Outline ·
[ Standard ] ·
Linear+
Chat CIMB kena hack?
|
unknown_2
|
Dec 17 2018, 11:35 AM
|
|
QUOTE(metaloid @ Dec 17 2018, 11:27 AM) Those that link their credit card to Alipay also really unsafe. They dont even ask for any TAC or CVV when you confim pay. So anyone who logs in your taobao app can just buy anything and click pay. Not used to china away of doing things. Fave also. it doesn't hav pin protection. when u buy deals, once u select buy now, straight away go through. dint ask for confirmation, need TAC, no need pin.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 11:52 AM
|
|
QUOTE(incubus_skj @ Dec 17 2018, 11:45 AM) Fave first time when you register your card got ask TAC ma Paypal you register anybody's card, don't even need TAC. yeah, but afterwards, any1 got hold of ur phone, can simply buy deals.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 01:37 PM
|
|
QUOTE(linkinstreet @ Dec 17 2018, 01:22 PM) Some people were using bots to bruteforce password, since CIMB has no failed login limits. The CAPTCHA was supposed to slow the bots down wtf is wrong wit CIMB? that's like security 101, this is 1 of the very 1st thing i teach coder to implement in their login. i tot since ages ago also all bank got login limit? the old cimbclick hav login limit?
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 01:42 PM
|
|
QUOTE(shihnobie @ Dec 17 2018, 01:40 PM) the old cimbclicks had login limit, if i am not not mistaken. i remember i was overseas and forgot my password and they locked me out. so front end updated, but bck end regression. topkek coder. i mean this is basic security 101. 1) u nvr store password as clear text 2) u always hav try limit before @ least temporary lock out.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 01:51 PM
|
|
QUOTE(Mummy Shark @ Dec 17 2018, 01:45 PM) no. CAPTCHA is not "speed bump". it's just either yes or no - a bot is not supposed to be able to resolve CAPTCHA altogether. "speed bump" is like ambank - "5 minutes login-again-later" when you try to be funny, even when you mistakenly clicked "back" or double login in app and web at same time. all u need to do is install ads blocking extension on ur browser, & u'll bypass the captcha altogether.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 01:53 PM
|
|
QUOTE(evilsmile @ Dec 17 2018, 01:52 PM) Ambank i ban for life because of bijan 2.6b No integrity OCBC not bad, their branch amoi also not bad. especially masjid jamek branch, almost all amoi is tapable.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 02:08 PM
|
|
QUOTE(scorptim @ Dec 17 2018, 02:06 PM) Actually all OCBC branches have pretty nice OL working in their customer facing roles. Puchong and subang OCBC also many hnnngh. The bank pandai to pick smexy amois for marketing purposes. i noticed they hav 1 amoi just to stand at the ticketing machine to press the button for u. they will change shift & always only good looking amoi get that post.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 03:03 PM
|
|
QUOTE(Mummy Shark @ Dec 17 2018, 03:00 PM) people are taking shortcut by blaming cimb, which have their own fault. it's paypal that people should be burning, for allowing the fraud to happen. they should support 3D Secure, but they chose not to. not implementing try limit to stop brute force attack is their fault.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 05:47 PM
|
|
QUOTE(Mummy Shark @ Dec 17 2018, 05:46 PM) the only guys who whould know that CVV behind card is you and the bank. even bank call center won't ask you for it. if you need to photocopy the card for whatever reason, always blank the cvv. i often see cashier note down the CVV in their system.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 05:48 PM
|
|
QUOTE(talzer @ Dec 17 2018, 05:17 PM) damn transfer limit only RM5k to maybank. any better way to transfer large sum of money away? u can change the transfer limit in cimbclicks, max is 30k i think.
|
|
|
|
|
|
unknown_2
|
Dec 17 2018, 11:14 PM
|
|
QUOTE(SweetPuff @ Dec 17 2018, 11:09 PM) Aren't all our ATM cards considered debit cards? it used to be u wan atm card or debit card, ehich comes wit atm function also. but ever wince the pin & pay, banks has been forcing customers to change to debit card by no providing atm only card anymore.
|
|
|
|
|
|
unknown_2
|
Dec 18 2018, 11:05 AM
|
|
QUOTE(sevenegg @ Dec 18 2018, 10:57 AM) for 4th condition, does it mean any characters u used in your ID and secure words cannot be used again in ur password? for 5th condition, does it mean cannot use 3 same type of character (eg: abc, 123) consecutively? if it's break then ok (eg: a1b2c3)? put @ least 1 caps, 1 number, & 1 special character in your password, then ur password will b solid.
|
|
|
|
|
|
unknown_2
|
Dec 18 2018, 02:46 PM
|
|
QUOTE(sevenegg @ Dec 18 2018, 02:35 PM) yes, initial pw is >8 characters, and I can login as usual everytime. nvr try to purposely key in wrong pw to testing. for me, since everything is safe for me, just change new pw only la, not need kpkb so much. of coz i wont say this if im the victim of this loophole.  still not fix their coding? i tried mine cant be exploit through this loophole.
|
|
|
|
|
|
unknown_2
|
Jan 1 2019, 09:01 PM
|
|
QUOTE(kyLL @ Jan 1 2019, 08:53 PM) just implement lock out after 3 failed attempts izzit. previous, since the new site until recent hoo haa, u can fail many times yet no account lock out. izzit jist implemented to cover their asses.
|
|
|
|
|