Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
Rhetoric
post Dec 17 2018, 11:34 AM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(PhakFuhZai @ Dec 17 2018, 11:29 AM)
i think google, spotify, netflix etc doesn't ask for TAC either

its just not the angmoh culture, also due to the cc fraud is lower in the western world
*
also like the guy above said, alipay also didnt ask for TAC. i bought alot of stuff from taobao never once ask for TAC.
Rhetoric
post Dec 17 2018, 01:14 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
Did CIMB ever give PSA for their customer to change password?.

Rhetoric
post Dec 17 2018, 01:17 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
if this is coding issue, what this got anthing to do with the CAPTCHA people talking about?.
Rhetoric
post Dec 17 2018, 01:30 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(BuLaDiFu @ Dec 17 2018, 01:18 PM)
But its better to change your password to something longer though.

Think someone linked a website just now and it said an 8 character password only needs 8 hours to break.
*
Thats the thing, as an account holder i received zero communication from CIMB regarding this issue. the first i heard about the news is from Lowyat FB page and constant info from this thread. Official CIMB = 0


Rhetoric
post Dec 17 2018, 01:39 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(linkinstreet @ Dec 17 2018, 01:22 PM)
Some people were using bots to bruteforce password, since CIMB has no failed login limits. The CAPTCHA was supposed to slow the bots down
*
then the captcha is no issue la.
Rhetoric
post Dec 17 2018, 07:39 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(TheEvilMan @ Dec 17 2018, 07:35 PM)
THE ISSUE ONLY TOWARD CREDIT CARD OR ACCOUNT TOO?
*
ACCOUNT, READ THE NEW LOWYAT POST FROM FRONTPAGE HERE


Rhetoric
post Dec 18 2018, 01:13 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(sniper msia @ Dec 18 2018, 01:02 PM)
This entire fiasco is really kind of like 'making a mountain out of a molehill'.

Honestly, I was just as worried as you guys initially. First thing in the morning, i went to the CIMB branch near my workplace just to double check my balance with the branch staff (in addition to what I have already checked via CIMB Clicks), and there really was no issue at all. My money, thankfully, is still intact, so to speak.

If the problem was as bad as what some articles are saying, the police stations would have long queues already of people making reports! biggrin.gif
*
CIMB should just sue Vijandren, hes the one that broke the stoli. ohwai, they dont dare because its true.
Rhetoric
post Dec 18 2018, 01:17 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(okuribito @ Dec 18 2018, 01:03 PM)
Something doesn't seem right to me. Everywhere I look, I'm told that passwords are stored after (one-way) hashing (& even salting), never in its original form.

When you originally set up your password as 12345678H%&*GGhklp, it would have been stored as a certain hash. Any slight diff would result in a totally diff hash. (That's why they say they do not know what your password is)

So what boggles me is how someone can get in when he submits 12345678 - the hash for that would definitely be diff from the hash for 12345678H%&*GGhklp ...No?

The only possibility this can happen is IF at the point you originally set up your password as 12345678H%&*GGhklp, it was truncated to 12345678... damn FUBAR, right? Telling ppl to set up long complex pw & truncating to short
*
alot of Malaysia gov sites still save password as plain text. theres been more than one occasion where i forgot password and request for password they just email me the exact password i use instead of some random passkey.
Rhetoric
post Dec 18 2018, 10:33 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
inb4 use Huawei phone.
Rhetoric
post Dec 20 2018, 09:35 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(heinlein @ Dec 20 2018, 04:14 PM)
https://www.facebook.com/113376605363982/po...999957/?app=fbl

You scroll down and find kc chan's comment

user posted image
user posted image
*
This kind of case is old. Not just cimb but alot of other banks where the owner not carefull enuf to take care of their card.
Rhetoric
post Dec 20 2018, 09:54 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(heinlein @ Dec 20 2018, 09:37 PM)
No missing physical card involved.
*
It doesnt have to be missing.
Rhetoric
post Dec 21 2018, 12:12 PM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(khainiz94 @ Dec 21 2018, 09:46 AM)
I think it is not related to users carelessness.
I think there is some data leak happened inside CIMB or related to the data backups lost last year.
My two friends kena with PayPal unauthorised transaction amounting more than RM100.
And the worst part, you need to pay to replace your card eventhough it is not your fault.
It is not cheap at all.

And just want to tell you someone did post on Twitter that some hacker spam message and is looking to find partner to cash out money from CIMB.
*
Ughh i hate when people just jumped in other people converstation without knowing the issue they are talking about.

Paypal abuse you dont have to argue with me, i know its happening. That guy is posting the TAC issue. Paypal dont use TAC.
Rhetoric
post Apr 4 2020, 08:07 AM

On my way
****
Junior Member
553 posts

Joined: Mar 2018
QUOTE(kyLL @ Jan 1 2019, 08:53 PM)
This is a good read. thanks for sharing.

 

Change to:
| Lo-Fi Version
0.0520sec    0.46    7 queries    GZIP Disabled
Time is now: 10th December 2025 - 09:32 AM