Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 RM2822.16 gone via unauthorized transaction in PBe, Please be extra careful!!!

views
     
patricktoh
post Oct 11 2008, 01:38 AM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


With keylogger, hacker will receive your login ID, password & TAC that you input to real online banking in no time. Normally TAC has an expiration of 30 mins to few hours so hacker could use all the 3 info to conduct online transction during that small window.

That also means external random key generator also not secure as long keylogger is operating.
patricktoh
post Oct 11 2008, 02:03 AM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


Keylogger is some sort of trojan that running in the background without user's knowledge. Normally planted to PC via free downloaded apps, games or software from net.

PC must be protected by reputeable antivirus such as Symantec, McAfee and etc. Of cause the virus def must up to date.
patricktoh
post Oct 11 2008, 02:08 AM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


QUOTE(toby.c13 @ Oct 11 2008, 02:03 AM)
for tac, u can oni change ur phone number thru atm rite?
and to do that they would need ur atm card too..
i wonder how.. hmm.gif
*
Refer to my earlier explanation then you will understand why the hacker don't event need to change the phone no. Basically make use of the same TAC within the small validity window.
patricktoh
post Oct 11 2008, 02:22 AM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


QUOTE(toby.c13 @ Oct 11 2008, 02:11 AM)
but then to do so.. dont the time frame must be the same when felicious is doing the transaction?
*
Hacker can wait until the genuine user logout and betting on TAC is still valid for next transaction.
patricktoh
post Oct 11 2008, 11:53 AM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


If I can get hold of the stolen ATM card and PIN, I rather withdraw cash directly from ATM machine. No electronic traces left compare to intenet banking which could be traced all the way to the location of the fraud origin.


Added on October 11, 2008, 12:09 pmThe victim must prove it is a genuine fraud else bank is not liable for the loses. Sad by facts.

Once I was hit by credit card being cloned and used for refuel petrol. The bank dropped those transactions without much questions becuase

1. It was used to pump dif brand of petrol that I used to.
2. The locations were not the place I frequent to.
3. The transactions amount and frequency were significantly dif from my regular refuel amount.

Transaction was perfromed everyday around midnite time for fewdays before it was detected by the bank and card was blocked by fraud preventive systems.

This post has been edited by patricktoh: Oct 11 2008, 12:09 PM
patricktoh
post Oct 11 2008, 12:33 PM

Casual
***
Junior Member
490 posts

Joined: Jan 2006
From: Kuala Lumpur


QUOTE(PureGeek @ Oct 11 2008, 12:19 PM)
actually in this case who bears the losses?
*
The petrol station or "merchant" (in credit card terminology) bears the loses. I can tell you that bank is always well protected from any fraud loses. If the card holder can't prove fraud then he/she has to absorb the loses. Else the merchant has to absorb because it allows fraud transaction. brows.gif

I work in banking & finance industry so can share with you some insight of the urgly practices.

 

Change to:
| Lo-Fi Version
0.0181sec    0.65    6 queries    GZIP Disabled
Time is now: 6th December 2025 - 08:17 AM