Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

Chat CIMB kena hack?

views
     
TSpeja5081
post Dec 16 2018, 10:20 PM, updated 6y ago

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
Update from cimb
https://www.thestar.com.my/news/nation/2018...-all-is-secure/

Update from lowyat.com
https://www.lowyat.net/2018/175102/what-cim...you-but-should/


CIMB Clicks ‘kena hacked’ concern: Here are 4 things you need to know
Cimb Faq about recaptcha:
https://www.cimbclicks.com.my/pdf/201812-Cl...-Public-FAQ.pdf
QUOTE(HolySatan @ Dec 17 2018, 02:42 PM)
user posted image

user posted image

user posted image
*
Hack story
https://m.facebook.com/story.php?story_fbid...100000746122106

https://m.facebook.com/story.php?story_fbid...100000339018919

People lost money .someone hack and use to transfer through paypal


user posted image

user posted image

https://pokde.net/news/cimb-clicks-facing-m...security-flaws/
Update:cimb use recaptha to slow hacking process
Update from pokde. Basically u can login with wrong password
Update source:
https://www.soyacincau.com/2018/12/17/was-c...-clicks-hacked/
Quote for the lol
QUOTE(se7en @ Dec 17 2018, 12:55 PM)
will just leave this here for now

user posted image
*
This post has been edited by peja5081: Dec 17 2018, 07:58 PM
TSpeja5081
post Dec 16 2018, 10:49 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(feiraron @ Dec 16 2018, 10:45 PM)
OP dude the link you post got nothing to do with the capthcha thing, not even a mention there??

looks to me like their debit card is registered and linked with paypal and some sort of exploit there
*
https://m.facebook.com/story.php?story_fbid...100000339018919
Original post..that one i post is feedback from other case.but similar
TSpeja5081
post Dec 16 2018, 10:52 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(se7en @ Dec 16 2018, 10:50 PM)
ok, ran through their page, apart from the recaptcha, nothing else to worry about.

and for the record, using recaptcha on a bank login page is plain dumb.
*
Ok.maybe nothing to do we recaptcha.but many report unauthorized usage from paypal
TSpeja5081
post Dec 17 2018, 06:54 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Muhammad Syukri @ Dec 17 2018, 06:50 AM)
https://www.nst.com.my/news/crime-courts/20...-back-data-lost

Guys rhe issues is not about the password.

The real issue is that our bank information has been leaked , they do not use cimbclicks to hack your money but just through your card info link to paypal.
*
From pokde
https://pokde.net/news/cimb-clicks-facing-m...security-flaws/
TSpeja5081
post Dec 17 2018, 07:19 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Muhammad Syukri @ Dec 17 2018, 07:15 AM)
Yea it not just because of cimb click this gotta be related to the missing tape last year but cimb denied that the tape consist of customers information.
*
Problem is hacker just can brute force for password to log in.
TSpeja5081
post Dec 17 2018, 07:20 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Spectreoutreach @ Dec 17 2018, 07:17 AM)
Macam ini just cut off your card and resort to old fashioned withdraw counter
*
Lucky i dont activate online transaction for debit card
TSpeja5081
post Dec 17 2018, 08:09 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(IvanWong1989 @ Dec 17 2018, 07:58 AM)
Hmm..
I didn't login or access my CIMB account since few days ago. What should I do now? To safeguard my account . . .
*
"If you’re a CIMB Clicks customer, it is advisable to check if you have any suspicious transactions. If you received SMS notifications for transactions you didn’t make, do contact your bank immediately so that they can block your card or account from further abuse. "-soyacincau
TSpeja5081
post Dec 17 2018, 08:41 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(hirano @ Dec 17 2018, 08:21 AM)
Security is part of IT dept.

I browsed cimb's twitter and fb, still they wont mention any shit about the issue. If 1st world country, they would have made press release and apologize.
*
If they inform people will flood their system to transfer money
TSpeja5081
post Dec 17 2018, 08:43 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(olman @ Dec 17 2018, 08:35 AM)
So ahh DuitNOW can caya?

Amacam
*
Not related .but anything can be hack . security and it need to be careful and user need to aware of new threat
TSpeja5081
post Dec 17 2018, 09:01 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(aspartame @ Dec 17 2018, 09:00 AM)
But guys....to transfer money out still need TAC right? Why the panic?
*
Its link to paypal without need tac.not transfer to his account bank
TSpeja5081
post Dec 17 2018, 09:02 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(PhakFuhZai @ Dec 17 2018, 09:01 AM)
Change password problem solved?
*
Dont think so.he can brute force again until cimb fix it.only way is transfer out
TSpeja5081
post Dec 17 2018, 09:11 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(aspartame @ Dec 17 2018, 09:06 AM)
Oh ok...is this the way Paypal work? Why does paypal allow this kind of dangerous mode of operation?
*
Dont know la..now tac many remove alreay..view also no need password..maybe they thought more convenient
TSpeja5081
post Dec 17 2018, 09:13 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Richkierich @ Dec 17 2018, 09:12 AM)
Dudes, i hv money in cimb, but i did not login, will i be affected?
*
Probably they random people.people not login also kena

This post has been edited by peja5081: Dec 17 2018, 09:13 AM
TSpeja5081
post Dec 17 2018, 09:54 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(halglory @ Dec 17 2018, 09:53 AM)
CIMB so hard to login right now
takut customer transfer wang ke bank lain ke
*
Maybe people flood their server to tranfer money out
TSpeja5081
post Dec 17 2018, 09:59 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(annoymous1234 @ Dec 17 2018, 09:58 AM)
Is this related? Someone is trying to use??
*
Maybe yor autodebit?
TSpeja5081
post Dec 17 2018, 10:04 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Mummy Shark @ Dec 17 2018, 10:03 AM)
it's 10am.

you guys  can start the bank run *NOW*.
*
Online kan ada
TSpeja5081
post Dec 17 2018, 10:07 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(happyking4ever @ Dec 17 2018, 10:05 AM)
maybe it is just an instruction from the higher up to improve security only. recaptcha is normally used to stop automated brute force login attempts. maybe lah.
*
Recaptcha is cimb implementation using google security.not related to hacking password
TSpeja5081
post Dec 17 2018, 10:09 AM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Skylinestar @ Dec 17 2018, 10:07 AM)
who da fak uses recaptcha for banking service? imagine you're in a country that blocks google technology, how u gonna use the service without vpn?
*
Damage control..need to act fast.no time to implement others.if no google services no recaptcha

This post has been edited by peja5081: Dec 17 2018, 10:10 AM
TSpeja5081
post Dec 17 2018, 02:21 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(Mummy Shark @ Dec 17 2018, 02:18 PM)
Obviously they know it before..that why upgrading their system on 14dec
TSpeja5081
post Dec 17 2018, 02:34 PM

Getting Started
**
Junior Member
291 posts

Joined: Sep 2007
QUOTE(timo1003 @ Dec 17 2018, 02:30 PM)
Someone already shared.but i put in front page anyway.

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0522sec    0.58    7 queries    GZIP Disabled
Time is now: 9th December 2025 - 01:30 PM