoidea
post Dec 16 2018, 10:58 PM

Regular
******
Senior Member
1,300 posts

Joined: Sep 2012
the person must have had link his bank info to paypal and had his paypal info hacked or something. you dont need tac if you are paying using paypal
party
post Dec 16 2018, 10:58 PM

Enthusiast
*****
Senior Member
813 posts

Joined: May 2013


QUOTE(Cookie101 @ Dec 16 2018, 10:52 PM)
Either their data is compromised by their own carelessness on website or data breach at seller side like the Starwood issue.

But many water fish just blame it on banks and make malicious fitnahs.

This shows the general public lack of common sense to determine the reliability of the information and knowledge of the basic issue.

#donedakwah
*
But seems only C*** is always being affected? I dun see other banks kena that much.
feiraron
post Dec 16 2018, 10:59 PM

Getting Started
**
Junior Member
236 posts

Joined: Nov 2009


most likely leak card info

but how do they get around the registration of card into paypal is another story, as far as i know, paypal charge you with a code number in the description, and you can only get that code via your statement. after input the code only can link.

QUOTE(ketaros @ Dec 16 2018, 10:52 PM)
one more thing is for the app...if u put your password and any numbers or letters after it....you would still be able to login...i've tried myself
*
its not that you can input any text after your pass, most people didnt realize this but before this cimb only can input 8 character as password, really dumb but i think since this month only they allow for more characters as password. made me scratched my head a bit when it happen, last2 i just input first 8 character then walla. all this while i thought it was capturing my full password even during regeistration doh.gif

This post has been edited by feiraron: Dec 16 2018, 11:01 PM
jimmyktp
post Dec 16 2018, 10:59 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(Shanks @ Dec 16 2018, 10:56 PM)
Called the call centre. They say the recaptcha is a recent enhancement and that it's indeed the original CIMBClicks page. Also checked about the phone number +603 6204 7788 which they say is legit.
*
Instead of recaptcha, they should follow what UK banks doing. 2FA. But problem is that could be too complicated for users to set up the first time. Recaptcha is to identify bots. What about real humans? I don't think recaptcha is relevant for a banking website.

I'm using HSBC UK's 2FA. Really powerful. But is a pain to set up for the first time.

This post has been edited by jimmyktp: Dec 16 2018, 11:00 PM
Shanks
post Dec 16 2018, 10:59 PM

Getting Started
**
Junior Member
182 posts

Joined: Jan 2003
From: KL
QUOTE(stupiak07 @ Dec 16 2018, 10:57 PM)
Number is legit but alot number spoofer using this number
*
Yeah I know was worried when I heard about that. Quickly hung up the phone...
swks26
post Dec 16 2018, 10:59 PM

CEO RM20k/day
*****
Senior Member
942 posts

Joined: Jan 2007
QUOTE(jimmyktp @ Dec 16 2018, 10:54 PM)
Yup. Also, CIMB limiting their password to only 8 characters, it's plain dumb.

Other countries already using 2FA for banking transaction, but Malaysian banks still use Mobile Number authentication. Just a ticking timebomb considering how easy it is to hijack a number..
*
CIMB increased the character count above 8 recently. But yes, it was mind boggling that they capped it at 8 before.
MANUTD676767
post Dec 16 2018, 10:59 PM

Casual
***
Junior Member
347 posts

Joined: Jun 2017


QUOTE(ihavenoidea @ Dec 16 2018, 10:58 PM)
the person must have had link his bank info to paypal and had his paypal info hacked or something. you dont need tac if you are paying using paypal
*
Blame other people because of their own stupidity
ketaros
post Dec 16 2018, 11:00 PM

Getting Started
**
Junior Member
117 posts

Joined: Apr 2010
QUOTE(DarkAeon @ Dec 16 2018, 10:54 PM)
really? someone is so fired
*
Yup, my friend shared a post on FB...gotta try myself and it works. Immediately change password
Mr_47
post Dec 16 2018, 11:01 PM

***NOT MODERATOR *** Post : +10,000,000,00 Warn: 100%
*******
Senior Member
4,339 posts

Joined: Jan 2003
From: Bora-bora u jelly? Special: Age of multi-monitor



goddamn huh so real onot? seems real nation world wide
kueks
post Dec 16 2018, 11:03 PM

Playstation
*******
Senior Member
6,437 posts

Joined: Jan 2003
From: -Destiny Island- Status:Online

QUOTE(jimmyktp @ Dec 16 2018, 10:54 PM)
Yup. Also, CIMB limiting their password to only 8 characters, it's plain dumb.

Other countries already using 2FA for banking transaction, but Malaysian banks still use Mobile Number authentication. Just a ticking timebomb considering how easy it is to hijack a number..
*
ohmy.gif

how easy to hijack a number? that we should take precaution of
SUSEdBaaBaa
post Dec 16 2018, 11:03 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
I've just got off the line with cimb customer service who has told me that the recaptcha has been instituted by cimb.
jimmyktp
post Dec 16 2018, 11:04 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(swks26 @ Dec 16 2018, 10:59 PM)
CIMB increased the character count above 8 recently. But yes, it was mind boggling that they capped it at 8 before.
*
Thanks for the info! I got frustrated because of this. Gonna change my password now..
feiraron
post Dec 16 2018, 11:04 PM

Getting Started
**
Junior Member
236 posts

Joined: Nov 2009


QUOTE(MANUTD676767 @ Dec 16 2018, 10:59 PM)
Blame other people because of their own stupidity
*
ive read through the comments asking same question whether they had ever link before. they answer they had never used paypal
Dark_Knight90
post Dec 16 2018, 11:05 PM

Getting Started
**
Junior Member
77 posts

Joined: May 2014



QUOTE(jimmyktp @ Dec 16 2018, 10:59 PM)
Instead of recaptcha, they should follow what UK banks doing. 2FA. But problem is that could be too complicated for users to set up the first time. Recaptcha is to identify bots. What about real humans? I don't think recaptcha is relevant for a banking website.

I'm using HSBC UK's 2FA. Really powerful. But is a pain to set up for the first time.
*
Yeah agreed , all my emails and socials apps are safely secured with 2FA , its kinda annoying that the local banks dont take initiative for 2 Factor Authentication and Yubiki
MANUTD676767
post Dec 16 2018, 11:06 PM

Casual
***
Junior Member
347 posts

Joined: Jun 2017


QUOTE(feiraron @ Dec 16 2018, 11:04 PM)
ive read through the comments asking same question whether they had ever link before. they answer they had never used paypal
*
If that's the case better withdraw all money to be safe lol
sakuraboo
post Dec 16 2018, 11:08 PM

thereisnospoon
******
Senior Member
1,644 posts

Joined: Jan 2007
It's kinda stupid to initiate something without prior notification to the users

Gaya Malaysia
azbro
post Dec 16 2018, 11:11 PM

Look at all my stars!!
*******
Senior Member
4,403 posts

Joined: Jan 2007
From: Johor Bahru


Dun dare even open
jimmyktp
post Dec 16 2018, 11:12 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(kueks @ Dec 16 2018, 11:03 PM)
ohmy.gif

how easy to hijack a number? that we should take precaution of
*
It is super easy.

Coupled with installing Cerberus app on an unsuspecting phone, I can even read or send sms from my computer/phone

Note: Cerberus is a legitimate app but could be easily misused.



Let's take this as a scenario:

1. You went overseas for holiday bringing your phone with you. Someone knew you are not in the country.

2. Scammer goes to police station and make a report saying lost IC (pretending as you).

3. Using the police report, goes to make a temporary IC.

4. Using temp IC and police report, makes a report with telco to get them reissued a replacement sim card.

5. You realised your phone cannot use while you were in overseas. You didn't bother because you think you will sort it out when u come home.

6. Scammer can get banks to reissue a new CC, or if they already have your username and password, you GG because now any new sms from banks to you will be sent to the replacement sim card which is being held by the scammer.

7. See how powerful if someone gets your Phone Number?? A chain is only as strong as the weakest link. The phone number is the weakest link!

*Happened to my friend's dad* A big foreign bank in Malaysia who is famous with issuing CCs wanted to sue my friend's dad* The suit was thrown out eventually.

This post has been edited by jimmyktp: Dec 16 2018, 11:15 PM
jimmyktp
post Dec 16 2018, 11:14 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(Dark_Knight90 @ Dec 16 2018, 11:05 PM)
Yeah agreed  , all my  emails and socials apps are safely secured with 2FA , its kinda  annoying that the local banks dont take initiative for 2 Factor Authentication and Yubiki
*
Lack of resources, too expensive and not enough professional IT security experts could be the limiting factors.

Also, too high-end security features, Malaysians might not know how to appreciate. LOL.
emburrar
post Dec 16 2018, 11:20 PM

New Member
*
Newbie
14 posts

Joined: Oct 2014
From: Bandar Damai dan Indah


oh my duit
JohnLai
post Dec 16 2018, 11:21 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
Login without password as long as username is valid? doh.gif
Oh my.....what a screwup. bangwall.gif

Luckily my username might be a bit too long......cause last time cimb didn't allow long password,so I made my username longer.
PleaseEnterYourName
post Dec 16 2018, 11:23 PM

Casual
***
Junior Member
386 posts

Joined: Jan 2006
From: between 0 and 1


the app got cache features maybe.
DeniseLau
post Dec 16 2018, 11:24 PM

Casual
***
Junior Member
324 posts

Joined: Mar 2008
QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
It's this, not the normal reCaptcha
https://developers.google.com/recaptcha/docs/invisible
https://wptavern.com/google-launches-invisible-recaptcha

This post has been edited by DeniseLau: Dec 16 2018, 11:25 PM
Skylinestar
post Dec 16 2018, 11:24 PM

Mega Duck
********
All Stars
10,475 posts

Joined: Jan 2003
From: Sarawak
QUOTE(jimmyktp @ Dec 16 2018, 11:12 PM)
6. Scammer can get banks to reissue a new CC, or if they already have your username and password, you GG because now any new sms from banks to you will be sent to the replacement sim card which is being held by the scammer.

*Happened to my friend's dad* A big foreign bank in Malaysia who is famous with issuing CCs wanted to sue my friend's dad* The suit was thrown out eventually.
*
Bank so stupid no check thumbprint?
jimmyktp
post Dec 16 2018, 11:28 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(Skylinestar @ Dec 16 2018, 11:24 PM)
Bank so stupid no check thumbprint?
*
I'm not sure with this, perhaps there could be other ways to bypass this. Perhaps a replacement credit card sent straight to the home address? It is easy getting CC replaced without going to the bank.

Nowadays you don't need to go to banks to get things done.
azbro
post Dec 16 2018, 11:29 PM

Look at all my stars!!
*******
Senior Member
4,403 posts

Joined: Jan 2007
From: Johor Bahru


QUOTE(Supreme1394 @ Dec 16 2018, 10:40 PM)
Oh shit,,I login via the app yesterday, it prompted the captcha "click all the images containing traffic lights". So I did, should I be worried? Bank account still same balance.
*
I kena also..but it was due to wrong password which I swear is correct. Dem..now I dun dare open to check the balance.
jimmyktp
post Dec 16 2018, 11:30 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(swks26 @ Dec 16 2018, 10:59 PM)
CIMB increased the character count above 8 recently. But yes, it was mind boggling that they capped it at 8 before.
*
Now they force you to add in special character in their password. Lagi menyusahkan.

Really half pass six implementations. Instead of making life hard for 1 time, they make life hard everytime someone login!

Their app and website really lack user-friendliness. I remember I send in CC enquiry via their website compose message box, the stupid bank officer have the cheek to ask for a reply reason. Problem is, there isn't a reply button! KNS.. I had to compose a new message again.

This post has been edited by jimmyktp: Dec 16 2018, 11:34 PM
DeniseLau
post Dec 16 2018, 11:34 PM

Casual
***
Junior Member
324 posts

Joined: Mar 2008
QUOTE(jimmyktp @ Dec 16 2018, 11:12 PM)
It is super easy.

Coupled with installing Cerberus app on an unsuspecting phone, I can even read or send sms from my computer/phone

Note: Cerberus is a legitimate app but could be easily misused.
Let's take this as a scenario:

1. You went overseas for holiday bringing your phone with you. Someone knew you are not in the country.

2. Scammer goes to police station and make a report saying lost IC (pretending as you).

3. Using the police report, goes to make a temporary IC.

4. Using temp IC and police report, makes a report with telco to get them reissued a replacement sim card.

5. You realised your phone cannot use while you were in overseas. You didn't bother because you think you will sort it out when u come home.

6. Scammer can get banks to reissue a new CC, or if they already have your username and password, you GG because now any new sms from banks to you will be sent to the replacement sim card which is being held by the scammer.

7. See how powerful if someone gets your Phone Number?? A chain is only as strong as the weakest link. The phone number is the weakest link!

*Happened to my friend's dad* A big foreign bank in Malaysia who is famous with issuing CCs wanted to sue my friend's dad* The suit was thrown out eventually.
*
Omg shit... they dont check finger print when making a new IC ka?
PCMasterRace
post Dec 16 2018, 11:35 PM

Getting Started
**
Junior Member
53 posts

Joined: Sep 2013
this recaptcha shit is fucking stupid, can they not disable this on their site?
jimmyktp
post Dec 16 2018, 11:36 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(DeniseLau @ Dec 16 2018, 11:34 PM)
Omg shit... they dont check finger print when making a new IC ka?
*
That one I not sure, but it happened in 2005. Last time you need to hold your temporary paper IC for a month and wait for your MyKad. Now you can get it on the day itself.

But what I wanted to stress here is, Phone Number is not a secure method especially for banks.

This post has been edited by jimmyktp: Dec 16 2018, 11:37 PM
SUSEdBaaBaa
post Dec 16 2018, 11:37 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
QUOTE(jimmyktp @ Dec 16 2018, 11:28 PM)
I'm not sure with this, perhaps there could be other ways to bypass this. Perhaps a replacement credit card sent straight to the home address? It is easy getting CC replaced without going to the bank.

Nowadays you don't need to go to banks to get things done.
*
I wanted to collect my replacement card from a designated branch but was told the bank does not allow that anymore and it MUST be couriered to me.
briantwj
post Dec 16 2018, 11:37 PM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


so what's the fuss now, because they publish this captcha thing without prior notice to us? Or were they legitimately hacked, that's why added this captcha thing? Or they dont have answer why got this captcha thing appearing for some users?

zzzzz
hakim1994
post Dec 16 2018, 11:38 PM

Getting Started
**
Junior Member
183 posts

Joined: Nov 2011
From: belakang lu bro
So cimb stock turun?
BBBBBBBB UUUUUUUU
ahhann
post Dec 16 2018, 11:39 PM

Lim Peh
****
Senior Member
545 posts

Joined: Mar 2006
From: The Weirdo River O_o


Tried app login. Put in correct username and correct image and correct password. Immediately prompt alert ask me go to their website to change password. De fuck? I just successfully login last week.
jimmyktp
post Dec 16 2018, 11:39 PM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(EdBaaBaa @ Dec 16 2018, 11:37 PM)
I wanted to collect my replacement card from a designated branch but was told the bank does not allow that anymore and it MUST  be couriered to me.
*
If you not at home then GG lah.. If the postman/courier man hardworking, they will take it back. If not, they just drop into your house letterbox, even easier for the scammer to climb over your fence and collect the letter for u.. HAHA
JohnLai
post Dec 16 2018, 11:40 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
Aik? se7en keeps on changing the frontpage title.
alpha001
post Dec 16 2018, 11:42 PM

On my way
****
Senior Member
686 posts

Joined: Jun 2012
From: Egypt


so reCAPTCHA not an issue?
masamura
post Dec 16 2018, 11:42 PM

Casual
***
Junior Member
384 posts

Joined: Feb 2005
From: Bahamut's Lair


We got so many aunties and uncles that can't even comprehend on how to login properly. 2FA will just make them think they're living in a different planet. Although I really want 2FA also, I can understand how it feels for the bankers to actually teach uncles and aunties about how to setup and actually use it.
se7en
post Dec 16 2018, 11:43 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

QUOTE(JohnLai @ Dec 16 2018, 11:40 PM)
Aik? se7en keeps on changing the frontpage title.
*
sorry about that, the more we dig, the more shit we are getting. for now, all i can say is this is going to be VERY bad.
azbro
post Dec 16 2018, 11:43 PM

Look at all my stars!!
*******
Senior Member
4,403 posts

Joined: Jan 2007
From: Johor Bahru


Anyone can verify if I check balance using android CIMB apps with fingerprint will have issues or not?
se7en
post Dec 16 2018, 11:43 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

QUOTE(alpha001 @ Dec 16 2018, 11:42 PM)
so reCAPTCHA not an issue?
*
i can safely say now, they abruptly implemented the recaptcha, to avoid further damage.
Quantum Geist
post Dec 16 2018, 11:44 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(alpha001 @ Dec 16 2018, 11:42 PM)
so reCAPTCHA not an issue?
*
Most probably no, the captcha reports back to genuine google servers
shihnobie
post Dec 16 2018, 11:44 PM

New Member
*
Junior Member
34 posts

Joined: Jun 2006
i find it a bit odd that they introduce the recaptcha, at around the same time they introduce duitnow. i wonder if duitnow has caused some security issues.
JohnLai
post Dec 16 2018, 11:44 PM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
QUOTE(se7en @ Dec 16 2018, 11:43 PM)
sorry about that, the more we dig, the more shit we are getting. for now, all i can say is this is going to be VERY bad.
*
So.....I presume it is pointless for us to change cimb password right now? sweat.gif
Snoopycute98
post Dec 16 2018, 11:45 PM

Casual
***
Junior Member
407 posts

Joined: Oct 2016
Soon Lowyat.net expose this issue,
will forum lowyat.net kena media diu like last time tho
se7en
post Dec 16 2018, 11:46 PM

resistance is futile
Group Icon
Admin
1,806 posts

Joined: Jan 2003
From: Captain's Cabin, Black Pearl

QUOTE(JohnLai @ Dec 16 2018, 11:44 PM)
So.....I presume it is pointless for us to change cimb password right now? sweat.gif
*
wouldn't say its pointless, but you probably need to keep changing it till they fix it up.

My suggestion, use an online random password generator, to get a really complex password.
Quantum Geist
post Dec 16 2018, 11:48 PM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(ahhann @ Dec 16 2018, 11:39 PM)
Tried app login. Put in correct username and correct image and correct password. Immediately prompt alert ask me go to their website to change password. De fuck? I just successfully login last week.
*
Been getting the same past few weeks, called their rep and all I got was "you probably put in the wrong password" response. I checked my account and there was no out of the ordinary transactions, changed the password to something I never used before. cimb is not my main account so I didn't think too much about it.
xpole
post Dec 16 2018, 11:48 PM

Rain on me baby
******
Senior Member
1,410 posts

Joined: Dec 2009
From: Everywhere



That's why I dont use CIMB.
Always have so many issue.

My company use cimb bank, but every month gaji masuk, i straightly transfer to maybank or rhb
alien9
post Dec 16 2018, 11:50 PM

These stars mean nothing
*******
Senior Member
3,030 posts

Joined: Dec 2009
From: Jelatek / Wangsa Maju


QUOTE(se7en @ Dec 16 2018, 11:46 PM)
wouldn't say its pointless, but you probably need to keep changing it till they fix it up.

My suggestion, use an online random password generator, to get a really complex password.
*
long password is much harder to crack than a complex, but short password

SOS
kerolzarmyfanboy
post Dec 16 2018, 11:50 PM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
so better to transfer all my cimb moneh to other bank account for the time being..?

Duckies
post Dec 16 2018, 11:50 PM

Rubber Ducky
*******
Senior Member
9,795 posts

Joined: Jun 2008
From: Rubber Duck Pond


They should learn from Maybank. Maybank has the best mobile apps for now.

PBB is shit. CIMB is shit.
wufei
post Dec 16 2018, 11:51 PM

Look at all my stars!!
*******
Senior Member
3,039 posts

Joined: Jan 2003
From: Laputa


so after 5 page, apa conclusion ? safe or not safe?
hcmalaya
post Dec 16 2018, 11:51 PM

Getting Started
**
Junior Member
61 posts

Joined: Oct 2015
My iPhone safari browser also kena this captcha thing
Is it safe?
xpole
post Dec 16 2018, 11:52 PM

Rain on me baby
******
Senior Member
1,410 posts

Joined: Dec 2009
From: Everywhere



QUOTE(Duckies @ Dec 16 2018, 11:50 PM)
They should learn from Maybank. Maybank has the best mobile apps for now.

PBB is shit. CIMB is shit.
*
PBB online banking for dekstop version is not for human use one.

So shit
wufei
post Dec 16 2018, 11:52 PM

Look at all my stars!!
*******
Senior Member
3,039 posts

Joined: Jan 2003
From: Laputa


ok masuk lowyat.net headline

https://www.lowyat.net/2018/175051/cimb-cli...er-the-weekend/
ahhann
post Dec 16 2018, 11:54 PM

Lim Peh
****
Senior Member
545 posts

Joined: Mar 2006
From: The Weirdo River O_o


No shit!? What the fuck is this?
Attached Image
Happen when I tried to change my password
SUSEdBaaBaa
post Dec 16 2018, 11:54 PM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
QUOTE(jimmyktp @ Dec 16 2018, 11:39 PM)
If you not at home then GG lah.. If the postman/courier man hardworking, they will take it back. If not, they just drop into your house letterbox, even easier for the scammer to climb over your fence and collect the letter for u.. HAHA
*
Best part is the courier guy knows it's a credit card.

In theory the courier needs signed acknowledgement by recipient.

However recently I had an issue with the bank where they claimed I had signed acknowledgement of a redemption item although I've not received it. Only resolved when I told them I will file a police report for forgery against the courier n aiding & abetting a crime against the bank.



Duckies
post Dec 16 2018, 11:55 PM

Rubber Ducky
*******
Senior Member
9,795 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(xpole @ Dec 16 2018, 11:52 PM)
PBB online banking for dekstop version is not for human use one.

So shit
*
Ya man. PBB app lagi teruk. Maybank app and website is the best. CIMB website is second but their app is shit. PBB is the worst among all.
sepulse
post Dec 16 2018, 11:55 PM

Casual
***
Junior Member
434 posts

Joined: Dec 2008
just login and transfer ur money to other acc. i saw 2 fb friends post their card got unauthorized usage on paypal.
Mr. Najib Razak
post Dec 16 2018, 11:56 PM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
I tried Cimb mobile app android
No recaptcha
SUSEdBaaBaa
post Dec 17 2018, 12:00 AM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
QUOTE(se7en @ Dec 16 2018, 11:46 PM)

My suggestion, use an online random password generator, to get a really complex password.
*
Wonderful. It will be so complex that I won't be able to remember it.
audi90
post Dec 17 2018, 12:01 AM

Getting Started
**
Junior Member
96 posts

Joined: Nov 2012


Last month my CIMB account kena lock 4 times because someone did an unsuccessful login attempt.

I think CIMB security really mess up. Mcb

This post has been edited by audi90: Dec 17 2018, 12:02 AM
SUSEdBaaBaa
post Dec 17 2018, 12:04 AM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
QUOTE(DeniseLau @ Dec 16 2018, 11:24 PM)
QUOTE(Mr. Najib Razak @ Dec 16 2018, 11:56 PM)
I tried Cimb mobile app android
No recaptcha
*
See above, read 2nd link.
UserU
post Dec 17 2018, 12:04 AM

CSONLINE2.NET - FREE COUNTER-STRIKE
Group Icon
Elite
5,093 posts

Joined: Mar 2009
From: Land of make believe

Strange for a bank to use reCAPTCHA for logging in.
briantwj
post Dec 17 2018, 12:05 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Probably they notice weird IP hitting their front end. Even after blocking still weird IP appearing and the hits pattern are similar. Which is why they implement this captcha.

Just saying. icon_idea.gif
jimmyktp
post Dec 17 2018, 12:05 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(EdBaaBaa @ Dec 16 2018, 11:54 PM)
Best part is the courier guy knows it's a credit card.

In theory the courier needs signed acknowledgement by recipient.

However recently I had an issue with the bank where they claimed I had signed acknowledgement of a redemption item although I've not received it.  Only resolved when I told them I will file a police report for forgery against the courier n aiding &  abetting a crime against the bank.
*
if Bank come and chase you for a Rm70k debt, your mind already can't think straight. Coupled with the hassle of runaround, having to take leave off work, shit credit profile. All these just because of phone number authentication.
annoymous1234
post Dec 17 2018, 12:06 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

NO WONDER!!!!! MY MUM RECEIVED SMS SOMETHING ABOUT DEBIT CARD BEING BLOCK ONLINE!
pandera999
post Dec 17 2018, 12:07 AM

모든 것​에는 정해진 때​가 있으니
*******
Senior Member
6,214 posts

Joined: Sep 2010
From: Busan, Kr | Kuching, Swk



it is strange for bank use recaptcha... i tot someone report bout it couples of months ago bout the things appear? tot its a glitch.. but decide not clicking.
jimmyktp
post Dec 17 2018, 12:09 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(EdBaaBaa @ Dec 17 2018, 12:00 AM)
Wonderful.  It will be so complex that I won't be able to remember it.
*
Haha, more complex than MFA. It's already 2018. Gone are the days of complex passwords. Besides, the website doesn't support Google Password which makes your life even harder. online banking should make life easier, not harder
Neo8663
post Dec 17 2018, 12:09 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


RHB blocking user login now ?
kerolzarmyfanboy
post Dec 17 2018, 12:12 AM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
it's after 12am.. CIMB servers maintenance time rite? can't do transaction rite now?
teehk_tee
post Dec 17 2018, 12:12 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

is it a man-in-the-middle attack?
or

brute force?

This post has been edited by teehk_tee: Dec 17 2018, 12:15 AM
annoymous1234
post Dec 17 2018, 12:13 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

How to change password if cannot log in??
SUSEdBaaBaa
post Dec 17 2018, 12:13 AM

Getting Started
**
Junior Member
67 posts

Joined: Jan 2013
QUOTE(se7en @ Dec 16 2018, 11:43 PM)
sorry about that, the more we dig, the more shit we are getting. for now, all i can say is this is going to be VERY bad.
*
"Something strange is happening with CIMB Clicks, and judging by their rather abrupt implementation of a reCaptcha code on their login page today, there is reasons to be concerned."

jeez, even if it's a piece to be rushed out, surely basic grammar can be correctly used?

Yep, it must hv been an "abrupt implementation" because the customer service personnel don't seem to know when exactly it was started. The guy I spoke to gave me 3 different answers, changing each time I queried an answer.

First told me implemented 3 days, then 2 days ago then since yesterday??


This post has been edited by EdBaaBaa: Dec 17 2018, 12:18 AM
buraqdunia
post Dec 17 2018, 12:15 AM

On my way
****
Junior Member
617 posts

Joined: Jul 2006


QUOTE(Neo8663 @ Dec 17 2018, 12:09 AM)
RHB blocking user login now ?
*
maintenance.
Quantum Geist
post Dec 17 2018, 12:15 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(briantwj @ Dec 17 2018, 12:05 AM)
Probably they notice weird IP hitting their front end. Even after blocking still weird IP appearing and the hits pattern are similar. Which is why they implement this captcha.

Just saying. icon_idea.gif
*
So dictionary or bruteforce attack? They still have to bypass TAC or they got card numbers to transfer to paypal.

Looks like Se7en got something judging by the update


briantwj
post Dec 17 2018, 12:16 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(annoymous1234 @ Dec 17 2018, 12:13 AM)
How to change password if cannot log in??
*
Maintenance now. Their daily maintenance is at 12am til 12.20am iirc.
briantwj
post Dec 17 2018, 12:17 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(Quantum Geist @ Dec 17 2018, 12:15 AM)
So dictionary or bruteforce attack? They still have to bypass TAC or they got card numbers to transfer to paypal.

Looks like Se7en got something judging by the update
*
More like ddos maybe. Bruteforce trying to login via tons of username. That's the use case for using captcha.

Don't quote me for thisJust guessing. Someone might have got a copy of all the user login ID. Then wrote a script to keep trying to login with those user names.

This post has been edited by briantwj: Dec 17 2018, 12:18 AM
HolySatan
post Dec 17 2018, 12:17 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
ramai complaint..
hacked, paypal, recaptcha etc
macam biasa, cimb never wrong..
always blame customer..
Mr. Najib Razak
post Dec 17 2018, 12:22 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(EdBaaBaa @ Dec 17 2018, 12:04 AM)
See above,  read 2nd link.
*
i loggon to cimb clicks
got this recaptcha thingy
but in the mobile phone app for cimb
no this thingy
iamkid
post Dec 17 2018, 12:22 AM

On my way
****
Senior Member
677 posts

Joined: Jan 2009
From: Selayang/Kepong
omg
graphidz
post Dec 17 2018, 12:22 AM

F.A.T.E
******
Senior Member
1,411 posts

Joined: Jun 2009
From: land of burung kenyalang

Oh schiit I login today to do transaction and I believe I did saw this recapcha thing but ignored it
seanlam
post Dec 17 2018, 12:23 AM

Casual
***
Junior Member
489 posts

Joined: Jun 2009
North korea hackers? 😎
HolySatan
post Dec 17 2018, 12:23 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
https://amanz.my/2018188328/
https://www.lowyat.net/2018/175051/cimb-cli...er-the-weekend/

habislah CIMB..
Akmal47
post Dec 17 2018, 12:23 AM

Getting Started
**
Junior Member
84 posts

Joined: Sep 2009
From: Soviet Russia


Park for tomorrow. dont mind me
nxfx
post Dec 17 2018, 12:24 AM

Enthusiast
*****
Senior Member
979 posts

Joined: Jan 2003


mayb bots trying to brute force? thats why they add captcha ?
annoymous1234
post Dec 17 2018, 12:25 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

Is it safe to login now to change password?
Captain Coco
post Dec 17 2018, 12:26 AM

Getting Started
**
Junior Member
216 posts

Joined: Feb 2016
QUOTE(se7en @ Dec 16 2018, 10:33 PM)
something is definitely wrong with the cimb clicks login page. we are investigating.
*
QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
I dont see that in CMBClicks app on Android. Does it mean safe?
Quantum Geist
post Dec 17 2018, 12:26 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


Reading around, apparently http without the s (no ssl) on cimb sure works

Really roasted whoever is handling the network
kyogre
post Dec 17 2018, 12:28 AM

Getting Started
**
Junior Member
217 posts

Joined: Jan 2013
ah shiet, now not even safe to login issit?
well its maintenance now, i meant after the maintenance
feiraron
post Dec 17 2018, 12:28 AM

Getting Started
**
Junior Member
236 posts

Joined: Nov 2009


amanz better take the hint down, else someone will start poking around. lowyat words better, not publishing details
Legendary Big Boss
post Dec 17 2018, 12:29 AM

Getting Started
**
Junior Member
56 posts

Joined: Jun 2009
is the captcha safe to click?

briantwj
post Dec 17 2018, 12:29 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Removed

This post has been edited by briantwj: Dec 17 2018, 12:32 AM
Oblah
post Dec 17 2018, 12:31 AM

Getting Started
**
Junior Member
51 posts

Joined: Dec 2015


Lol Amanz straight up telling the Internet CIMB is currently a free-for-all.
persona93
post Dec 17 2018, 12:32 AM

Regular
******
Senior Member
1,180 posts

Joined: Oct 2010


QUOTE(Oblah @ Dec 17 2018, 12:31 AM)
Lol Amanz straight up telling the Internet CIMB is currently a free-for-all.
*
topkek
briantwj
post Dec 17 2018, 12:33 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(Oblah @ Dec 17 2018, 12:31 AM)
Lol Amanz straight up telling the Internet CIMB is currently a free-for-all.
*
They probably patched it. U can try it on ur own account. Mcm not working dy. Lul

This post has been edited by briantwj: Dec 17 2018, 12:33 AM
HolySatan
post Dec 17 2018, 12:33 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
user posted image

user posted image
ahhann
post Dec 17 2018, 12:33 AM

Lim Peh
****
Senior Member
545 posts

Joined: Mar 2006
From: The Weirdo River O_o


already have video circulating in WhatsApp with the exact attack method in play dee ...
briantwj
post Dec 17 2018, 12:34 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(ahhann @ Dec 17 2018, 12:33 AM)
already have video circulating in WhatsApp with the exact attack method in play dee ...
*
Pls share here bro
Jibbynomo
post Dec 17 2018, 12:34 AM

New Member
*
Newbie
4 posts

Joined: May 2018
So um.. Is it safe to login and change password now?

I have a PayPal acc linked to my account. Should i keep it linked or unlink it?? If it stays link would paypal block new account trying to link to my account? I dont get this
Supreme1394
post Dec 17 2018, 12:34 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(Oblah @ Dec 17 2018, 12:31 AM)
Lol Amanz straight up telling the Internet CIMB is currently a free-for-all.
*
Just tried, can't login with incorrect password
HolySatan
post Dec 17 2018, 12:35 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
QUOTE(ahhann @ Dec 17 2018, 12:33 AM)
already have video circulating in WhatsApp with the exact attack method in play dee ...
*
share notworthy.gif
JohnLai
post Dec 17 2018, 12:36 AM

Skeptical Cat
*******
Senior Member
3,669 posts

Joined: Apr 2006
QUOTE(se7en @ Dec 16 2018, 11:46 PM)
wouldn't say its pointless, but you probably need to keep changing it till they fix it up.

My suggestion, use an online random password generator, to get a really complex password.
*
My username is long and complex enough, unless if the attacker know my username....i doubt they can login...... brows.gif
maxera
post Dec 17 2018, 12:36 AM

Casual
***
Junior Member
382 posts

Joined: May 2011
From: Subang Jaya


QUOTE(Supreme1394 @ Dec 17 2018, 01:34 AM)
Just tried, can't login with incorrect password
*
Actually you need to enter your password and then enter any alphabets and numbers after your password. You can login as usual. That's fcked up.
annoymous1234
post Dec 17 2018, 12:37 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

so is it safe to login now to change password?
teehk_tee
post Dec 17 2018, 12:37 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(maxera @ Dec 17 2018, 12:36 AM)
Actually you need to enter your password and then enter any alphabets and numbers after your password. You can login as usual. That's fcked up.
*
WTF?

THATS FKED UP
Oblah
post Dec 17 2018, 12:37 AM

Getting Started
**
Junior Member
51 posts

Joined: Dec 2015


QUOTE(briantwj @ Dec 17 2018, 12:33 AM)
They probably patched it. U can try it on ur own account. Mcm not working dy. Lul
*
Would be very good if they did.
Amanz is being VERY irresponsible with their Twitter and page post.
Imagine the shitshow if the patch came much later.
victor_hoh
post Dec 17 2018, 12:37 AM

pump my muscles
******
Senior Member
1,191 posts

Joined: Nov 2004
From: Ipoh, now PJ


probably hashing problem. causing abnormally frequent collision.

This post has been edited by victor_hoh: Dec 17 2018, 12:38 AM
str4n93r
post Dec 17 2018, 12:37 AM

Getting Started
**
Junior Member
94 posts

Joined: Jul 2012
From: Batcave



My sis baru kena semalam. Demn
Krv23490
post Dec 17 2018, 12:38 AM

Look at all my stars!!
*******
Senior Member
2,175 posts

Joined: Mar 2016
QUOTE(ahhann @ Dec 17 2018, 12:33 AM)
already have video circulating in WhatsApp with the exact attack method in play dee ...
*
Share bro
Ee_
post Dec 17 2018, 12:38 AM

Mehh
*****
Senior Member
856 posts

Joined: Sep 2004
From: Aurora



QUOTE(maxera @ Dec 17 2018, 12:36 AM)
Actually you need to enter your password and then enter any alphabets and numbers after your password. You can login as usual. That's fcked up.
*
That means you still need to know the password, right? The captcha might help from brute force attack though. Damn, what's really going on
Neo8663
post Dec 17 2018, 12:39 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(buraqdunia @ Dec 17 2018, 12:15 AM)
maintenance.
*
ya, forgot they do maintenance night time doh.gif
stupiak07
post Dec 17 2018, 12:39 AM

Casual
***
Junior Member
397 posts

Joined: Oct 2007
From: broken heart land, single forever~
They should just shut the server down as it affected too many user.

This post has been edited by stupiak07: Dec 17 2018, 12:40 AM
ahhann
post Dec 17 2018, 12:40 AM

Lim Peh
****
Senior Member
545 posts

Joined: Mar 2006
From: The Weirdo River O_o


not going to share the video for the obvious reason. later all /k use that method to go attack pula hahahahhahah ~ wait la, i'm sure your whatsapp will ring later.

maxpudding
post Dec 17 2018, 12:40 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Jibbynomo @ Dec 17 2018, 12:34 AM)
So um.. Is it safe to login and change password now?

I have a PayPal acc linked to my account. Should i keep it linked or unlink it?? If it stays link would paypal block new account trying to link to my account? I dont get this
*
unlink first

can always link later
maxpudding
post Dec 17 2018, 12:41 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Neo8663 @ Dec 17 2018, 12:39 AM)
ya, forgot they do maintenance night time  doh.gif
*
can change now

cimb maintenance until 12.20
briantwj
post Dec 17 2018, 12:41 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Removed

This post has been edited by briantwj: Dec 17 2018, 12:43 AM
HolySatan
post Dec 17 2018, 12:41 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
user posted image

dah kantoi since morning
Mr. Najib Razak
post Dec 17 2018, 12:42 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(ahhann @ Dec 17 2018, 12:33 AM)
already have video circulating in WhatsApp with the exact attack method in play dee ...
*
mohon share
thewan
post Dec 17 2018, 12:42 AM

Getting Started
**
Junior Member
156 posts

Joined: Apr 2009
QUOTE(jimmyktp @ Dec 16 2018, 11:12 PM)
It is super easy.

Coupled with installing Cerberus app on an unsuspecting phone, I can even read or send sms from my computer/phone

Note: Cerberus is a legitimate app but could be easily misused.
Let's take this as a scenario:

1. You went overseas for holiday bringing your phone with you. Someone knew you are not in the country.

2. Scammer goes to police station and make a report saying lost IC (pretending as you).

3. Using the police report, goes to make a temporary IC.

4. Using temp IC and police report, makes a report with telco to get them reissued a replacement sim card.

5. You realised your phone cannot use while you were in overseas. You didn't bother because you think you will sort it out when u come home.

6. Scammer can get banks to reissue a new CC, or if they already have your username and password, you GG because now any new sms from banks to you will be sent to the replacement sim card which is being held by the scammer.

7. See how powerful if someone gets your Phone Number?? A chain is only as strong as the weakest link. The phone number is the weakest link!

*Happened to my friend's dad* A big foreign bank in Malaysia who is famous with issuing CCs wanted to sue my friend's dad* The suit was thrown out eventually.
*
So much work. SMS can be redirected to another number. No need IC, no need Sim Card with target number. No need visit Police or telco, just sit at home. Just redirect all the bank sms to a hacker controlled number. Old vulnerability is old, please get educated dear Malaysians, and tell your banks, No more sms based authentication. Bank Negara should step in and fine or revoke licenses of banks that do not protect their customers money adequately.

Start here: https://arstechnica.com/information-technol...uting-protocol/ and then look up more on SS7 and SMS and how it all works. Then you will understand, no more SMS please.

This post has been edited by thewan: Dec 17 2018, 12:43 AM
Sichiri
post Dec 17 2018, 12:42 AM

Regular
******
Senior Member
1,192 posts

Joined: Jan 2003
From: Kepong, Kuala Lumpur, Malaysia.


QUOTE(briantwj @ Dec 17 2018, 12:41 AM)
Just saw the video. And it is legit. So guys. Please keep ur username safe to urself.
*
Just username is enough to log in?
Jibbynomo
post Dec 17 2018, 12:43 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(maxpudding @ Dec 17 2018, 12:40 AM)
unlink first

can always link later
*
Wouldn't it be easier for abuser to link acc to PayPal then? Like dont PayPal allow bank account link to only one PP acc? Or am i wrong (u can link bank acc to numerous PP acc)?
Duckies
post Dec 17 2018, 12:43 AM

Rubber Ducky
*******
Senior Member
9,795 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
Just tested. This is so fucking legit man. Pls change ur password guys.
teehk_tee
post Dec 17 2018, 12:44 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

Fark.. This is legit..
fark im changing my pw now.
Seng89
post Dec 17 2018, 12:44 AM

Look at all my stars!!
*******
Senior Member
2,687 posts

Joined: Sep 2012
Park
incubus_skj
post Dec 17 2018, 12:44 AM

oh mai gotto
******
Senior Member
1,750 posts

Joined: Feb 2009


QUOTE(maxera @ Dec 17 2018, 12:36 AM)
Actually you need to enter your password and then enter any alphabets and numbers after your password. You can login as usual. That's fcked up.
*
Holy shit I just tried that and I could still log in WTFFFF
Mr. Najib Razak
post Dec 17 2018, 12:45 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(ahhann @ Dec 17 2018, 12:40 AM)
not going to share the video for the obvious reason. later all /k use that method to go attack pula hahahahhahah ~ wait la, i'm sure your whatsapp will ring later.
*
share to ayam
ayam holy moly no do this kind of stuff 1 tongue.gif
xeon1989
post Dec 17 2018, 12:45 AM

Member since 2008
*****
Junior Member
964 posts

Joined: Jun 2008
QUOTE(thewan @ Dec 17 2018, 12:42 AM)
So much work. SMS can be redirected to another number. No need IC, no need Sim Card with target number. No need visit Police or telco, just sit at home. Just redirect all the bank sms to a hacker controlled number. Old vulnerability is old, please get educated dear Malaysians, and tell your banks, No more sms based authentication. Bank Negara should step in and fine or revoke licenses of banks that do not protect their customers money adequately.

Start here: https://arstechnica.com/information-technol...uting-protocol/ and then look up more on SS7 and SMS and how it all works. Then you will understand, no more SMS please.
*
Finally there are someone who knows the business.
I already warn all institute that uses sms based TAC about how easy to reroute sms, yet it falls to deaf ear.
briantwj
post Dec 17 2018, 12:45 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(Sichiri @ Dec 17 2018, 12:42 AM)
Just username is enough to log in?
*
Nope. I can't talk too much bout it. But it's a big flaw.
Duckies
post Dec 17 2018, 12:46 AM

Rubber Ducky
*******
Senior Member
9,795 posts

Joined: Jun 2008
From: Rubber Duck Pond


Just change your password guys.

Your old password + any numbers or alphabets can go in weh.

But then hackers need to know your old password la else also no use cannot go in.

I just changed mine and now okay adi.
LaiN87
post Dec 17 2018, 12:46 AM

Nom nom nom...
******
Senior Member
1,320 posts

Joined: Jan 2003
From: メラカ /b/PowerLvl:Over9000!


QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
QUOTE(Duckies @ Dec 17 2018, 12:43 AM)
Just tested. This is so fucking legit man. Pls change ur password guys.
*
This is an issue but I don’t think this issue is what is important?

In order for the hacker to go into your account it still needs to get the first 8 char correctly.

Is this the video that is circulating in WhatsApp?
teehk_tee
post Dec 17 2018, 12:47 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(LaiN87 @ Dec 17 2018, 12:46 AM)
This is an issue but I don’t think this issue is what is important?

In order for the hacker to go into your account it still needs to get the first 8 char correctly.

Is this the video that is circulating in WhatsApp?
*
dude it's not important?

security is COMPROMISED man.

Duckies
post Dec 17 2018, 12:47 AM

Rubber Ducky
*******
Senior Member
9,795 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(LaiN87 @ Dec 17 2018, 12:46 AM)
This is an issue but I don’t think this issue is what is important?

In order for the hacker to go into your account it still needs to get the first 8 char correctly.

Is this the video that is circulating in WhatsApp?
*
Yea don't think it's a big concern since the hacker would need to know the first 8 characters correctly. But then it's still so fuckup to know it works as well with 8 characters + any random characters.
JustForCheonging
post Dec 17 2018, 12:47 AM

Getting Started
**
Junior Member
215 posts

Joined: May 2013


QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
Thanks for telling us that.
stupiak07
post Dec 17 2018, 12:48 AM

Casual
***
Junior Member
397 posts

Joined: Oct 2007
From: broken heart land, single forever~
But I recommend that you go call cimb and close you internet banking immediately
FatalExe
post Dec 17 2018, 12:48 AM

On my way
****
Senior Member
695 posts

Joined: Jan 2008


I'm closing my account tomorrow.
Jibbynomo
post Dec 17 2018, 12:49 AM

New Member
*
Newbie
4 posts

Joined: May 2018
Can u change pw in cimb app for ios?
Mr. Najib Razak
post Dec 17 2018, 12:49 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
should i change my passwords?
swks26
post Dec 17 2018, 12:49 AM

CEO RM20k/day
*****
Senior Member
942 posts

Joined: Jan 2007
QUOTE(jimmyktp @ Dec 16 2018, 11:30 PM)
Now they force you to add in special character in their password. Lagi menyusahkan.

Really half pass six implementations. Instead of making life hard for 1 time, they make life hard everytime someone login!

Their app and website really lack user-friendliness. I remember I send in CC enquiry via their website compose message box, the stupid bank officer have the cheek to ask for a reply reason. Problem is, there isn't a reply button! KNS.. I had to compose a new message again.
*
Eh? Special character? Mine didn't ask for that.
Quantum Geist
post Dec 17 2018, 12:49 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
How the heck cimb hash & store password sampai boleh buat macam tu
Oblah
post Dec 17 2018, 12:49 AM

Getting Started
**
Junior Member
51 posts

Joined: Dec 2015


QUOTE(Mr. Najib Razak @ Dec 17 2018, 12:49 AM)
should i change my passwords?
*
Better to be safe than sorry.
briantwj
post Dec 17 2018, 12:49 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Guys. Yes it is security compromise. But it's more of a flaw. Ppl will still need to know ur username and current password to login. So just refrain from sharing account.
Supreme1394
post Dec 17 2018, 12:49 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


Just changed my password using the online password generator that se7en posted.

This post has been edited by Supreme1394: Dec 17 2018, 12:51 AM
Sichiri
post Dec 17 2018, 12:49 AM

Regular
******
Senior Member
1,192 posts

Joined: Jan 2003
From: Kepong, Kuala Lumpur, Malaysia.


QUOTE(Mr. Najib Razak @ Dec 17 2018, 12:49 AM)
should i change my passwords?
*
No need since they're probably all frozen already. laugh.gif

This post has been edited by Sichiri: Dec 17 2018, 12:50 AM
teehk_tee
post Dec 17 2018, 12:50 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(Jibbynomo @ Dec 17 2018, 12:49 AM)
Can u change pw in cimb app for ios?
*
i tried, cant find the button on android

so i logged in on pc and changed it.
HolySatan
post Dec 17 2018, 12:50 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
RIP CIMB

user posted image
vanhoe0
post Dec 17 2018, 12:50 AM

New Member
*
Junior Member
39 posts

Joined: Dec 2011

JimbeamofNRT
post Dec 17 2018, 12:50 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
user posted image

I actually noticed this since early this week. suddenly got captcha verification. i was like ?!?!

then since many of my pwd got 12 characters and above I did overtyped several digits at the back and yup can login as well

knn... I think tomorrow cimb branch sure pack one!
maxpudding
post Dec 17 2018, 12:50 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(LaiN87 @ Dec 17 2018, 12:46 AM)
This is an issue but I don’t think this issue is what is important?

In order for the hacker to go into your account it still needs to get the first 8 char correctly.

Is this the video that is circulating in WhatsApp?
*
that's why they are bruteforcing your account

if they can get first 8 char correctly say bye bye to your account
ragu91
post Dec 17 2018, 12:51 AM

Casual
***
Junior Member
336 posts

Joined: Jan 2009
From: behind you


QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
fucuk, just tested. legit.

Changed password right away.
yw46
post Dec 17 2018, 12:51 AM

Casual
***
Junior Member
400 posts

Joined: Nov 2008
QUOTE(Duckies @ Dec 17 2018, 12:47 AM)
Yea don't think it's a big concern since the hacker would need to know the first 8 characters correctly. But then it's still so fuckup to know it works as well with 8 characters + any random characters.
*
Should be the hashing part.

Brute force attack is significantly easier now since 1000000x easier to get the password to login, hence the recaptcha.


briantwj
post Dec 17 2018, 12:53 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(maxpudding @ Dec 17 2018, 12:50 AM)
that's why they are bruteforcing your account

if they can get first 8 char correctly say bye bye to your account
*
This. Ppl can just bruteforce ur password now. As long as it hits the first 8 or the number or char u use on ur password. Then gg.

So.... No point changing password now. Lol. The change need to come from CIMB.

This post has been edited by briantwj: Dec 17 2018, 12:54 AM
Krv23490
post Dec 17 2018, 12:55 AM

Look at all my stars!!
*******
Senior Member
2,175 posts

Joined: Mar 2016
QUOTE(maxpudding @ Dec 17 2018, 12:50 AM)
that's why they are bruteforcing your account

if they can get first 8 char correctly say bye bye to your account
*
Okay sorry for my noob question . If they need to brute force it, can't they do it without the last 1234 at the back of your correct password ?
sixshot
post Dec 17 2018, 12:55 AM

Casual
***
Junior Member
464 posts

Joined: Apr 2010
From: Des Plaines


they already disable money transfer. cant even transfer money for now
teehk_tee
post Dec 17 2018, 12:55 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(briantwj @ Dec 17 2018, 12:53 AM)
This. Ppl can just bruteforce ur password now. As long as it hits the first 8 or the number or char u use on ur password. Then gg.

So.... No point changing password now. Lol. The change need to come from CIMB.
*
i think just make it longer and harder for it to bruteforce.

if 10digits hexadecimal it will be significantly harder. just dont put like simple strings.
pufferfish
post Dec 17 2018, 12:55 AM

Casual
***
Junior Member
439 posts

Joined: Oct 2005


obviously when submitted the password it just take the first 8 characters,hence the rest of the characters dont really matter,this is known from a while ago
Quantum Geist
post Dec 17 2018, 12:55 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(briantwj @ Dec 17 2018, 12:53 AM)
This. Ppl can just bruteforce ur password now. As long as it hits the first 8 or the number or char u use on ur password. Then gg.

So.... No point changing password now. Lol. The change need to come from CIMB.
*
Nothing short of freezing online transaction can help
Jibbynomo
post Dec 17 2018, 12:56 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(teehk_tee @ Dec 17 2018, 12:50 AM)
i tried, cant find the button on android

so i logged in on pc and changed it.
*
Mobile web cimb can ah?? Coz no laptop/pc wit me now.. 😭😭
kerolzarmyfanboy
post Dec 17 2018, 12:56 AM

On my way
****
Junior Member
575 posts

Joined: Feb 2013
QUOTE(sixshot @ Dec 17 2018, 12:55 AM)
they already disable money transfer. cant even transfer money for now
*
no la

i just successfully transferred my remaining cimb money to my bank islam acc just now
maxpudding
post Dec 17 2018, 12:56 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Krv23490 @ Dec 17 2018, 12:55 AM)
Okay sorry for my noob question . If they need to brute force it, can't they do it without the last 1234 at the back of your correct password ?
*
you need to understand how a bruteforce works


KcX35
post Dec 17 2018, 12:57 AM

ㄨㄨ
*******
Senior Member
2,364 posts

Joined: Aug 2011
From: Between Heaven & Hell


just transfer all my $$ to maybank lol
briantwj
post Dec 17 2018, 12:57 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Hey Se7en. Is it still safe for this thread to go on? Lol. The digging has gone too far.
Mr. Najib Razak
post Dec 17 2018, 12:59 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(Sichiri @ Dec 17 2018, 12:49 AM)
No need since they're probably all frozen already.  laugh.gif
*
eh dun liddat la dry.gif
babybaby1988
post Dec 17 2018, 12:59 AM

Getting Started
**
Junior Member
262 posts

Joined: Feb 2011
From: bolehLAND! <3


i cant change pass, it says

Invalid User ID or Password [CLK00619]

I tried 3 times logged out and logged in also same
ExHellSing
post Dec 17 2018, 01:00 AM

Getting Started
**
Junior Member
56 posts

Joined: Apr 2007
From: KL


QUOTE(babybaby1988 @ Dec 17 2018, 12:59 AM)
i cant change pass, it says

Invalid User ID or Password [CLK00619]

I tried 3 times logged out and logged in also same
*
Having same problem. Maybe bank side freeze the operation.
Snoe II
post Dec 17 2018, 01:00 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


Gg CIMB. Just transfer all money to RHB
maxpudding
post Dec 17 2018, 01:01 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
a lot of people transferred their monies out from cimb methinks

habislah saham cimb besok lulz
annoymous1234
post Dec 17 2018, 01:01 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

just changed my password.
Quantum Geist
post Dec 17 2018, 01:02 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


So if kena what else can you do besides calling cimb and PayPal? Can report to bnm and claim some sort of damages from cimb?
mambangafro
post Dec 17 2018, 01:02 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


i managed to change. my password moments ago
HolySatan
post Dec 17 2018, 01:02 AM

Regular
******
Senior Member
1,116 posts

Joined: Dec 2009
sotong got many tentacles, tapi useless
teehk_tee
post Dec 17 2018, 01:03 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

tried transferring money

Status:
Your transaction has been put on hold for further validation due to security reasons. Please check the status in "My Accounts > My Account Details" after 24 hours.

edit: approved.

fk this bank, im moving all my money out at the branch tmrw.

This post has been edited by teehk_tee: Dec 17 2018, 01:05 AM
Legendary Big Boss
post Dec 17 2018, 01:03 AM

Getting Started
**
Junior Member
56 posts

Joined: Jun 2009
cukur transfer all my duit kahwin to other account
yw46
post Dec 17 2018, 01:03 AM

Casual
***
Junior Member
400 posts

Joined: Nov 2008
Stupid bank without damage control so far and still avoiding reality in 21st century, hahaha
Jibbynomo
post Dec 17 2018, 01:04 AM

New Member
*
Newbie
4 posts

Joined: May 2018
user posted image

Does this work? Beside calling cimb 24/7 and wait like a fool for them to talk to u and verify ur identity all just to say block online transaction
djhenry91
post Dec 17 2018, 01:06 AM

Slow and Steady
*******
Senior Member
6,779 posts

Joined: Jan 2009
From: SEGI Heaven


no wonder la..
i go change pass..it wont..
thn i realise..the existing pass is max 8.. but wont key extra few word..
now u can key more thn 8..

LaiN87
post Dec 17 2018, 01:06 AM

Nom nom nom...
******
Senior Member
1,320 posts

Joined: Jan 2003
From: メラカ /b/PowerLvl:Over9000!


Shit... I know what’s happening.
Banks do not have that much cash in liquid.

If everyone transfers out their cash to other banks, especially a viral flaw thing like this. Bank will have severe issue.

So let’s hope BNM honour PDIM if it comes to that.
Jibbynomo
post Dec 17 2018, 01:06 AM

New Member
*
Newbie
4 posts

Joined: May 2018
Also, what's the best security bank malaysia have with 2FA and no problems using it online


I tahan wit cimb for 10 years now, every 1-2 years always got problem blocking my transaction for no reason (playstation, netflix, Spotify, apple).. Now this.. Mahai
teehk_tee
post Dec 17 2018, 01:07 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(Jibbynomo @ Dec 17 2018, 01:06 AM)
Also, what's the best security bank malaysia have with 2FA and no problems using it online
I tahan wit cimb for 10 years now, every 1-2 years always got problem blocking my transaction for no reason (playstation, netflix, Spotify, apple).. Now this.. Mahai
*
the foreign banks (HSBC, CITI) all have 2FA. heck.. it is 2FA + securepin (only u will know)
timo1003
post Dec 17 2018, 01:07 AM

Casual
***
Junior Member
364 posts

Joined: Mar 2016
Couldn't happen to a shitty bank after their 'stealth' interest raise move (like ah long)..
maxpudding
post Dec 17 2018, 01:08 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Jibbynomo @ Dec 17 2018, 01:06 AM)
Also, what's the best security bank malaysia have with 2FA and no problems using it online
I tahan wit cimb for 10 years now, every 1-2 years always got problem blocking my transaction for no reason (playstation, netflix, Spotify, apple).. Now this.. Mahai
*
So far, for me, maybank

Citibank for cc
Mr. Najib Razak
post Dec 17 2018, 01:08 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(sixshot @ Dec 17 2018, 12:55 AM)
they already disable money transfer. cant even transfer money for now
*
i just transferred money out to maybank
all good
veron4best
post Dec 17 2018, 01:09 AM

Regular
******
Senior Member
1,146 posts

Joined: Sep 2005
From: Kuala Lumpur


does it affect cimb app?
Supreme1394
post Dec 17 2018, 01:10 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(Jibbynomo @ Dec 17 2018, 01:04 AM)
user posted image

Does this work? Beside calling cimb 24/7 and wait like a fool for them to talk to u and verify ur identity all just to say block online transaction
*
Overseas Spends & Withdrawals already deactivated automatically by cimb. Must be some serious shit going on.
maxpudding
post Dec 17 2018, 01:11 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(veron4best @ Dec 17 2018, 01:09 AM)
does it affect cimb app?
*
This is affecting your bank ACCOUNT, regardless of platforms
briantwj
post Dec 17 2018, 01:11 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(Mr. Najib Razak @ Dec 17 2018, 01:08 AM)
i just transferred money out to maybank
all good
*
Account x freeze ke Mr Bijan
Seng89
post Dec 17 2018, 01:12 AM

Look at all my stars!!
*******
Senior Member
2,687 posts

Joined: Sep 2012
So cimb did announce anything yet ? 🤔
CAL V
post Dec 17 2018, 01:13 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


what about cimb cc, damn don't dare to login
mambangafro
post Dec 17 2018, 01:13 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


sesape cann withdraw from ATM x?
aku nak isi minyak esok nie...x de duit cash skang
Supreme1394
post Dec 17 2018, 01:14 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(CAL V @ Dec 17 2018, 01:13 AM)
what about cimb cc, damn don't dare to login
*
Login now and change your password.
SUSLumiaaa
post Dec 17 2018, 01:14 AM

Getting Started
**
Junior Member
172 posts

Joined: Sep 2014
From: LYN
Probably IT department all action stations chaos in HQ Liao

Lock downnnnn
aspartame
post Dec 17 2018, 01:14 AM

Look at all my stars!!
*******
Senior Member
3,165 posts

Joined: Feb 2015
QUOTE(teehk_tee @ Dec 17 2018, 01:07 AM)
the foreign banks (HSBC, CITI) all have 2FA. heck.. it is 2FA + securepin (only u will know)
*
Locals banks also have what...using TAC..or securepay.....
teehk_tee
post Dec 17 2018, 01:14 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(CAL V @ Dec 17 2018, 01:13 AM)
what about cimb cc, damn don't dare to login
*
the issue is not website spoofing. just double check it is https and the website is as usual link.
just log in, and change yr pw asap.
seanlam
post Dec 17 2018, 01:15 AM

Casual
***
Junior Member
489 posts

Joined: Jun 2009
QUOTE(Supreme1394 @ Dec 17 2018, 01:10 AM)
Overseas Spends & Withdrawals already deactivated automatically by cimb. Must be some serious shit going on.
*
If one happen to be travelling and found out his cc is just a useless plastic card, while cash in hand running low......
ze2
post Dec 17 2018, 01:16 AM

Casual
***
Junior Member
318 posts

Joined: Nov 2011
Few months back they kena bots attacked as I got trouble transferring money from using the app or cimb clicks.

No choice went to the bank and did a manual transfer and email them to complain. They didn't even know what's going on and dare asked me to clear cache etc. Until I told them to check properly they reverted the site is under attacked.

Now I just went into the site and there is this extra icon demanding extra pics vilidation?

ahhann
post Dec 17 2018, 01:16 AM

Lim Peh
****
Senior Member
545 posts

Joined: Mar 2006
From: The Weirdo River O_o


QUOTE(aspartame @ Dec 17 2018, 01:14 AM)
Locals banks also have what...using TAC..or securepay.....
*
i think he refer to login method instead, not transaction.
Neo8663
post Dec 17 2018, 01:16 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(Snoe II @ Dec 17 2018, 01:00 AM)
Gg CIMB. Just transfer all money to RHB
*
ya, rhb better...long time no use cimb
cajun2de
post Dec 17 2018, 01:16 AM

de Reaper
*******
Senior Member
2,791 posts

Joined: Sep 2005
From: Ipoh/Melaka


Maybe there is some unnecessary panic.
I logged via PC, no captcha. Changed my password and logged off.


Jigoku
post Dec 17 2018, 01:17 AM

Getting Started
**
Junior Member
288 posts

Joined: Jan 2010

babi now i need to do it
Omgf
post Dec 17 2018, 01:17 AM

Casual
***
Junior Member
392 posts

Joined: Jul 2009


Damn it, feel scared to login now damn
teehk_tee
post Dec 17 2018, 01:17 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(aspartame @ Dec 17 2018, 01:14 AM)
Locals banks also have what...using TAC..or securepay.....
*
cimb and mbb

login guna pw je
then TAC for transaction.
annoymous1234
post Dec 17 2018, 01:17 AM

Look at all my stars!!
*******
Senior Member
7,616 posts

Joined: Mar 2009

tomorrow sure masuk news. just like that massive data breach
maxpudding
post Dec 17 2018, 01:17 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Omgf @ Dec 17 2018, 01:17 AM)
Damn it, feel scared to login now damn
*
You login or dont, your account is still vulnerable
incubus_skj
post Dec 17 2018, 01:18 AM

oh mai gotto
******
Senior Member
1,750 posts

Joined: Feb 2009


QUOTE(Omgf @ Dec 17 2018, 01:17 AM)
Damn it, feel scared to login now damn
*
You log no log also same la if kena targeted
audi90
post Dec 17 2018, 01:18 AM

Getting Started
**
Junior Member
96 posts

Joined: Nov 2012


QUOTE(Mr. Najib Razak @ Dec 17 2018, 01:08 AM)
i just transferred money out to maybank
all good
*
Kek i loled hard at your username and the comment
max291
post Dec 17 2018, 01:18 AM

New Member
*
Junior Member
34 posts

Joined: Oct 2008
QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
It have always been like this ever since they introduce it many years ago. Only first 8 characters are counted. The rest are jumbled out to confuse any keylogger.
Jigoku
post Dec 17 2018, 01:18 AM

Getting Started
**
Junior Member
288 posts

Joined: Jan 2010

die now cannot transfer money then how if money gone?

CIMB gonna reimburse or what

I got money there use cimb to pay bill
Krv23490
post Dec 17 2018, 01:18 AM

Look at all my stars!!
*******
Senior Member
2,175 posts

Joined: Mar 2016
CIMB SG have to use TAC or security device to login


adamhzm90
post Dec 17 2018, 01:19 AM

Regular
******
Senior Member
1,389 posts

Joined: Apr 2014


Damn, i also can log in using fake password.

And can transfer money too. Wtf cimb?
buraqdunia
post Dec 17 2018, 01:19 AM

On my way
****
Junior Member
617 posts

Joined: Jul 2006


so any1 whose transfer out, the amount alrdy reflect in new acc and can cash out? just to make sure that is just a number on the screen.
Jigoku
post Dec 17 2018, 01:20 AM

Getting Started
**
Junior Member
288 posts

Joined: Jan 2010

QUOTE(adamhzm90 @ Dec 17 2018, 01:19 AM)
Damn, i also can log in using fake password.

And can transfer money too. Wtf cimb?
*
You can transfer money?
mambangafro
post Dec 17 2018, 01:21 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


geng...leh kuar duit dari atm tak?

jangan weiii aku x de cash nak isi minyak esok
maxpudding
post Dec 17 2018, 01:21 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(max291 @ Dec 17 2018, 01:18 AM)
It have always been like this ever since they introduce it many years ago. Only first 8 characters are counted. The rest are jumbled out to confuse any keylogger.
*
Previously I remembered my password was set to 8 chars, but i terclick lebih, cant go in

Now, with that method, you can login
Supreme1394
post Dec 17 2018, 01:21 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(Jigoku @ Dec 17 2018, 01:18 AM)
die now cannot transfer money then how if money gone?

CIMB gonna reimburse or what

I got money there use cimb to pay bill
*
Cimb has disabled overseas transaction for now, so your money should be safe (for now)
Mr. Najib Razak
post Dec 17 2018, 01:21 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(audi90 @ Dec 17 2018, 01:18 AM)
Kek i loled hard at your username and the comment
*
well
when u have 2.6b in that stupid bank
u will panic smile.gif
Raexim
post Dec 17 2018, 01:22 AM

Getting Started
**
Junior Member
75 posts

Joined: Aug 2016
QUOTE(adamhzm90 @ Dec 17 2018, 01:19 AM)
Damn, i also can log in using fake password.

And can transfer money too. Wtf cimb?
*
Fake password first 8 characters same as ori password or totally different?
teehk_tee
post Dec 17 2018, 01:22 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(buraqdunia @ Dec 17 2018, 01:19 AM)
so any1 whose transfer out, the amount  alrdy reflect in new acc and can cash out? just to make sure that is just a number on the screen.
*
use instant transfer. mine worked.
Omgf
post Dec 17 2018, 01:22 AM

Casual
***
Junior Member
392 posts

Joined: Jul 2009


Login CIMB IOS app via touch ID, money still there.
sixshot
post Dec 17 2018, 01:22 AM

Casual
***
Junior Member
464 posts

Joined: Apr 2010
From: Des Plaines


QUOTE(Jigoku @ Dec 17 2018, 01:20 AM)
You can transfer money?
*
can lol
briantwj
post Dec 17 2018, 01:22 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(max291 @ Dec 17 2018, 01:18 AM)
It have always been like this ever since they introduce it many years ago. Only first 8 characters are counted. The rest are jumbled out to confuse any keylogger.
*
Eh yea. I think I exp this b4. All this while thot my password is 9 letters. Then last time try with 8. It works. Read back only saw the 8 character limit password.
adamhzm90
post Dec 17 2018, 01:22 AM

Regular
******
Senior Member
1,389 posts

Joined: Apr 2014


QUOTE(Jigoku @ Dec 17 2018, 01:20 AM)
You can transfer money?
*
Yes able to instant transfer via app
maxpudding
post Dec 17 2018, 01:23 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(briantwj @ Dec 17 2018, 01:22 AM)
Eh yea. I think I exp this b4. All this while thot my password is 9 letters. Then last time try with 8. It works. Read back only saw the 8 character limit password.
*
Damn, nobody realizes abt the danger of this? Wtf cimb
veron4best
post Dec 17 2018, 01:24 AM

Regular
******
Senior Member
1,146 posts

Joined: Sep 2005
From: Kuala Lumpur


how do I change password? can't find le,
teehk_tee
post Dec 17 2018, 01:24 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(max291 @ Dec 17 2018, 01:18 AM)
It have always been like this ever since they introduce it many years ago. Only first 8 characters are counted. The rest are jumbled out to confuse any keylogger.
*
no its not.

back then it was character limited to 8.
u literally cant type more than 8 into it.

i know cuz this pw 8 char i always confius ingat lebih drpd 12 char
CAL V
post Dec 17 2018, 01:24 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


anak haram, really can simply login with wrong pw

briantwj
post Dec 17 2018, 01:25 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


The feck is their service manyzer doing mia. No ppl escalate to him kah
Snoe II
post Dec 17 2018, 01:25 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


QUOTE(Neo8663 @ Dec 17 2018, 01:16 AM)
ya, rhb better...long time no use cimb
*
Will start using RHB from now. The only thing is RHB app sucks big time 🤦🏻‍♂️🤦🏻‍♂️
Captain Coco
post Dec 17 2018, 01:26 AM

Getting Started
**
Junior Member
216 posts

Joined: Feb 2016
QUOTE(Omgf @ Dec 17 2018, 01:22 AM)
Login CIMB IOS app via touch ID, money still there.
*
TouchID is an easy login by recognizing your fingerprint and phone will assist to login using your username and password.. means yours are also compromised..
maxpudding
post Dec 17 2018, 01:26 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc

Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move
teehk_tee
post Dec 17 2018, 01:27 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(maxpudding @ Dec 17 2018, 01:26 AM)
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc

Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move
*
yes

back then it was limited to 8

now when u change u can put in 9, 10, 11, 12, 13 chars

defeck seriously
briantwj
post Dec 17 2018, 01:28 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Btw any other platform or Reddit reporting on this? Getting kinda boring here. Lol
ashburn98
post Dec 17 2018, 01:28 AM

Runaway train
******
Senior Member
1,570 posts

Joined: Nov 2005
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
Neo8663
post Dec 17 2018, 01:29 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(Snoe II @ Dec 17 2018, 01:25 AM)
Will start using RHB from now. The only thing is RHB app sucks big time 🤦🏻‍♂️🤦🏻‍♂️
*
but their website , i feels more user friendly
Zanei Gundan
post Dec 17 2018, 01:30 AM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
QUOTE(briantwj @ Dec 17 2018, 01:28 AM)
Btw any other platform or Reddit reporting on this? Getting kinda boring here. Lol
*
amanz
Higgsboson8888
post Dec 17 2018, 01:31 AM

Casual
***
Junior Member
362 posts

Joined: Jan 2015


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
Interested in knowing too
Muhammad Syukri
post Dec 17 2018, 01:31 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(Neo8663 @ Dec 17 2018, 01:29 AM)
but their website , i feels more user friendly
*
it feel early 2000's website
maxpudding
post Dec 17 2018, 01:31 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
Baca la

Short answer: nope, you are still farked

This post has been edited by maxpudding: Dec 17 2018, 01:31 AM
briantwj
post Dec 17 2018, 01:31 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
As long as u have a cimbclicks account, u are in danger.

Cimbclicks account meaning u have a password n ID to login to cimbclicks

This post has been edited by briantwj: Dec 17 2018, 01:32 AM
aku_ker
post Dec 17 2018, 01:32 AM

Casual
***
Junior Member
438 posts

Joined: Mar 2005



The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
jimmyktp
post Dec 17 2018, 01:32 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(thewan @ Dec 17 2018, 12:42 AM)
So much work. SMS can be redirected to another number. No need IC, no need Sim Card with target number. No need visit Police or telco, just sit at home. Just redirect all the bank sms to a hacker controlled number. Old vulnerability is old, please get educated dear Malaysians, and tell your banks, No more sms based authentication. Bank Negara should step in and fine or revoke licenses of banks that do not protect their customers money adequately.

Start here: https://arstechnica.com/information-technol...uting-protocol/ and then look up more on SS7 and SMS and how it all works. Then you will understand, no more SMS please.
*
Wow.

The method I explained was the modus operandi in 2004. Seems like the loophole is even easier now. Seriously, I started despising sms based authentication in 2015 when I arrived in UK to realise banks such as HSBC uses 2FA + Secureword. Just wow. Setting up initially is a pain and confusion, but once you done first time set up, everything is secured and easy. Consumers have to be smart. Say no to SMS authentication especially when it comes to banking..
NotYourKuda
post Dec 17 2018, 01:33 AM

Getting Started
**
Junior Member
137 posts

Joined: Sep 2016
From: Litar Kuda

IT dept will be fucked alive.
briantwj
post Dec 17 2018, 01:34 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
It’s an opening to many possibilities. Plus it coincides with the recent captcha introduction. 1+1.
hans86
post Dec 17 2018, 01:34 AM

New Member
*
Junior Member
31 posts

Joined: Oct 2006
From: Malaysia Ku Tercinta



I think cimb programmer use substr 8 then compare hash as first attempt and full str hash as 2nd attempt (after 8 char max removed).

Edit: Thats why they ask user to change password since the hash compare should be updated already.

This post has been edited by hans86: Dec 17 2018, 01:37 AM
Neo8663
post Dec 17 2018, 01:34 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


QUOTE(ashburn98 @ Dec 17 2018, 01:28 AM)
Late to the thread. If I didn't log in the whole week into CIMB Clicks, am I safe from this?
*
best way is transfer to other bank
iskull
post Dec 17 2018, 01:34 AM

Getting Started
**
Junior Member
66 posts

Joined: Jun 2016
if i am cimb it guy, i will consider change career

maybe cook noodle
jimmyktp
post Dec 17 2018, 01:35 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(maxpudding @ Dec 17 2018, 01:26 AM)
When exactly they allowed more than 8 chars for password? Back then they force you to have only 8 chars after opening your acc

Then, suddenly allows more than 8 chars without notifying you to strengthen your acc? That’s just a twat move
*
That is a fucking idiot move. I was complaining about this in earlier post. I didn't even know they SECRETLY allowed more than 8 characters now. But they forcing you to put special character now! Makes life even harder logging in from phone

This post has been edited by jimmyktp: Dec 17 2018, 01:36 AM
Snoe II
post Dec 17 2018, 01:36 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


QUOTE(veron4best @ Dec 17 2018, 01:24 AM)
how do I change password? can't find le,
*
Can't change using mobile phone. Must use PC or laptop. Or use your mobile phone, but access the desktop version one
Snoe II
post Dec 17 2018, 01:38 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


QUOTE(Neo8663 @ Dec 17 2018, 01:29 AM)
but their website , i feels more user friendly
*
Yeah. Can't denied that. But app one, never work. Always FC. 🤦🏻‍♂️
But still much better than having a massive security flaws
Jibbynomo
post Dec 17 2018, 01:38 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
For me i noticed now transfer money also no need any tac for verification. Crazy. So if they masuk someone acc and no need tac verify... Thats it
jimmyktp
post Dec 17 2018, 01:38 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(Muhammad Syukri @ Dec 17 2018, 01:31 AM)
it feel early 2000's website
*
Rookie web and app developer.
Jibbynomo
post Dec 17 2018, 01:38 AM

New Member
*
Newbie
4 posts

Joined: May 2018
Edit: OP twitter claiming cimb fixed the issue apologized for false info and confusion, requested to delete. OP apology below

QUOTE(faezpotato @ Dec 17 2018, 02:37 AM)
Hi All, im the OP from twitter. Sorry for the confusion on this. My bad for raising false alarm.
Sorry to everyone that believed in this.

Forgive for my stupidity.

sad.gif  sad.gif  sad.gif  cry.gif  cry.gif
*
This post has been edited by Jibbynomo: Dec 17 2018, 03:21 AM
teehk_tee
post Dec 17 2018, 01:39 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
check this thread.
most of the WTF I TRIED comments were still posted at 1+ am
zhuoyang
post Dec 17 2018, 01:40 AM

Getting Started
**
Junior Member
197 posts

Joined: Jul 2011
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
still can login with first 8 character correct tho
blacktubi
post Dec 17 2018, 01:40 AM

-
Group Icon
Elite
8,413 posts

Joined: Jul 2008

Actually some America banks are like that.

Despite allowing longer password, the system don’t care beyond certain number of characters.

Not sure the practice is still that way these days.

The situation at CIMB is not optimal but accounts are still secure. I think CIMB actually lock the account after 3 failed attempts.
Muhammad Syukri
post Dec 17 2018, 01:40 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
lies.

try check yourself.
Jibbynomo
post Dec 17 2018, 01:41 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(teehk_tee @ Dec 17 2018, 01:39 AM)
check this thread.
most of the WTF I TRIED comments were still posted at 1+ am
*
Exactly, dunno where he get sources from
lightbringer
post Dec 17 2018, 01:41 AM

Casual
***
Junior Member
395 posts

Joined: Jan 2003


QUOTE(zhuoyang @ Dec 17 2018, 01:40 AM)
still can login with first 8 character correct tho
*
not me though, i changed my password, tried inputting the first 8 characters only, prompted with invalid username/password error message
Shooterz
post Dec 17 2018, 01:41 AM

abcdefaiz
*******
Senior Member
2,538 posts

Joined: Jan 2003
From: Kota Bharu



gimme an id to check i dont have acc there
fridel
post Dec 17 2018, 01:41 AM

kuran ka? ok e oi?
******
Senior Member
1,659 posts

Joined: Nov 2010
From: the tip of borneo
Cukur i dun use cimb
portgasz
post Dec 17 2018, 01:41 AM

New Member
*
Junior Member
14 posts

Joined: Feb 2013
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
Wrong lo. until now still can.
forte_amirul
post Dec 17 2018, 01:42 AM

New Member
*
Newbie
1 posts

Joined: Dec 2012


QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
Haven't changed my password yet, tried login using CIMB app with the exploit and it worked lol
jimmyktp
post Dec 17 2018, 01:42 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(blacktubi @ Dec 17 2018, 01:40 AM)
Actually some America banks are like that.

Despite allowing longer password, the system don’t care beyond certain number of characters.

Not sure the practice is still that way these days.

The situation at CIMB is not optimal but accounts are still secure. I think CIMB actually lock the account after 3 failed attempts.
*
Don't bother following America. Their security are shit anyways. Look at their card payments fraud. Still using magnetic lol
briantwj
post Dec 17 2018, 01:42 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
Why not ask him? Lol
maxpudding
post Dec 17 2018, 01:43 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka?
*
Fixed pala hotak dia

Putting recaptcha, disabling overseas transfers are not what you can call “fixed”

Serious breach of security, and cimb should answer for it
CAL V
post Dec 17 2018, 01:45 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


bullshit, had to wake up my sister from her sleep and risk getting scolded. Turns out her acc is compromised in the same way too. (*as in adding random numbers behind the original pw)

This post has been edited by CAL V: Dec 17 2018, 01:48 AM
syamilshahimi
post Dec 17 2018, 01:46 AM

Getting Started
**
Junior Member
137 posts

Joined: Jul 2011


My other acc is Tabung Haji. How le? Transfer there also money hilang lmao gg
Jigoku
post Dec 17 2018, 01:46 AM

Getting Started
**
Junior Member
288 posts

Joined: Jan 2010

QUOTE(CAL V @ Dec 17 2018, 01:45 AM)
bullshit, had to wake up my sister from her sleep and risk getting scolded. Turns out her acc is compromised in the same way too.
*
compromised as in insert first 8password then cincai belakang dapat masuk or hilang duit?


blacktubi
post Dec 17 2018, 01:47 AM

-
Group Icon
Elite
8,413 posts

Joined: Jul 2008

“The standard DES-based crypt() returns the salt as the first two characters of the output. It also only uses the first eight characters of str, so longer strings that start with the same eight characters will generate the same result (when the same salt is used).”

Not sure if this is actually the case. My 2 cents. smile.gif

http://php.net/manual/en/function.crypt.php
Muhammad Syukri
post Dec 17 2018, 01:47 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(maxpudding @ Dec 17 2018, 01:43 AM)
Fixed pala hotak dia

Putting recaptcha, disabling overseas transfers are not what you can call “fixed”

Serious breach of security, and cimb should answer for it
*
biasalah twittard people nak woke jer
briantwj
post Dec 17 2018, 01:47 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Ok I just tried this and it worked. Change ur password. After that try the exploit again. It didn’t work.

Just change ur password and go to sleep guys. I think it only affect those ppl that is still on their old 8 alphabet password.
CAL V
post Dec 17 2018, 01:47 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


QUOTE(Jigoku @ Dec 17 2018, 01:46 AM)
compromised as in insert first 8password then cincai belakang dapat masuk or hilang duit?
*
cincai add number also can login, considered lucky still haven't lose money doh.gif
mambangafro
post Dec 17 2018, 01:48 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


QUOTE(briantwj @ Dec 17 2018, 01:47 AM)
Ok I just tried this and it worked. Change ur password. After that try the exploit again. It didn’t work.

Just change ur password and go to sleep guys. I think it only affect those ppl that is still on their old 8 alphabet password.
*
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
JimbeamofNRT
post Dec 17 2018, 01:49 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(maxpudding @ Dec 17 2018, 01:43 AM)
Fixed pala hotak dia

Putting recaptcha, disabling overseas transfers are not what you can call “fixed”

Serious breach of security, and cimb should answer for it
*
KNN CIMB! u make me lose my sleeping time ! now I have to transfer the remaining money into my chinaman bank.




now it looks like bank run situation. wonder how much % did cimb losing tonight

This post has been edited by JimbeamofNRT: Dec 17 2018, 01:49 AM
Mr. Najib Razak
post Dec 17 2018, 01:49 AM

Casual
***
Junior Member
321 posts

Joined: Jun 2016
QUOTE(syamilshahimi @ Dec 17 2018, 01:46 AM)
My other acc is Tabung Haji. How le? Transfer there also money hilang lmao gg
*
transfer to me smile.gif
u money will be safe and sound smile.gif
AyamBannedTwice
post Dec 17 2018, 01:50 AM

Getting Started
**
Junior Member
130 posts

Joined: Feb 2015


Serious question,
If got no cimbclicks account safe or not?
Quantum Geist
post Dec 17 2018, 01:50 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(blacktubi @ Dec 17 2018, 01:47 AM)
“The standard DES-based crypt() returns the salt as the first two characters of the output. It also only uses the first eight characters of str, so longer strings that start with the same eight characters will generate the same result (when the same salt is used).”

Not sure if this is actually the case. My 2 cents. smile.gif

http://php.net/manual/en/function.crypt.php
*
Thought of the same thing, but if true cimb really cheapskate to dedicate resources for hashing
teehk_tee
post Dec 17 2018, 01:50 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(JimbeamofNRT @ Dec 17 2018, 01:49 AM)
KNN CIMB! u make me lose my sleeping time ! now I have to transfer the remaining money into my chinaman bank.
now it looks like bank run situation. wonder how much % did cimb losing tonight
*
I was surfing before sleep

Kanineh now did all i can n wide awake now lul.
briantwj
post Dec 17 2018, 01:50 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(mambangafro @ Dec 17 2018, 01:48 AM)
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
*
Boleh kut. Ni more like masalah login authorisation je for cimbclicks. Naik grab je bruh. Atau suruh si Wanni jadi mamat je
xeon1989
post Dec 17 2018, 01:50 AM

Member since 2008
*****
Junior Member
964 posts

Joined: Jun 2008
QUOTE(blacktubi @ Dec 17 2018, 01:47 AM)
“The standard DES-based crypt() returns the salt as the first two characters of the output. It also only uses the first eight characters of str, so longer strings that start with the same eight characters will generate the same result (when the same salt is used).”

Not sure if this is actually the case. My 2 cents. smile.gif

http://php.net/manual/en/function.crypt.php
*
This is only true if password was used for salt.
But we certainly won't know for sure. tongue.gif
veron4best
post Dec 17 2018, 01:50 AM

Regular
******
Senior Member
1,146 posts

Joined: Sep 2005
From: Kuala Lumpur


QUOTE(briantwj @ Dec 17 2018, 01:47 AM)
Ok I just tried this and it worked. Change ur password. After that try the exploit again. It didn’t work.

Just change ur password and go to sleep guys. I think it only affect those ppl that is still on their old 8 alphabet password.
*
how to change password?

only by call customer servic?

This post has been edited by veron4best: Dec 17 2018, 01:51 AM
JimbeamofNRT
post Dec 17 2018, 01:50 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(mambangafro @ Dec 17 2018, 01:48 AM)
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
*
most likely u will see this error message tomorrow

GGWP

user posted image
maxpudding
post Dec 17 2018, 01:51 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(mambangafro @ Dec 17 2018, 01:48 AM)
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
*
Boleh la bang

CAL V
post Dec 17 2018, 01:51 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


QUOTE(JimbeamofNRT @ Dec 17 2018, 01:49 AM)
KNN CIMB! u make me lose my sleeping time ! now I have to transfer the remaining money into my chinaman bank.
now it looks like bank run situation. wonder how much % did cimb losing tonight
*
Check their stock price in the morning unsure.gif
mambangafro
post Dec 17 2018, 01:52 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


QUOTE(JimbeamofNRT @ Dec 17 2018, 01:50 AM)
most likely u will see this error message tomorrow

GGWP

user posted image
*
sekeh kang
aku dalam wallet ade 5 ringgit je ni
maxpudding
post Dec 17 2018, 01:52 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
Besok masuk kerja lambat

Blame cimb

Lulz

Luckily my time is flexible
briantwj
post Dec 17 2018, 01:52 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(veron4best @ Dec 17 2018, 01:50 AM)
how to change password?

only by call customer servic?
*
Login to cimbclicks. But can’t change if u login via webpage on android. I guna IPad only can change. Bottom left settings icon.
JimbeamofNRT
post Dec 17 2018, 01:53 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 01:50 AM)
I was surfing before sleep

Kanineh now did all i can n wide awake now lul.
*
real p#ndek I tell you

my staff message me at midnight telling me about this fiasco






I am sure there will be a long queue at the cimb branch tomorrow

user posted image

user posted image
briantwj
post Dec 17 2018, 01:53 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(maxpudding @ Dec 17 2018, 01:52 AM)
Besok masuk kerja lambat

Blame cimb

Lulz

Luckily my time is flexible
*
Kerja apa bang
teehk_tee
post Dec 17 2018, 01:53 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(veron4best @ Dec 17 2018, 01:50 AM)
how to change password?

only by call customer servic?
*
Login to desktop version
Bottom left there is a Gear icon.. Click on it
jesserider223
post Dec 17 2018, 01:53 AM

Getting Started
**
Junior Member
173 posts

Joined: Mar 2015


QUOTE(Mr. Najib Razak @ Dec 17 2018, 01:49 AM)
transfer to me smile.gif
u money will be safe and sound smile.gif
*
i'll do it

better as you're someone well known in public and trusted

let me know which bank and account no ya icon_rolleyes.gif



maxpudding
post Dec 17 2018, 01:54 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(briantwj @ Dec 17 2018, 01:53 AM)
Kerja apa bang
*
Pekebun berjaya
briantwj
post Dec 17 2018, 01:55 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(maxpudding @ Dec 17 2018, 01:54 AM)
Pekebun berjaya
*
Fun Berjaya. Got ur hint bruh. brows.gif
JimbeamofNRT
post Dec 17 2018, 01:55 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 01:53 AM)
Login to desktop version
Bottom left there is a Gear icon.. Click on it
*
suddenly feel uneasy to do that lol

god knows maybe the captcha shit is a trojan ... KNNCCB NOW I AM PARANOID



what if the captcha shit already record all the login and pwd... waiting for the right time to strike?
briantwj
post Dec 17 2018, 01:56 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(JimbeamofNRT @ Dec 17 2018, 01:55 AM)
suddenly feel uneasy to do that lol

god knows maybe the captcha shit is a trojan ... KNNCCB NOW I AM PARANOID
what if the captcha shit already record all the login and pwd... waiting for the right time to strike?
*
I don’t think captcha works that way...
forte_amirul
post Dec 17 2018, 01:57 AM

New Member
*
Newbie
1 posts

Joined: Dec 2012


QUOTE(AyamBannedTwice @ Dec 17 2018, 01:50 AM)
Serious question,
If got no cimbclicks account safe or not?
*
Same with my mom, had her card cancelled too cuz she thought she lost it. Are they safe?
Supreme1394
post Dec 17 2018, 01:58 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(JimbeamofNRT @ Dec 17 2018, 01:55 AM)
suddenly feel uneasy to do that lol

god knows maybe the captcha shit is a trojan ... KNNCCB NOW I AM PARANOID
what if the captcha shit already record all the login and pwd... waiting for the right time to strike?
*
Captcha was implemented by cimb bro, not some hackers
maxpudding
post Dec 17 2018, 01:58 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(JimbeamofNRT @ Dec 17 2018, 01:55 AM)
suddenly feel uneasy to do that lol

god knows maybe the captcha shit is a trojan ... KNNCCB NOW I AM PARANOID
what if the captcha shit already record all the login and pwd... waiting for the right time to strike?
*
The captcha thing is to slow down bruteforce attack


olman
post Dec 17 2018, 01:58 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


Dats y harimau bank best

Cimb is related to u know who is riddled with corrupt scandals
aeiou228
post Dec 17 2018, 01:58 AM

Look at all my stars!!
*******
Senior Member
5,867 posts

Joined: Feb 2006
Just logined but my debit card and Lazada prepaid card not listed, hilang. Then after changed password, Lazada prepaid card reappeared like magic but debit card still out of sight.
You guys can see your debit card in cimb clicks?
maxpudding
post Dec 17 2018, 01:58 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(briantwj @ Dec 17 2018, 01:55 AM)
Fun Berjaya. Got ur hint bruh.  brows.gif
*
Err 🤭
Neo8663
post Dec 17 2018, 01:59 AM

Regular
******
Senior Member
1,244 posts

Joined: Jul 2005


going to bed ...what a sunday night , spend time on this dafak...
Jibbynomo
post Dec 17 2018, 01:59 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(mambangafro @ Dec 17 2018, 01:48 AM)
yes i did and it works for now
but atm still can keluar duit esok rite?
nak isi minyak kete ni
*
U and ur isi minyak kete from just now 😂🤣

Should be no problem.. Unless attackers taken all ur money already lo 😭😭
JimbeamofNRT
post Dec 17 2018, 01:59 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(briantwj @ Dec 17 2018, 01:56 AM)
I don’t think captcha works that way...
*
what IF some trojan disguising as real "recaptcha"

imagine if someone created some trojan using this idea ->

https://fakecaptcha.com/
https://fakecaptcha.com/generate.php

This post has been edited by JimbeamofNRT: Dec 17 2018, 02:00 AM
briantwj
post Dec 17 2018, 02:00 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Hmm. Just my guess. Maybe there are still a lot of ppl that didn’t change their password to cimb latest policy, a lot still on the 8 character password policy.

And recently a lot of brute force on user login. So they implement the captcha thing.

Doing my best making up setoli. Lol
JimbeamofNRT
post Dec 17 2018, 02:01 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(Neo8663 @ Dec 17 2018, 01:59 AM)
going to bed ...what a sunday night , spend time on this dafak...
*
real p_ndek I tell u this cimb
leftycall9
post Dec 17 2018, 02:01 AM

Left of leftist
******
Senior Member
1,046 posts

Joined: Jun 2010
I don't dare to log in my account through cimb click now

wanna wait until they sort things out first
maxpudding
post Dec 17 2018, 02:01 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(JimbeamofNRT @ Dec 17 2018, 01:59 AM)
what IF some trojan disguising as real "recaptcha"

imagine if someone created some trojan using this idea ->

https://fakecaptcha.com/
https://fakecaptcha.com/generate.php
*
Cimb already said they were implementing it because of some “issues”

They did not clarify it was a massive security breach happening behind their system that made them implement it
himura_21
post Dec 17 2018, 02:02 AM

New Member
*
Junior Member
33 posts

Joined: May 2008
From: petaling jaya


Was about to go to sleep at 12++..now i am wideee awaakkeeee.
dummies
post Dec 17 2018, 02:02 AM

Getting Started
**
Junior Member
268 posts

Joined: Apr 2005
who can change password on cimbclicks, i tried to change it , it keeps on saying invalid user name and password and give that damn error id: CLK00619
maxpudding
post Dec 17 2018, 02:02 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(leftycall9 @ Dec 17 2018, 02:01 AM)
I don't dare to log in my account through cimb click now

wanna wait until they sort things out first
*
You login or not, your account is still vulnerable
JimbeamofNRT
post Dec 17 2018, 02:02 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(leftycall9 @ Dec 17 2018, 02:01 AM)
I don't dare to log in my account through cimb click now

wanna wait until they sort things out first
*
better log in now, transfer all your money into your other bank account FAST

otherwise what if.............................................


JimbeamofNRT
post Dec 17 2018, 02:03 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(maxpudding @ Dec 17 2018, 02:01 AM)
Cimb already said they were implementing it because of some “issues”

They did not clarify it was a massive security breach happening behind their system that made them implement it
*
there goes your personal data

DAMN U CIMB! vmad.gif vmad.gif vmad.gif
yoyo_icecube
post Dec 17 2018, 02:04 AM

Getting Started
**
Junior Member
66 posts

Joined: Jul 2010
From: ipoh


QUOTE(ahhann @ Dec 16 2018, 11:39 PM)
Tried app login. Put in correct username and correct image and correct password. Immediately prompt alert ask me go to their website to change password. De fuck? I just successfully login last week.
*
Happen to me too. I found it weird, and suddenly (on the same day) my card cannot use to do payment while buying blackpink concert tickets. But no weird transfer so far. Maybe i will withdraw all money tomorrow if no update from cimb by tomorrow morning.

QUOTE(seanlam @ Dec 17 2018, 01:15 AM)
If one happen to be travelling and found out his cc is just a useless plastic card, while cash in hand running low......
*
Go kedutaan to seek help? Can ah?
teehk_tee
post Dec 17 2018, 02:04 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(briantwj @ Dec 17 2018, 01:47 AM)
Ok I just tried this and it worked. Change ur password. After that try the exploit again. It didn’t work.

Just change ur password and go to sleep guys. I think it only affect those ppl that is still on their old 8 alphabet password.
*
can confirm.. once change pw is ok.

but this dent in trust, i cannot accept.
maxpudding
post Dec 17 2018, 02:05 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(teehk_tee @ Dec 17 2018, 02:04 AM)
can confirm.. once change pw is ok.

but this dent in trust, i cannot accept.
*
Yup, seriously thinking to close cimb account right now
Supreme1394
post Dec 17 2018, 02:05 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(JimbeamofNRT @ Dec 17 2018, 02:02 AM)
better log in now, transfer all your money into your other bank account FAST

otherwise what if.............................................
*
Overseas transactions automatically disabled for now, just login and change password
JimbeamofNRT
post Dec 17 2018, 02:06 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 02:04 AM)
can confirm.. once change pw is ok.

but this dent in trust, i cannot accept.

*
summore it is about $

aiseh cimb... u really want to be famous for wrong reason lah this time...
Zanei Gundan
post Dec 17 2018, 02:06 AM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
QUOTE(maxpudding @ Dec 17 2018, 02:05 AM)
Yup, seriously thinking to close cimb account right now
*
imagine if many pipul kolos bank liddis

scary weh
briantwj
post Dec 17 2018, 02:07 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(teehk_tee @ Dec 17 2018, 02:04 AM)
can confirm.. once change pw is ok.

but this dent in trust, i cannot accept.
*
Plus the sudden captcha implementation. I never see bank industry use captcha for ebanking before. LOL.

It’s like, they know there are scripts trying to brute force. But captcha? Seriously?

This post has been edited by briantwj: Dec 17 2018, 02:08 AM
aeiou228
post Dec 17 2018, 02:07 AM

Look at all my stars!!
*******
Senior Member
5,867 posts

Joined: Feb 2006
QUOTE(yoyo_icecube @ Dec 17 2018, 02:04 AM)
Happen to me too. I found it weird, and suddenly (on the same day) my card cannot use to do payment while buying blackpink concert tickets. But no weird transfer so far. Maybe i will withdraw all money tomorrow if no update from cimb by tomorrow morning.
Go kedutaan to seek help? Can ah?
*
Can you see your debit card in clicks? Mine hilang.
Hensem
post Dec 17 2018, 02:07 AM

New Member
*
Junior Member
22 posts

Joined: Aug 2008
luckily i stash all my money under my pillow

own saving ftw
CAL V
post Dec 17 2018, 02:08 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


QUOTE(Zanei Gundan @ Dec 17 2018, 02:06 AM)
imagine if many pipul kolos bank liddis

scary weh
*
later you see bank kolos door *touch wood touch wood*
JimbeamofNRT
post Dec 17 2018, 02:08 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(Zanei Gundan @ Dec 17 2018, 02:06 AM)
imagine if many pipul kolos bank liddis

scary weh
*
no need to close but to transfer ALL THE MONEY TO OTHER BANK ASAP

knn now feels like bank run already

I WASTED ALMOST AN HOUR OF MY SLEEPING TIME FURIOUSLY TRANSFERRING some $ to that chinaman bank KNNCCB BETUL CIMB!
ashburn98
post Dec 17 2018, 02:09 AM

Runaway train
******
Senior Member
1,570 posts

Joined: Nov 2005
Changed my password from old 8 characters to a new (confusing) password.

Getting some sleep now and see what transpires tomorrow.
briantwj
post Dec 17 2018, 02:09 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Wasted 2 hours of sleep for this shit
JimbeamofNRT
post Dec 17 2018, 02:10 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(Supreme1394 @ Dec 17 2018, 02:05 AM)
Overseas transactions automatically disabled for now, just login and change password
*
imagine u are in overseas, no need to go far lah, SG enough... knn u panic or not?

I got a morning flight summore this morning KNN now I Cannot sleep at all
Supreme1394
post Dec 17 2018, 02:10 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(aeiou228 @ Dec 17 2018, 02:07 AM)
Can you see your debit card in clicks? Mine hilang.
*
Go check your "Overseas Spends & Withdrawals", your card number should be there with "Disabled" shown.
JimbeamofNRT
post Dec 17 2018, 02:10 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(briantwj @ Dec 17 2018, 02:09 AM)
Wasted 2 hours of sleep for this shit
*
I think we need to write to BNM after this

KNN CIMB! mad.gif mad.gif mad.gif
dummies
post Dec 17 2018, 02:11 AM

Getting Started
**
Junior Member
268 posts

Joined: Apr 2005
QUOTE(ashburn98 @ Dec 17 2018, 02:09 AM)
Changed my password from old 8 characters to a new (confusing) password.

Getting some sleep now and see what transpires tomorrow.
*
how you changed your password? I can't change it if i login to their website using my laptop
it keeps on giving me the invalid ID and password error even though i keyed in the correct password

This post has been edited by dummies: Dec 17 2018, 02:11 AM
Supreme1394
post Dec 17 2018, 02:11 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(JimbeamofNRT @ Dec 17 2018, 02:10 AM)
imagine u are in overseas, no need to go far lah, SG enough... knn u panic or not?

I got a morning flight summore this morning KNN now I Cannot sleep at all
*
Confirm panic, especially cannot use funds from cards overseas.
Zanei Gundan
post Dec 17 2018, 02:12 AM

Getting Started
**
Junior Member
143 posts

Joined: Aug 2010
From: My Bloody Valentine
QUOTE(JimbeamofNRT @ Dec 17 2018, 02:08 AM)
no need to close but to transfer ALL THE MONEY TO OTHER BANK ASAP

knn now feels like bank run already

I WASTED ALMOST AN HOUR OF MY SLEEPING TIME FURIOUSLY TRANSFERRING some $ to that chinaman bank KNNCCB BETUL CIMB!
*
transfer and remind HR to transfer paycheck to other banks as well

am fortunate enough to be alerted earlier before things went out of control on whatsapp
teehk_tee
post Dec 17 2018, 02:12 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

Jeez.. Nothing else i can do except grab some sleep. All i can hope is tmrw my money still there n try to move it out to a safer institution.

This post has been edited by teehk_tee: Dec 17 2018, 02:13 AM
Supreme1394
post Dec 17 2018, 02:13 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(dummies @ Dec 17 2018, 02:11 AM)
how you changed your password? I can't change it if i login to their website using my laptop
it keeps on giving me the invalid ID and password error even though i keyed in the correct password
*
Try use another device like your smartphone (must request desktop site) to change.
hor
post Dec 17 2018, 02:14 AM

New Member
*
Junior Member
37 posts

Joined: Dec 2007


My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only

*roll out*

4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
dummies
post Dec 17 2018, 02:15 AM

Getting Started
**
Junior Member
268 posts

Joined: Apr 2005
QUOTE(Supreme1394 @ Dec 17 2018, 02:13 AM)
Try use another device like your smartphone  (must request desktop site) to change.
*
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
JimbeamofNRT
post Dec 17 2018, 02:16 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(Zanei Gundan @ Dec 17 2018, 02:12 AM)
transfer and remind HR to transfer paycheck to other banks as well

am fortunate enough to be alerted earlier before things went out of control on whatsapp
*
tomorrow sure become like this

user posted image

already masuk whatsapp sure GGWP
JimbeamofNRT
post Dec 17 2018, 02:16 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 02:12 AM)
Jeez.. Nothing else i can do except grab some sleep. All i can hope is tmrw my money still there n try to move it out to a safer institution.
*
u r in overseas now? cannot do transfer online right now?
JimbeamofNRT
post Dec 17 2018, 02:17 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(Supreme1394 @ Dec 17 2018, 02:11 AM)
Confirm panic, especially cannot use funds from cards overseas.
*
become sitting duck liddat mad.gif
teehk_tee
post Dec 17 2018, 02:17 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(JimbeamofNRT @ Dec 17 2018, 02:16 AM)
u r in overseas now? cannot do transfer online right now?
*
Transfer limited to 10k je
briantwj
post Dec 17 2018, 02:17 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
Chrome? Tap the 3 dot icon on the top right. It should be there. Something like request desktop site
Supreme1394
post Dec 17 2018, 02:18 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
If you're using ios :

1. Visit the affected site in Safari.
2. Tap and hold the Refresh button in the URL bar.
3. Tap Request Desktop Site.
JimbeamofNRT
post Dec 17 2018, 02:18 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 02:17 AM)
Transfer limited to 10k je
*
daily max now rm30K

knn... meaning still need to go to branch tomorrow

WHYYYYYYYYYYYYYYYYYYYYY LAHHH CIMB!!! mad.gif bangwall.gif mad.gif bangwall.gif
teehk_tee
post Dec 17 2018, 02:19 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
Look at yr top right, 3 dots (beside the tab count), at the cimbclicks tab click it and tick 'request desktop site'
briantwj
post Dec 17 2018, 02:19 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Headline tmr:

We have updated password policy and send notice. However users are still on old policy. Hence we implemented captcha as additional security measure.

To those who are still using the old password policy. Please update to our new password policy. Thanks.

Lol
Jibbynomo
post Dec 17 2018, 02:19 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
Login window theres a underlined in black desktop view button there..

Or use as below, show as desktop.. But i tried that using safari iphone and didnt work, so had to use the underlined Desktop View button below login window

This post has been edited by Jibbynomo: Dec 17 2018, 02:20 AM
mambangafro
post Dec 17 2018, 02:19 AM

ME IS KUDA PING :3
****
Senior Member
639 posts

Joined: Aug 2010


QUOTE(dummies @ Dec 17 2018, 02:15 AM)
bro , how to request desktop site from the smart phone? It keeps on redirecting to their mobile site :-(
*
user posted image

tick DESKTOP SITE box
teehk_tee
post Dec 17 2018, 02:19 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(JimbeamofNRT @ Dec 17 2018, 02:18 AM)
daily max now rm30K

knn... meaning still need to go to branch tomorrow

WHYYYYYYYYYYYYYYYYYYYYY LAHHH CIMB!!!  mad.gif  bangwall.gif  mad.gif  bangwall.gif
*
How to increase limit online?
jimmyktp
post Dec 17 2018, 02:20 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(aspartame @ Dec 17 2018, 01:14 AM)
Locals banks also have what...using TAC..or securepay.....
*
SMS TAC is not secure and can be exploited
otakotak
post Dec 17 2018, 02:21 AM

Getting Started
**
Junior Member
280 posts

Joined: Nov 2010


QUOTE(blacktubi @ Dec 17 2018, 01:47 AM)
“The standard DES-based crypt() returns the salt as the first two characters of the output. It also only uses the first eight characters of str, so longer strings that start with the same eight characters will generate the same result (when the same salt is used).”

Not sure if this is actually the case. My 2 cents. smile.gif

http://php.net/manual/en/function.crypt.php
*
QUOTE(Quantum Geist @ Dec 17 2018, 01:50 AM)
Thought of the same thing, but if true cimb really cheapskate to dedicate resources for hashing
*
remind me of 3des in ecb mode haha. any 8 chars + 12345678 can straight login? rolleyes.gif
so migrate old customer with 8 chars password to new field length. do some shitty re-hashing workaround by just + current pass with random 12345678 number so that their password can still works.
i guess that captcha thing is to reduce bruteforce attempt? kek doh.gif if this is the case, just update your password will do la icon_rolleyes.gif

and this!!
QUOTE(hor @ Dec 17 2018, 02:14 AM)
My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only

*roll out*

4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
*
This post has been edited by otakotak: Dec 17 2018, 02:23 AM
Davez89
post Dec 17 2018, 02:21 AM

Regular
******
Senior Member
1,275 posts

Joined: Nov 2007


I have 10 ringgit in my account omg
JimbeamofNRT
post Dec 17 2018, 02:22 AM

the Original Lanji@_ Chicken Rice Shop Since 2002
******
Senior Member
1,902 posts

Joined: Sep 2012

QUOTE(teehk_tee @ Dec 17 2018, 02:19 AM)
How to increase limit online?
*
IIRC kana do at the cimb atm machine only. online cannot .

meaning if you are at overseas... GGWP
teehk_tee
post Dec 17 2018, 02:22 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(otakotak @ Dec 17 2018, 02:21 AM)
remind me of 3des in ecb mode haha. any 8 chars + 12345678 can straight login?  rolleyes.gif
so migrate old customer with 8 chars password to new field length. do some shitty re-hashing workaround by just + current pass with random 12345678 number so that their password can still works.
i guess that captcha thing is to reduce bruteforce attempt? kek  doh.gif if this is the case, just update your password will do la  icon_rolleyes.gif
*
Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this.

Not allow 8char + whatever shit to login.
dummies
post Dec 17 2018, 02:23 AM

Getting Started
**
Junior Member
268 posts

Joined: Apr 2005
QUOTE(teehk_tee @ Dec 17 2018, 02:19 AM)
Look at yr top right, 3 dots (beside the tab count), at the cimbclicks tab click it and tick 'request desktop site'
*
t
got it, thanks, but still the same result, it does not allow me to change my password...using iphone cannot change, using PC cannot change, using iphone with desktop site also does not allow me to change, not sure how i can change my password
teehk_tee
post Dec 17 2018, 02:25 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(JimbeamofNRT @ Dec 17 2018, 02:22 AM)
IIRC kana do at the cimb atm machine only. online cannot .

meaning if you are at overseas... GGWP
*
Aiseh.. Stress. Sleep first aih
derthvadar
post Dec 17 2018, 02:26 AM

(ง •̀_•́)ง
******
Senior Member
1,792 posts

Joined: Feb 2016
From: Bikini Bottom
Just transferred my money to Maybank account. Go take my balance.

user posted image
Jibbynomo
post Dec 17 2018, 02:28 AM

New Member
*
Newbie
4 posts

Joined: May 2018
QUOTE(derthvadar @ Dec 17 2018, 02:26 AM)
Just transferred my money to Maybank account. Go take my balance.

user posted image
*
Ok. Gimme ur cimb user id and pw. tongue.gif
JustcallmeLarry
post Dec 17 2018, 02:32 AM

Regular
******
Senior Member
1,363 posts

Joined: Jan 2010


Guys a bit tired to read through the thread now. Can someone pls give me the TLTR version.

Just want to know who is at risk & what to do if you been compromised???

Don't ask me to transfer money to other Banks bcs I have few loans with cimb...
Snoe II
post Dec 17 2018, 02:33 AM

Socialife;Not
******
Senior Member
1,395 posts

Joined: Feb 2012
From: Banting


user posted image

RIP CIMB

Sos: https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/

This post has been edited by Snoe II: Dec 17 2018, 02:34 AM
CAL V
post Dec 17 2018, 02:34 AM

Getting Started
**
Junior Member
277 posts

Joined: Dec 2011


QUOTE(JustcallmeLarry @ Dec 17 2018, 02:32 AM)
Guys a bit tired to read through the thread now. Can someone pls give me the TLTR version.

Just want to know who is at risk & what to do if you been compromised???

Don't ask me to transfer money to other Banks bcs I have few loans with cimb...
*
In short, the least is change your password immediately
teehk_tee
post Dec 17 2018, 02:34 AM

ไม่เป็นไร
*******
Senior Member
5,363 posts

Joined: Apr 2005
From: กรุงเทพมหานคร BKK

QUOTE(JustcallmeLarry @ Dec 17 2018, 02:32 AM)
Guys a bit tired to read through the thread now. Can someone pls give me the TLTR version.

Just want to know who is at risk & what to do if you been compromised???

Don't ask me to transfer money to other Banks bcs I have few loans with cimb...
*
Ok short version, please change your pw asap.
Supreme1394
post Dec 17 2018, 02:36 AM

Achieving Supremacy
*****
Senior Member
864 posts

Joined: Oct 2011
From: planet earth


QUOTE(JustcallmeLarry @ Dec 17 2018, 02:32 AM)
Guys a bit tired to read through the thread now. Can someone pls give me the TLTR version.

Just want to know who is at risk & what to do if you been compromised???

Don't ask me to transfer money to other Banks bcs I have few loans with cimb...
*
Basically every cimbclicks users are compromised. What you should do now is login and change your password. Cimb has disabled all overseas transactions for now to prevent further damage.
salya
post Dec 17 2018, 02:37 AM

Getting Started
**
Junior Member
70 posts

Joined: Jun 2010
I already change password, do you think it is safe? all the transaction limit to change to 0.00 and i was deactivate overseas spending also

This post has been edited by salya: Dec 17 2018, 02:39 AM
faezpotato
post Dec 17 2018, 02:37 AM

Getting Started
**
Junior Member
80 posts

Joined: Apr 2014
QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
user posted image

Betul ka? /s

Mamat ni merepek. Go ask him for source link for cimb fix this on his Twitter. Confirm nothing. Pulled it outta his lubang tahi
*
Hi All, im the OP from twitter. Sorry for the confusion on this. My bad for raising false alarm.
Sorry to everyone that believed in this.

Forgive for my stupidity.

sad.gif sad.gif sad.gif cry.gif cry.gif
leftycall9
post Dec 17 2018, 02:43 AM

Left of leftist
******
Senior Member
1,046 posts

Joined: Jun 2010
OMG!!!!

I just tried logged in using 12345678 it went straight into my account! the old password is useless now!

sudah changed tho. I used complex combination of numbers and characters hopefully it will be fine. balance still intact not much left because of Christmas shopping but damn you CIMB
derthvadar
post Dec 17 2018, 02:44 AM

(ง •̀_•́)ง
******
Senior Member
1,792 posts

Joined: Feb 2016
From: Bikini Bottom
QUOTE(faezpotato @ Dec 17 2018, 02:37 AM)
Hi All, im the OP from twitter. Sorry for the confusion on this. My bad for raising false alarm.
Sorry to everyone that believed in this.

Forgive for my stupidity.

sad.gif  sad.gif  sad.gif  cry.gif  cry.gif
*
Kasi delete tweets.
WhitE LighteR
post Dec 17 2018, 02:45 AM

WhitE LighteR Is Black~
********
All Stars
10,340 posts

Joined: Jan 2003


QUOTE(dummies @ Dec 17 2018, 02:02 AM)
who can change password on cimbclicks, i tried to change it , it keeps on saying invalid user name and password and give that damn error id: CLK00619
*
For those facing this problem. The website change password only require first 8 character of your original password. Dont enter more or it will give the above error. Once updated I think the database updates the data type and the exploit no longer seems to work. It will check and match the full new password.
red1982
post Dec 17 2018, 02:46 AM

Casual
***
Junior Member
488 posts

Joined: Jun 2017
For those who wants to know whether your password are secure .. test it here https://howsecureismypassword.net/
piringkosong
post Dec 17 2018, 02:49 AM

Getting Started
**
Junior Member
50 posts

Joined: Nov 2012
The fukkk. So is it safe to online transfer to other bank account now?
Cept
post Dec 17 2018, 02:51 AM

Getting Started
**
Junior Member
51 posts

Joined: Jun 2017
Looks like they disable Login and Register already.
Muhammad Syukri
post Dec 17 2018, 02:51 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(leftycall9 @ Dec 17 2018, 02:43 AM)
OMG!!!!

I just tried logged in using 12345678 it went straight into my account! the old password is useless now!

sudah changed tho. I used complex combination of numbers and characters hopefully it will be fine. balance still intact not much left because of Christmas shopping but damn you CIMB
*
Biar betul bro 12345678 oso can?
leftycall9
post Dec 17 2018, 02:56 AM

Left of leftist
******
Senior Member
1,046 posts

Joined: Jun 2010
QUOTE(Muhammad Syukri @ Dec 17 2018, 02:51 AM)
Biar betul bro 12345678 oso can?
*
just got a call from my friend saying his cimb click account can be logged in using consecutive numbers
when I tried it yup,mine oso kena

better fast fast change your password because the old one cannot be used anymore
yoyo_icecube
post Dec 17 2018, 02:57 AM

Getting Started
**
Junior Member
66 posts

Joined: Jul 2010
From: ipoh


QUOTE(aeiou228 @ Dec 17 2018, 02:07 AM)
Can you see your debit card in clicks? Mine hilang.
*
Where to check that? In web version is it? I haven’t use my debit card since then, n now only login via ios apps. Money still save.
faezpotato
post Dec 17 2018, 02:59 AM

Getting Started
**
Junior Member
80 posts

Joined: Apr 2014
QUOTE(derthvadar @ Dec 17 2018, 02:44 AM)
Kasi delete tweets.
*
Oledi delete tuan, hoping the OP that posted my tweet can also do the same


strace
post Dec 17 2018, 03:05 AM

Ayy
*****
Senior Member
700 posts

Joined: Aug 2005
can we finally have Fido U2F for malaysian banks now?
SUSIdiuU
post Dec 17 2018, 03:07 AM

Casual
***
Junior Member
346 posts

Joined: Apr 2017


QUOTE(leftycall9 @ Dec 17 2018, 02:56 AM)
just got a call from my friend saying his cimb click account can be logged in using consecutive numbers
when I tried it yup,mine oso kena

better fast fast change your password because the old one cannot be used anymore
*
pw 12345678 doesnt work on my acc...
so, does it mean im safe?
StarScream01
post Dec 17 2018, 03:08 AM

Getting Started
**
Junior Member
73 posts

Joined: Feb 2011
QUOTE(leftycall9 @ Dec 17 2018, 02:43 AM)
OMG!!!!

I just tried logged in using 12345678 it went straight into my account! the old password is useless now!

sudah changed tho. I used complex combination of numbers and characters hopefully it will be fine. balance still intact not much left because of Christmas shopping but damn you CIMB
*
Really KNN CIMB if what you said is true. Need to escalate to BNM
jimmyktp
post Dec 17 2018, 03:10 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(leftycall9 @ Dec 17 2018, 02:43 AM)
OMG!!!!

I just tried logged in using 12345678 it went straight into my account! the old password is useless now!

sudah changed tho. I used complex combination of numbers and characters hopefully it will be fine. balance still intact not much left because of Christmas shopping but damn you CIMB
*
Eh, sure or not.. don't think it is that weak... I tried on my acc, doesn't work.
jimmyktp
post Dec 17 2018, 03:13 AM

Getting Started
**
Junior Member
244 posts

Joined: Jun 2006
From: the bolehland..


QUOTE(strace @ Dec 17 2018, 03:05 AM)
can we finally have Fido U2F for malaysian banks now?
*
Haha, this time they will charge u RM16 as annual fee.. or maybe RM32. Fido keys are too expensive for implementation unless users buy themselves. But Banks cannot discriminate..
leftycall9
post Dec 17 2018, 03:16 AM

Left of leftist
******
Senior Member
1,046 posts

Joined: Jun 2010
QUOTE(StarScream01 @ Dec 17 2018, 03:08 AM)
Really KNN CIMB if what you said is true. Need to escalate to BNM
*
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/

QUOTE(jimmyktp @ Dec 17 2018, 03:10 AM)
Eh, sure or not.. don't think it is that weak... I tried on my acc, doesn't work.
*
it happened to mine and my friend's account. not sure about others but I have changed my password

azbro
post Dec 17 2018, 03:33 AM

Look at all my stars!!
*******
Senior Member
4,403 posts

Joined: Jan 2007
From: Johor Bahru


Tomorrow go ATM straight away take out cash

azbro
post Dec 17 2018, 03:35 AM

Look at all my stars!!
*******
Senior Member
4,403 posts

Joined: Jan 2007
From: Johor Bahru


Hey wait, my loan and Financing from Rm500,000 become 0 already, thank you thank you for helping me to pay.... Dream On...
NataM
post Dec 17 2018, 03:38 AM

New Member
*
Newbie
19 posts

Joined: Nov 2018


I already kena last 2 months. Got sms charged from Uber at 3am. Straight went Cimb change new card and account. Transaction was real.
haimirmaya
post Dec 17 2018, 03:38 AM

Getting Started
**
Junior Member
106 posts

Joined: May 2009
From: Penang


Pukimak fucking thru. Password + 12345678 is working.

I need to disable my clickaccount until this sort out!!!

Boy96
post Dec 17 2018, 03:41 AM

That's a tripod.
*******
Senior Member
3,848 posts

Joined: Dec 2009
From: Ampang


Great. Now suddenly my CIMB say need to reset password after I tried the password + 123456 trick..

Kenot even login already
UnknownH
post Dec 17 2018, 03:55 AM

Enthusiast
******
Senior Member
1,437 posts

Joined: Mar 2009
From: ME TO YOU



QUOTE(Boy96 @ Dec 17 2018, 03:41 AM)
Great. Now suddenly my CIMB say need to reset password after I tried the password + 123456 trick..

Kenot even login already
*
Sounds like good thing. Imagine if it actually worked. Someone might already took advantage of that.
cant think of a username
post Dec 17 2018, 03:57 AM

Getting Started
**
Junior Member
72 posts

Joined: Apr 2015
20k celery wei

kek
killerjeya
post Dec 17 2018, 04:04 AM

Getting Started
**
Junior Member
80 posts

Joined: Jun 2011


QUOTE(juneong @ Dec 17 2018, 03:22 AM)
my password need 34 thousand year to crack, is that secure ?
*
That site knows your password now, all they need is your username. If only there was a site to check how secure your username is xD

eddie2020
post Dec 17 2018, 04:04 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
*
QUOTE(haimirmaya @ Dec 17 2018, 03:38 AM)
Pukimak fucking thru. Password + 12345678 is working.

I need to disable my clickaccount until this sort out!!!
*
Only through apps? If website working or not
eddie2020
post Dec 17 2018, 04:13 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



I use any character plus 12345678 is not working.. So I am safe?
KuzumiTaiga
post Dec 17 2018, 04:17 AM

Spends too much time with mechanical keyboards
*******
Senior Member
3,317 posts

Joined: Jun 2008
From: Cheras ~ London WC1E 7HU~ Shenzhen



i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
eddie2020
post Dec 17 2018, 04:23 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



QUOTE(KuzumiTaiga @ Dec 17 2018, 04:17 AM)
i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
*
What the issue actually? My acc is new and my password is not 8 characters... So I shouldn't be affected rite? But I see they said those recapcha is other story?
olman
post Dec 17 2018, 04:26 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


Other bank got this problem?
olman
post Dec 17 2018, 04:27 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


QUOTE(KuzumiTaiga @ Dec 17 2018, 04:17 AM)
i think i kena, not too sure as i did not receive the SMSes, but my available balance is definitely far lower than I expected, and debit transactions don't update until at least 3~4 days later.

called CIMB call center, have been put on hold for 20 minutes, looks like they're really overloaded, even at this hour
*
Ur wangs kena ccuri?
See transaksi rekod to where

This post has been edited by olman: Dec 17 2018, 04:28 AM
eddie2020
post Dec 17 2018, 04:35 AM

Trusted
*******
Senior Member
3,125 posts

Joined: Jun 2008
From: Mars



Idk what is the problem after read so long.. How the hack take place? The recapcha ntg, I saw it and I didn't click or do anything.. I just use desktop go website n try simple password my acc still secure till I use my own password I only able login.. So I logged in will my password leak? Lol
lemon5969
post Dec 17 2018, 04:38 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



Lel try login with that exploit using webpage also could work just now..
EatFriesEggs
post Dec 17 2018, 04:43 AM

Getting Started
**
Junior Member
91 posts

Joined: Oct 2018
QUOTE(haimirmaya @ Dec 17 2018, 03:38 AM)
Pukimak fucking thru. Password + 12345678 is working.

I need to disable my clickaccount until this sort out!!!
*
But the hacker has to resolve the "Password" part of the equation first right?
sharpman
post Dec 17 2018, 04:44 AM

Veteran LYN Forumer
******
Senior Member
1,110 posts

Joined: Jan 2003



After i changed my password to complex password now I cannot login with the password trick anymore.

Still considering moving my money out of CIMB for now
DuitNow
post Dec 17 2018, 04:49 AM

On my way
****
Junior Member
597 posts

Joined: Oct 2018
QUOTE(aku_ker @ Dec 17 2018, 01:32 AM)
The only issue is you can type your password + random numbers and able to login.it takes more than that to transfer money to unknown account.
For Maybank u know right you can withdraw money without ATM card.

Anyway it's a security flaw and cimb should announce and take action.
*
Can explain more on the above? blink.gif

QUOTE(Jibbynomo @ Dec 17 2018, 01:38 AM)
For me i noticed now transfer money also no need any tac for verification. Crazy. So if they masuk someone acc and no need tac verify... Thats it
*
Which bank can do that? blink.gif

QUOTE(hor @ Dec 17 2018, 02:14 AM)
My wild guess:
1) Business: ok guys we need to remove the 8 char pw limitation
2) Tester: wth I used to type the same but now couldn't login
3) Dev: that's easy, we just attempt login with full input and if cant we try again with first 8 char only

*roll out*

4) Customer: wth I can login with extra junk char
5) Dev: (*oh shit)
*
laugh.gif laugh.gif laugh.gif

QUOTE(teehk_tee @ Dec 17 2018, 02:22 AM)
Cant they void all the old passwords and force customers to update new pw upon login? Many brokerages do this.

Not allow 8char + whatever shit to login.
*
Maybank actually do this a couple of months ago, I was force to change my password a couple of times. Probably kena... hmm.gif

QUOTE(leftycall9 @ Dec 17 2018, 03:16 AM)
CIMB didn't send any warning or anything about this through message or announcement. yeah I'm really pissed :/
it happened to mine and my friend's account. not sure about others but I have changed my password
*
What! blink.gif Password : 12345678 can log into your accounts? doh.gif
leymahn
post Dec 17 2018, 04:50 AM

Getting Started
**
Junior Member
150 posts

Joined: Mar 2008


can someone uodate the first post regarding what to do with this case. wake up 4.30am and read all this shit up.
sharpman
post Dec 17 2018, 04:54 AM

Veteran LYN Forumer
******
Senior Member
1,110 posts

Joined: Jan 2003



QUOTE(leymahn @ Dec 17 2018, 04:50 AM)
can someone uodate the first post regarding what to do with this case. wake up 4.30am and read all this shit up.
*
TLDR: if your password is a simple password, change to complex password (UPPER CASE + lower case + NUMBER + special character) then your login is safe

leymahn
post Dec 17 2018, 04:55 AM

Getting Started
**
Junior Member
150 posts

Joined: Mar 2008


QUOTE(sharpman @ Dec 17 2018, 04:54 AM)
TLDR: if your password is a simple password, change to complex password (UPPER CASE + lower case + NUMBER + special character) then your login is safe
*
okay thanx
nxfx
post Dec 17 2018, 05:18 AM

Enthusiast
*****
Senior Member
979 posts

Joined: Jan 2003


from my what i understand.
CIMB put limit of 8 characters long password, but on their login page their password text box can input more than 8.
So when people key in their password + random characters, they still can login.
BUT technically correct cos the system only check the first 8 characters which is their password.
BUT logically is wrong cos anything you key in is not the same as your password EVEN with extra character is considered wrong.
eg,
apple123 is not the same as apple123456

imma rite????



facktura
post Dec 17 2018, 05:39 AM

Regular
******
Senior Member
1,566 posts

Joined: Jun 2013


wanna log in via browser but already ask to click captcha, sked to proceed.

so how now to change log in and change new password???
:3mushy:3
post Dec 17 2018, 05:42 AM

<--~(--+<[o]>+--)~-->
*******
Senior Member
4,723 posts

Joined: Apr 2008
QUOTE(red1982 @ Dec 17 2018, 02:46 AM)
For those who wants to know whether your password are secure .. test it here  https://howsecureismypassword.net/
*
It would take a computer about

93 TRILLION YEARS

Kek
kinglau66
post Dec 17 2018, 05:45 AM

New Member
*
Junior Member
5 posts

Joined: Oct 2010
From: Sarawak


QUOTE(:3mushy:3 @ Dec 17 2018, 05:42 AM)
It would take a computer about

93 TRILLION YEARS

Kek
*
It take mine 1 hour because of cimb 8 character limit, so there's that
sharpman
post Dec 17 2018, 05:46 AM

Veteran LYN Forumer
******
Senior Member
1,110 posts

Joined: Jan 2003



QUOTE(kinglau66 @ Dec 17 2018, 05:45 AM)
It take mine 1 hour because of cimb 8 character limit, so there's that
*
now can update to complex password with more than 8 characters already. do it now
vin_ann
post Dec 17 2018, 05:47 AM

10k Club
********
All Stars
10,912 posts

Joined: Feb 2006
UPDATE: We stumbled upon a tweet by ZDnet security reporter, Catalin Cimpanu, which alleged that a hacker might have obtained a large stash of card numbers. We can’t verify if this is related to the current CIMB Clicks issue.

https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/

Also about CIMB hacks
UnknownH
post Dec 17 2018, 06:06 AM

Enthusiast
******
Senior Member
1,437 posts

Joined: Mar 2009
From: ME TO YOU



QUOTE(DuitNow @ Dec 17 2018, 04:49 AM)
Can explain more on the above? blink.gif
Which bank can do that? blink.gif
laugh.gif  laugh.gif  laugh.gif
Maybank actually do this a couple of months ago, I was force to change my password a couple of times. Probably kena... hmm.gif
What! blink.gif  Password : 12345678 can log into your accounts? doh.gif
*
It's a feature actually. Not sure other banks offer this as well.

https://www.soyacincau.com/2014/01/27/forgo...ess-withdrawal/
haimirmaya
post Dec 17 2018, 06:07 AM

Getting Started
**
Junior Member
106 posts

Joined: May 2009
From: Penang


QUOTE(EatFriesEggs @ Dec 17 2018, 05:43 AM)
But the hacker has to resolve the "Password" part of the equation first right?
*
I dont want to take any risk. If them can add the password. They can change it too. Its just matter of time!

Bye2.. my money already moved to rimau..
jishu
post Dec 17 2018, 06:22 AM

Getting Started
**
Junior Member
289 posts

Joined: Apr 2016
QUOTE(EatFriesEggs @ Dec 17 2018, 04:43 AM)
But the hacker has to resolve the "Password" part of the equation first right?
*
Yes. The hacker get the first 8 characters through Brute-force attack.
CIMB implemented the CAPTCHA to delay/slow down the attack
Spectreoutreach
post Dec 17 2018, 06:25 AM

Enthusiast
*****
Senior Member
856 posts

Joined: Jan 2008


user posted image
user posted image
user posted image - https://m.facebook.com/story.php?story_fbid...100000746122106
jishu
post Dec 17 2018, 06:30 AM

Getting Started
**
Junior Member
289 posts

Joined: Apr 2016
Motherf*cker it has been more than 7-8 hours since lowyat amanz and soyacincau post about this but the FLAW IS STILL THERE!!!

I CAN STILL LOGIN with my 8 characters + ANYTHING bangwall.gif bangwall.gif

Their IT/Vendor do nothing ke? bangwall.gif bangwall.gif

BTW, the flaw for that password is called buffer overflow.
Read here: https://en.wikipedia.org/wiki/Buffer_overflow
jinaun
post Dec 17 2018, 06:30 AM

where are my stars???
Group Icon
Elite
6,139 posts

Joined: Jan 2003
QUOTE(jishu @ Dec 17 2018, 06:22 AM)
Yes. The hacker get the first 8 characters through Brute-force attack.
CIMB implemented the CAPTCHA to delay/slow down the attack
*
isn't 3 times wrong password will lock the login id?
Muhammad Syukri
post Dec 17 2018, 06:50 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
https://www.nst.com.my/news/crime-courts/20...-back-data-lost

Guys rhe issues is not about the password.

The real issue is that our bank information has been leaked , they do not use cimbclicks to hack your money but just through your card info link to paypal.

TSpeja5081
post Dec 17 2018, 06:54 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Muhammad Syukri @ Dec 17 2018, 06:50 AM)
https://www.nst.com.my/news/crime-courts/20...-back-data-lost

Guys rhe issues is not about the password.

The real issue is that our bank information has been leaked , they do not use cimbclicks to hack your money but just through your card info link to paypal.
*
From pokde
https://pokde.net/news/cimb-clicks-facing-m...security-flaws/
EVA MENDES
post Dec 17 2018, 06:56 AM

Getting Started
**
Junior Member
64 posts

Joined: Nov 2010
Hopefully cimb will solve this asap....tomorrow is salary day for gomen people.
maxpudding
post Dec 17 2018, 07:07 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Muhammad Syukri @ Dec 17 2018, 06:50 AM)
https://www.nst.com.my/news/crime-courts/20...-back-data-lost

Guys rhe issues is not about the password.

The real issue is that our bank information has been leaked , they do not use cimbclicks to hack your money but just through your card info link to paypal.
*
If it’s not about the password, then why implement the captcha?

Be safe than sorry
briantwj
post Dec 17 2018, 07:13 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Wadapak. I already reset my password B4 I sleep. Now.j login. It ask me to reset again????

Anyone facing same issue?
maxpudding
post Dec 17 2018, 07:14 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(Davez89 @ Dec 17 2018, 02:21 AM)
I have 10 ringgit in my account omg
*
Tipu, cimb minimum limit is 20
Muhammad Syukri
post Dec 17 2018, 07:15 AM

Enthusiast
*****
Senior Member
821 posts

Joined: Mar 2009
QUOTE(maxpudding @ Dec 17 2018, 07:07 AM)
If it’s not about the password, then why implement the captcha?

Be safe than sorry
*
Yea it not just because of cimb click this gotta be related to the missing tape last year but cimb denied that the tape consist of customers information.
Spectreoutreach
post Dec 17 2018, 07:17 AM

Enthusiast
*****
Senior Member
856 posts

Joined: Jan 2008


Macam ini just cut off your card and resort to old fashioned withdraw counter
TSpeja5081
post Dec 17 2018, 07:19 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Muhammad Syukri @ Dec 17 2018, 07:15 AM)
Yea it not just because of cimb click this gotta be related to the missing tape last year but cimb denied that the tape consist of customers information.
*
Problem is hacker just can brute force for password to log in.
TSpeja5081
post Dec 17 2018, 07:20 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Spectreoutreach @ Dec 17 2018, 07:17 AM)
Macam ini just cut off your card and resort to old fashioned withdraw counter
*
Lucky i dont activate online transaction for debit card
maxpudding
post Dec 17 2018, 07:21 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(briantwj @ Dec 17 2018, 07:13 AM)
Wadapak. I already reset my password B4 I sleep. Now.j login. It ask me to reset again????

Anyone facing same issue?
*
Nope
zamans98
post Dec 17 2018, 07:21 AM

oquıɐɹ ǝɥ ɹǝo 'ǝɹǝɥǝɯos
*******
Senior Member
8,510 posts

Joined: Dec 2004
From: KayEL


can login via apps without need of password
Thrust
post Dec 17 2018, 07:23 AM

Power To The People!!!
*******
Senior Member
3,760 posts

Joined: Oct 2005


QUOTE(zamans98 @ Dec 17 2018, 07:21 AM)
can login via apps without need of password
*
That is to view balance only. If you transfer money, password will be required.
lemon5969
post Dec 17 2018, 07:27 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



user posted image twitter posted 12 december, now 17 december, aumm
maxpudding
post Dec 17 2018, 07:35 AM

Getting Started
**
Junior Member
164 posts

Joined: Mar 2007
QUOTE(lemon5969 @ Dec 17 2018, 07:27 AM)
user posted image twitter posted 12 december, now 17 december, aumm
*
Yeah, looking back, the paypal-cimb unauthorized transactions started around that time
piringkosong
post Dec 17 2018, 07:37 AM

Getting Started
**
Junior Member
50 posts

Joined: Nov 2012
went to cimb atm. It didnt allow me to withdraw any money. The f is goin on wei
alexander3133
post Dec 17 2018, 07:40 AM

Regular
******
Senior Member
1,716 posts

Joined: May 2006
From: JDT


QUOTE(piringkosong @ Dec 17 2018, 07:37 AM)
went to cimb atm. It didnt allow me to withdraw any money. The f is goin on wei
*
Fuh, macam damage control.
kona|kona
post Dec 17 2018, 07:43 AM

arsengal u jelly【ツ】
*****
Senior Member
759 posts

Joined: Jan 2011
From: Izumi's Residence
lucky i withdraw money yesterday
now cimb no balance. not login into apps too
piringkosong
post Dec 17 2018, 07:43 AM

Getting Started
**
Junior Member
50 posts

Joined: Nov 2012
QUOTE(alexander3133 @ Dec 17 2018, 07:40 AM)
Fuh, macam damage control.
*
Ya wei. Theres no withdraw. Just check balance and all. Im checking other cimb atm later
IvanWong1989
post Dec 17 2018, 07:58 AM

!StringTheory!
*******
Senior Member
4,297 posts

Joined: Jul 2009



Hmm..
I didn't login or access my CIMB account since few days ago. What should I do now? To safeguard my account . . .
djhenry91
post Dec 17 2018, 07:59 AM

Slow and Steady
*******
Senior Member
6,779 posts

Joined: Jan 2009
From: SEGI Heaven


I still remember someone talk about this not sure related.. On cimb credit card thread.. I think he delete it..
CeDhhVss
post Dec 17 2018, 08:03 AM

Getting Started
**
Junior Member
92 posts

Joined: Jun 2012
From: hurr-durr


waaaaaaaaaaaaat
Revamperz
post Dec 17 2018, 08:05 AM

im freaking IN! ™
*******
Senior Member
5,164 posts

Joined: Jan 2003


even log in isnt need tac to transfer?
marche
post Dec 17 2018, 08:06 AM

Casual
***
Junior Member
392 posts

Joined: Jun 2008
From: BATU PAHAT


QUOTE(Revamperz @ Dec 17 2018, 08:05 AM)
even log in isnt need tac to transfer?
*
They will link ur account to paypal

Then no need tac anymore
lemon5969
post Dec 17 2018, 08:07 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



QUOTE(piringkosong @ Dec 17 2018, 07:37 AM)
went to cimb atm. It didnt allow me to withdraw any money. The f is goin on wei
*
Seriously...im faking cashless weyhhh
cyhborg
post Dec 17 2018, 08:07 AM

New Member
*
Junior Member
26 posts

Joined: Jul 2007


just changed my password. the old one first 8 digits + whatever can masuk sweat.gif

This post has been edited by cyhborg: Dec 17 2018, 08:07 AM
99FoxDemon
post Dec 17 2018, 08:08 AM

New Member
*
Junior Member
23 posts

Joined: Mar 2006
From: East Coast of Cuba.


wan to transfer money out, they block already in maintenance mode from 16-17?
SUSalexcky
post Dec 17 2018, 08:08 AM

business Sifu
*****
Senior Member
842 posts

Joined: Nov 2007


Shxt.. Was thinking of register PayPal for oversea transactions

Now have to think of other method
TSpeja5081
post Dec 17 2018, 08:09 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(IvanWong1989 @ Dec 17 2018, 07:58 AM)
Hmm..
I didn't login or access my CIMB account since few days ago. What should I do now? To safeguard my account . . .
*
"If you’re a CIMB Clicks customer, it is advisable to check if you have any suspicious transactions. If you received SMS notifications for transactions you didn’t make, do contact your bank immediately so that they can block your card or account from further abuse. "-soyacincau
olman
post Dec 17 2018, 08:14 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


Cimb going refund all the money lost or yall bear it?
lemon5969
post Dec 17 2018, 08:15 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



Just found this

RM0.00 No more waiting for SMS TAC! Update your CIMB Clicks app now in Google Play Store/Apple App Store to enjoy easy, secure one-tap approval for your mobile app transaction. More info: https://www.cimbclicks.com.my/securetac

15 december 12.36

So dont have sms tac ya? Btw my fon cant use cimb apps. Its detect root lel
ze2
post Dec 17 2018, 08:18 AM

Casual
***
Junior Member
318 posts

Joined: Nov 2011
QUOTE(jishu @ Dec 17 2018, 06:30 AM)
Motherf*cker it has been more than 7-8 hours since lowyat amanz and soyacincau post about this but the FLAW IS STILL THERE!!!

I CAN STILL LOGIN with my 8 characters + ANYTHING  bangwall.gif  bangwall.gif

Their IT/Vendor do nothing ke?  bangwall.gif  bangwall.gif

BTW, the flaw for that password is called buffer overflow.
Read here: https://en.wikipedia.org/wiki/Buffer_overflow
*
Can't 100% blame IT.

Security team and mgmt should be accountable as well.
NubPro
post Dec 17 2018, 08:18 AM

Casual
***
Junior Member
397 posts

Joined: Apr 2012


QUOTE(lemon5969 @ Dec 17 2018, 08:15 AM)
Just found this

RM0.00 No more waiting for SMS TAC! Update your CIMB Clicks app now in Google Play Store/Apple App Store to enjoy easy, secure one-tap approval for your mobile app transaction. More info: https://www.cimbclicks.com.my/securetac

15 december 12.36

So dont have sms tac ya? Btw my fon cant use cimb apps. Its detect root lel
*
use magisk bro
khainiz94
post Dec 17 2018, 08:19 AM

Look at all my stars!!
*******
Senior Member
2,856 posts

Joined: Mar 2012


Well nasib baik I don't have an account with them.
But damn now I need to assist my parents to change PW and transfer their money to a diff account for a moment.
I knew this CIMB Bank should not be trusted.
Got so many issues crop up recently.
coolguy99
post Dec 17 2018, 08:20 AM

Look at all my stars!!
*******
Senior Member
7,351 posts

Joined: Aug 2015



It's fixed already?
hirano
post Dec 17 2018, 08:21 AM

凸(`△´#)
*******
Senior Member
3,335 posts

Joined: Nov 2007
From: Pluto


QUOTE(ze2 @ Dec 17 2018, 08:18 AM)
Can't 100% blame IT.

Security team and mgmt should be accountable as well.
*
Security is part of IT dept.

I browsed cimb's twitter and fb, still they wont mention any shit about the issue. If 1st world country, they would have made press release and apologize.
phillip88
post Dec 17 2018, 08:22 AM

Sound of Silence
******
Senior Member
1,062 posts

Joined: Dec 2011
From: (╯°□°)╯︵ ┻━┻)



I just withdrawn money using other bank's ATM. Spent RM1 fee and it went through.

So, there's that.
Quantum Geist
post Dec 17 2018, 08:23 AM

Getting Started
**
Junior Member
109 posts

Joined: May 2013


QUOTE(hirano @ Dec 17 2018, 08:21 AM)
Security is part of IT dept.

I browsed cimb's twitter and fb, still they wont mention any shit about the issue. If 1st world country, they would have made press release and apologize.
*
I didn't catch anything on bfm news either, seems like there are still people who aren't aware of this case yet
lemon5969
post Dec 17 2018, 08:26 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



QUOTE(Quantum Geist @ Dec 17 2018, 08:23 AM)
I didn't catch anything on bfm news either, seems like there are still people who aren't aware of this case yet
*
I believe They aware but they want to control the branding name..at the end they should apologize..they not announce because still dont have solution?

This post has been edited by lemon5969: Dec 17 2018, 08:32 AM
hirano
post Dec 17 2018, 08:26 AM

凸(`△´#)
*******
Senior Member
3,335 posts

Joined: Nov 2007
From: Pluto


QUOTE(phillip88 @ Dec 17 2018, 08:22 AM)
I just withdrawn money using other bank's ATM. Spent RM1 fee and it went through.

So, there's that.
*
I'm hesitating to login to cimb clicks now. Probably i'll withdraw from atm too. But i expect queue will be shit long.
olman
post Dec 17 2018, 08:27 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


QUOTE(khainiz94 @ Dec 17 2018, 08:19 AM)
Well nasib baik I don't have an account with them.
But damn now I need to assist my parents to change PW and transfer their money to a diff account for a moment.
I knew this CIMB Bank should not be trusted.
Got so many issues crop up recently.
*
Bijan is not amused
John Chaser
post Dec 17 2018, 08:27 AM

On my way
****
Junior Member
685 posts

Joined: Sep 2005


Mainstream press are either ignoring it or this must be quite common among our banks.
bereev
post Dec 17 2018, 08:28 AM

Getting Started
**
Junior Member
257 posts

Joined: Dec 2011
ranting.gif
Cimb i am gonna stop all ur credit card , statement send via email also take so long some time no send at all what the fark is cimb staff doing
vin_ann
post Dec 17 2018, 08:29 AM

10k Club
********
All Stars
10,912 posts

Joined: Feb 2006
QUOTE(coolguy99 @ Dec 17 2018, 08:20 AM)
It's fixed already?
*
So far cimb no issue official statement ...


hirano
post Dec 17 2018, 08:29 AM

凸(`△´#)
*******
Senior Member
3,335 posts

Joined: Nov 2007
From: Pluto


QUOTE(lemon5969 @ Dec 17 2018, 08:26 AM)
They aware but they want to control the branding name..at the end they should apologize..they not announce because still dont have solution?
*
Control branding name at the expense of customers money? Hah. Has minister GOBIND been notified yet?

Lost my trust to cimb. Will withdraw my money out and park elsewhere.
prozdennis
post Dec 17 2018, 08:30 AM

Getting Started
**
Junior Member
127 posts

Joined: May 2017
I try ady.. i input my own password then behind add in any number, it still went in.. once i change the CIMB clicks password, then cannot already.. faster change your CIMB clicks password guys..
lemon5969
post Dec 17 2018, 08:31 AM

Casual
***
Junior Member
412 posts

Joined: May 2009



QUOTE(NubPro @ Dec 17 2018, 08:18 AM)
use magisk bro
*
I used magisk manager but still detected.. or in samsung they detect by knox?
olman
post Dec 17 2018, 08:32 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


QUOTE(hirano @ Dec 17 2018, 08:21 AM)
Security is part of IT dept.

I browsed cimb's twitter and fb, still they wont mention any shit about the issue. If 1st world country, they would have made press release and apologize.
*
Cum hr i tolong
Internal IT secu team is only there to maintain n administer
They know not 100% of said sistem perisian.

Aktual sistem implementer is 3rd party vendor in fin industri.

Tapi sy stuju that cimb kept mum is unethical
ze2
post Dec 17 2018, 08:32 AM

Casual
***
Junior Member
318 posts

Joined: Nov 2011
QUOTE(hirano @ Dec 17 2018, 08:21 AM)
Security is part of IT dept.

I browsed cimb's twitter and fb, still they wont mention any shit about the issue. If 1st world country, they would have made press release and apologize.
*
Well, as I mentioned in my previous post, they indeed were pretty clueless and slow to act.

I guess that prompted many making the jump to other banks.
briantwj
post Dec 17 2018, 08:33 AM

Pierluigi Collina
*******
Senior Member
3,968 posts

Joined: Sep 2012


Feck.. mine acting weird. I reset my password y'day B4 I sleep. Now I login. It ask me to update password again. Hmm. Fishy.
olman
post Dec 17 2018, 08:35 AM

Regular
******
Senior Member
1,998 posts

Joined: Jan 2003


So ahh DuitNOW can caya?

Amacam

4 Pages  1 2 3 > » Top
 

Change to:
| Lo-Fi Version
0.1051sec    0.47    6 queries    GZIP Disabled
Time is now: 10th December 2025 - 04:10 AM