Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
Duckies
post Dec 16 2018, 11:50 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


They should learn from Maybank. Maybank has the best mobile apps for now.

PBB is shit. CIMB is shit.
Duckies
post Dec 16 2018, 11:55 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(xpole @ Dec 16 2018, 11:52 PM)
PBB online banking for dekstop version is not for human use one.

So shit
*
Ya man. PBB app lagi teruk. Maybank app and website is the best. CIMB website is second but their app is shit. PBB is the worst among all.
Duckies
post Dec 17 2018, 12:43 AM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(HolySatan @ Dec 17 2018, 12:41 AM)
user posted image

dah kantoi since morning
*
Just tested. This is so fucking legit man. Pls change ur password guys.
Duckies
post Dec 17 2018, 12:46 AM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


Just change your password guys.

Your old password + any numbers or alphabets can go in weh.

But then hackers need to know your old password la else also no use cannot go in.

I just changed mine and now okay adi.
Duckies
post Dec 17 2018, 12:47 AM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(LaiN87 @ Dec 17 2018, 12:46 AM)
This is an issue but I don’t think this issue is what is important?

In order for the hacker to go into your account it still needs to get the first 8 char correctly.

Is this the video that is circulating in WhatsApp?
*
Yea don't think it's a big concern since the hacker would need to know the first 8 characters correctly. But then it's still so fuckup to know it works as well with 8 characters + any random characters.
Duckies
post Dec 17 2018, 01:03 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(OldSchoolJoke @ Dec 17 2018, 01:01 PM)
if i read correctly,

if password following the new format (have special characters and more or equal to 8 characters) then password will be as it is

else if old password format (8 characters), it will only take first 8 characters. any characters behind don't care..kena chopped
*
Lu coders ke? You are correcto.

Ini code macam intern buat weh.
Duckies
post Dec 17 2018, 01:19 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


This is because when they changed the password policy to include special characters, they didn't force everyone to change their password.

Therefore they have to cater logic for old password logic and also new password logic.

But to implement it in this half ass way is plain stupid. This is not some wordpress blog yo. This is a fucking bank.

#programmingtalk
Duckies
post Dec 17 2018, 01:20 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


Also, not sure if somebody mentioned before...using Google captcha...which genius thought of that way to do it? Limit the times of failed transaction or use phone secure SMS or TAC la adui.

This post has been edited by Duckies: Dec 17 2018, 01:20 PM
Duckies
post Dec 17 2018, 01:21 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


So head siapa yang akan roll on the ground? Sure somebody kena eat the dead cat and take the blame. Head of IT?
Duckies
post Dec 17 2018, 01:25 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(Mummy Shark @ Dec 17 2018, 01:23 PM)
sebab itu diorang gunakan kelemahan CIMB

DAN

paypal.

sebab paypal memang tak support TAC, 3D Secure, whatever.
asalkan boleh lepas card number DAN optional CVV paypal will keep on charging when requested.
*
So how did they managed to hack into user in the first place? Memang brute force password ke? Even though with that, they still need the USER ID.
Duckies
post Dec 17 2018, 01:25 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(linkinstreet @ Dec 17 2018, 01:23 PM)
Bukan ke their IT guy sudah lompat suicide?
*
Wa kesian, kena suicide to redeem himself/herself. Bukan as usual play the blame game ke?
Duckies
post Dec 17 2018, 01:27 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


https://www.nst.com.my/news/crime-courts/20...-back-data-lost
Duckies
post Dec 17 2018, 01:37 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(HMMaster @ Dec 17 2018, 01:35 PM)
The CAPTCHA is just a temporary solution... doubt that they can do a major change in a day. Modifying the system in such a short time might introduce more security flaws if not tested properly.

But CIMB should've implemented the login attempt limit or 2 factor authentication.
*
No excuse for that weh. CIMB is not the first day to have e-banking liao. Should have thought of the prevention way before it happens. Not only when hackers knock on the door then only implement some short term solution.
Duckies
post Dec 17 2018, 01:42 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(HMMaster @ Dec 17 2018, 01:40 PM)
nowadays a lot company want to simplify the login process... else the customer will complaint.
*
Ya man but look at the situation now...macam jadi more teruk. Compromises security for convenience. When money is related, security takes first ma.
Duckies
post Dec 17 2018, 01:48 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


Eh guys, CIMB UAT website is public?

http://uat.cimbclicks.com.my/
Duckies
post Dec 17 2018, 01:51 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(blackamikaze @ Dec 17 2018, 01:50 PM)
If u click login or register it still bring u to main website.
*
But UAT website can show to public?

Bukan for internal only ke?
Duckies
post Dec 17 2018, 02:26 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(PleaseEnterYourName @ Dec 17 2018, 02:24 PM)
cimb legacy system, only can handle 8 characters. So to create a front to able to use 20 characters this code was introduced.

But where seven found it?
*
Coded at the client side aka website there which by right should be at server side only.
Duckies
post Dec 17 2018, 02:32 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(rooney723 @ Dec 17 2018, 02:31 PM)
but i checked the code the logic says it will accept the password if its more than 8 characters and if the password is less than 8 characters it will take the first 8 chars, or am i wrong?
*
There's the checking for special characters as well.
Duckies
post Dec 17 2018, 02:36 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(teehk_tee @ Dec 17 2018, 02:33 PM)
Absolute garbage security
*
Intern do mia work ke. Or India aneh do mia work. Where got verification done at client side there geh. Now whole world sees the dumb logic/code.
Duckies
post Dec 17 2018, 02:40 PM

Rubber Ducky
*******
Senior Member
9,796 posts

Joined: Jun 2008
From: Rubber Duck Pond


QUOTE(OldSchoolJoke @ Dec 17 2018, 02:37 PM)
if got special characters and >= 8 characters, it will pass to server as it is
else it will chop off after 8 characters.

topkek betul. that's why your password + any characters behind still can pass
*
QUOTE(rooney723 @ Dec 17 2018, 02:38 PM)
yup i noe, then that means even the logic of the code is wrong? suppose if the legacy server side only accept max 8 characters then the client side is only suppose to accept 8 chars n below n substring the pass wif > 8 chars
*
Refer to OldSchoolJoke.

Because they need to cater for old password format which is without special characters. And also because they need to cater for new password with special characters.

Thus this retarded logic.


This post has been edited by Duckies: Dec 17 2018, 02:44 PM

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0207sec    0.66    7 queries    GZIP Disabled
Time is now: 11th December 2025 - 01:51 AM