Sampath Vishwa allows brute Forces

Jack_Sparrow

Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    this method is still safer. if the phone gets stolen, someone can still access the account. This way, unless the hacker changes his face and get a counterfeit ID card, is impossible to fool.

    ok Jack Sparrow lets fill a form and go to sampath bank :oo:
    but machan i think still too much it seems, this is online banking, hacker will not transfer money any bank account by leaving traces..
    anyway for Transactions there is again another password.
    If account has a webcard then they can block it there.

    u cant easily reset the password. you have to give them a letter. its secure but hassle for customer.

    great hassle if someone tries to play with keep blocking accounts :baffled:


    ඔව් බන් මම Manager කෙනෙක්ටත් කිව්ව ඒ කාලෙම ... තව ඕකෙ IT devision එකේ වැඩ කරන යාළුවෙක්ට කිව්වම ඌ කියපි ...

    "ඔව් බන් ඕක known bug එකක් ... ළඟම තියෙන branch එකකට ගිහිල්ල reset කරගනින්කො" කියල :lol:

    තව ඌ කියනව ඒක security feature එකක්ලු :rofl: ... උන්ගෙ IT ගැන හිතාගනින්කො :dull:


    sirawata branch gane yanna oni nam online banking daganna onida? anika nikan nemei ung owata service charge ekakut gannawa.. e madiwata wena bankuwata salli transfer kalot hena ganak gannawa :baffled:
     

    cedric1986

    Member
    Apr 9, 2012
    29,703
    941
    0
    192.168.1.1
    you are an idiot for posting something like this in a public forum. you should have informed them(sampath bank) instead of exposing a critical issue like this in their system and let hackers to mess up with accounts of innocents users. users can do nothing so why did you reveal such a crucial information in here? what is the point?

    :yes:
     

    dhanusha83

    Well-known member
  • May 24, 2007
    3,533
    62
    48
    Mirigama
    Better solution would be account locked. Blog ip not solution for ever, if u are u using dhcp ,VPN or public ip with nat enable ip blocking is not good solution. But sampath didnt use account lock feature.
     

    Ali Don

    Member
    Aug 1, 2012
    427
    18
    0
    Ammage ukkule
    samapth noobs :angry: un nan jeewitheta up to date wenne na. nathan mona lokeda password change karanna form ekak ussan bank gane aran yanne. i did this two times then I gave up my sampath account. bloody idiots
     

    Jack_Sparrow

    Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    nice to see that you admit to being a fool :P

    Yes fool for buying online facility where i have to travel for reliability issues :dull:
    Do you think this threads needs to be closed? :rolleyes:

    samapth noobs :angry: un nan jeewitheta up to date wenne na. nathan mona lokeda password change karanna form ekak ussan bank gane aran yanne. i did this two times then I gave up my sampath account. bloody idiots

    i should give up my sampath vishwa facility :baffled: i think even paypal operates recovery options with email. Then atleast they should give option to switch to email recovery or manual tedious recovery :)

    Okunge IT, let's not talk abt them bn ;)

    Well i guessed so thats why i didnt complain them
     

    Jack_Sparrow

    Well-known member
  • Jun 16, 2008
    42,522
    1
    16,928
    113
    Black Pearl
    Guys,

    Do you know about 'Honeypots' ???

    http://en.wikipedia.org/wiki/Honeypot_(computing)

    Maybe, Sampath is watching the IPs of people who's trying to put bogus username and passwords (and maybe trying to attempt a brute force).

    So, do not fall in their trap :yes:

    Usually security engineers lay honey pots without messing with real time system :) this is DOS.. most of the times DOS attack will be done distributively where sampath has spend huge money to track them...

    If the honeypot is to detect hacker who hacks and do money frauds its acceptable :)