They should learn from Maybank. Maybank has the best mobile apps for now.
PBB is shit. CIMB is shit.
Chat CIMB kena hack?
Chat CIMB kena hack?
|
|
Dec 16 2018, 11:50 PM
Return to original view | IPv6 | Post
#1
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
They should learn from Maybank. Maybank has the best mobile apps for now.
PBB is shit. CIMB is shit. |
|
|
|
|
|
Dec 16 2018, 11:55 PM
Return to original view | IPv6 | Post
#2
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 12:43 AM
Return to original view | IPv6 | Post
#3
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 12:46 AM
Return to original view | IPv6 | Post
#4
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
Just change your password guys.
Your old password + any numbers or alphabets can go in weh. But then hackers need to know your old password la else also no use cannot go in. I just changed mine and now okay adi. |
|
|
Dec 17 2018, 12:47 AM
Return to original view | IPv6 | Post
#5
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
QUOTE(LaiN87 @ Dec 17 2018, 12:46 AM) This is an issue but I don’t think this issue is what is important? Yea don't think it's a big concern since the hacker would need to know the first 8 characters correctly. But then it's still so fuckup to know it works as well with 8 characters + any random characters.In order for the hacker to go into your account it still needs to get the first 8 char correctly. Is this the video that is circulating in WhatsApp? |
|
|
Dec 17 2018, 01:03 PM
Return to original view | Post
#6
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
QUOTE(OldSchoolJoke @ Dec 17 2018, 01:01 PM) if i read correctly, Lu coders ke? You are correcto.if password following the new format (have special characters and more or equal to 8 characters) then password will be as it is else if old password format (8 characters), it will only take first 8 characters. any characters behind don't care..kena chopped Ini code macam intern buat weh. |
|
|
|
|
|
Dec 17 2018, 01:19 PM
Return to original view | Post
#7
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
This is because when they changed the password policy to include special characters, they didn't force everyone to change their password.
Therefore they have to cater logic for old password logic and also new password logic. But to implement it in this half ass way is plain stupid. This is not some wordpress blog yo. This is a fucking bank. #programmingtalk |
|
|
Dec 17 2018, 01:20 PM
Return to original view | Post
#8
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
Also, not sure if somebody mentioned before...using Google captcha...which genius thought of that way to do it? Limit the times of failed transaction or use phone secure SMS or TAC la adui.
This post has been edited by Duckies: Dec 17 2018, 01:20 PM |
|
|
Dec 17 2018, 01:21 PM
Return to original view | Post
#9
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
So head siapa yang akan roll on the ground? Sure somebody kena eat the dead cat and take the blame. Head of IT?
|
|
|
Dec 17 2018, 01:25 PM
Return to original view | Post
#10
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
QUOTE(Mummy Shark @ Dec 17 2018, 01:23 PM) sebab itu diorang gunakan kelemahan CIMB So how did they managed to hack into user in the first place? Memang brute force password ke? Even though with that, they still need the USER ID.DAN paypal. sebab paypal memang tak support TAC, 3D Secure, whatever. asalkan boleh lepas card number DAN optional CVV paypal will keep on charging when requested. |
|
|
Dec 17 2018, 01:25 PM
Return to original view | Post
#11
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 01:27 PM
Return to original view | Post
#12
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 01:37 PM
Return to original view | Post
#13
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
QUOTE(HMMaster @ Dec 17 2018, 01:35 PM) The CAPTCHA is just a temporary solution... doubt that they can do a major change in a day. Modifying the system in such a short time might introduce more security flaws if not tested properly. No excuse for that weh. CIMB is not the first day to have e-banking liao. Should have thought of the prevention way before it happens. Not only when hackers knock on the door then only implement some short term solution.But CIMB should've implemented the login attempt limit or 2 factor authentication. |
|
|
|
|
|
Dec 17 2018, 01:42 PM
Return to original view | Post
#14
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 01:48 PM
Return to original view | Post
#15
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 01:51 PM
Return to original view | Post
#16
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 02:26 PM
Return to original view | Post
#17
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 02:32 PM
Return to original view | Post
#18
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 02:36 PM
Return to original view | Post
#19
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
|
|
|
Dec 17 2018, 02:40 PM
Return to original view | Post
#20
|
![]() ![]() ![]() ![]() ![]() ![]() ![]()
Senior Member
9,796 posts Joined: Jun 2008 From: Rubber Duck Pond |
QUOTE(OldSchoolJoke @ Dec 17 2018, 02:37 PM) if got special characters and >= 8 characters, it will pass to server as it is else it will chop off after 8 characters. topkek betul. that's why your password + any characters behind still can pass QUOTE(rooney723 @ Dec 17 2018, 02:38 PM) yup i noe, then that means even the logic of the code is wrong? suppose if the legacy server side only accept max 8 characters then the client side is only suppose to accept 8 chars n below n substring the pass wif > 8 chars Refer to OldSchoolJoke.Because they need to cater for old password format which is without special characters. And also because they need to cater for new password with special characters. Thus this retarded logic. This post has been edited by Duckies: Dec 17 2018, 02:44 PM |
| Change to: | 0.0207sec
0.66
7 queries
GZIP Disabled
Time is now: 11th December 2025 - 01:51 AM |