🔴 PayHere වැඩ පෙන්නයි! 65GB ක දත්ත ලීක් කරගනී!

chami2015

Well-known member
  • Jul 14, 2015
    7,062
    8,363
    113
    thread 4 k yata pennane. 3 fast yanawa mekata wada
    නෑ බං මට මොන වදිියකින්වත් එලකිරි හෝම්පේජ් එකේ මේ ත්‍රෙඩ් එක පේන්නෙ නෑ. මම Find කරලත් බැලුව
     
    • Wow
    Reactions: HAneo

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    නෑ බං මට මොන වදිියකින්වත් එලකිරි හෝම්පේජ් එකේ මේ ත්‍රෙඩ් එක පේන්නෙ නෑ. මම Find කරලත් බැලුව
    1651559728258.png

    It's on 3rd now. refresh karala balanna machan
     

    elektro

    Well-known member
  • Apr 18, 2011
    6,865
    9,367
    113
    Tropical Island Of Sri Lanka

    ඕකා නම් වටේටම පුක දිදි මංපොර වෙන්න ට්‍රයි කරන එකෙක්. නෝස්කිල් . බැලුවොත් ලොකු ලොකු ප්‍රොෆයිල් වල පුක දෙනවා ගිහිං. මුටත් ඉන්නවා පට්ට toxic fan බේස් එකක්
     

    tharakaf

    Well-known member
  • Oct 19, 2020
    36,522
    75,315
    113
    So the merchant's customer's Cards are compromise. so what if hackers publish the Data Dump and people already have got the card numbers try to Use the cards? in that case don't you think that customer should empty the Related account ?
    It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.

    What pissed me off is the arrogance and the lack of transparency (only revealed this because they got their pants pulled down in public)
     
    • Like
    Reactions: HAneo

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.

    What pissed me off is the arrogance and the lack of transparency (only revealed this because they got their pants pulled down in public)
    Let me correct some point. when you connect to a Direct-Debit Payment Network you don't need an OTP CVV of customer every time. . All things happen under the hood. (When you pay using google Pay you just need a thumb print and you wont get any OTP) customer never ask for CVV or anything. they just need to given there thumb print and transaction done. So to handle this Marchant side must keep some track(AUTH Keys for DDP networks and Another data set.). basically customer gave mandate to handle transaction for them. good side this is very easy for customer.

    Now this system is hacked and that party got all the customer and secure data (we don't know the extend of the hack but we should think of the maximum for sake of the customers). now it's very easy to Commit a Direct Debit - pulls because attacker already have customer data and all the Auth he needs.

    And yes this is not easy for a programmer but a professional can easily do this. that's why people hack these kind of systems.
    All i am saying is that don't take any chance.
     
    • Like
    Reactions: elektro

    olu bakka

    Well-known member
  • Aug 18, 2011
    22,790
    23,463
    113
    1. ඉන්පසු "බැංකු ගිණුම connect කරන්න" button එක ඔබා, ඔබේ බැංකුව, හැඳුනුම්පත් අංකය සහ ගිණුම් අංකය ලබාදෙන්න.
    2. එවිට ඔබේ බැංකුවෙන් ඔබට SMS හරහා ලැබෙන OTP අංකය (JustPay code එක) හෙළPay වෙත ඇතුළත් කරන්න.
    මේක මචන් ඉතින් ගොඩක් ඇප්වල කරනවනෙ ලංකාවෙ

    Let me correct some point. when you connect to a Direct-Debit Payment Network you don't need an OTP CVV of customer every time. . All things happen under the hood. (When you pay using google Pay you just need a thumb print and you wont get any OTP) customer never ask for CVV or anything. they just need to given there thumb print and transaction done. So to handle this Marchant side must keep some track(AUTH Keys for DDP networks and Another data set.). basically customer gave mandate to handle transaction for them. good side this is very easy for customer.

    Now this system is hacked and that party got all the customer and secure data (we don't know the extend of the hack but we should think of the maximum for sake of the customers). now it's very easy to Commit a Direct Debit - pulls because attacker already have customer data and all the Auth he needs.

    And yes this is not easy for a programmer but a professional can easily do this. that's why people hack these kind of systems.
    All i am saying is that don't take any chance.
    මට මේ ගැන ලොකු දැනුමක් නෑ. මට කියපන් එහෙම ඩේටා ඉස්සුව කියල උන්ට cvv නැතුව payment එකක් කරන්න පුලුවන්ද? එහෙම පුලුවන් වෙන්නෙ මොන ඩේටා හින්ද්ද? මොකද දැන් වෙන කෙනෙක්ට cvv නැතුව payment එකක් කරන්න බෑනෙ. ඔය payhere වගේ network එකකට උනත් මුලින් authorize කරල දෙන්න එපැයි. Payhere එකෙන් කියන්නෙ cc numbers උනත් partial ගිහින් තියෙන්නෙ කියල. අනික password breach එකක් නැති නිසා පාස්වර්ඩ් මාරු කරන්න උවමනාවක් නෑ නේද?
    (Dialog app එකේ එහෙමනන් fingerprint එකවත් ඕනෙ නෑ නිකන්ම payment එක වෙනව ටච් කරපු ගමන් :sorry: )
    ------ Post added on May 3, 2022 at 1:53 PM
     
    • Like
    Reactions: U-tag

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    මේක මචන් ඉතින් ගොඩක් ඇප්වල කරනවනෙ ලංකාවෙ


    මට මේ ගැන ලොකු දැනුමක් නෑ. මට කියපන් එහෙම ඩේටා ඉස්සුව කියල උන්ට cvv නැතුව payment එකක් කරන්න පුලුවන්ද? එහෙම පුලුවන් වෙන්නෙ මොන ඩේටා හින්ද්ද? මොකද දැන් වෙන කෙනෙක්ට cvv නැතුව payment එකක් කරන්න බෑනෙ. ඔය payhere වගේ network එකකට උනත් මුලින් authorize කරල දෙන්න එපැයි. Payhere එකෙන් කියන්නෙ cc numbers උනත් partial ගිහින් තියෙන්නෙ කියල. අනික password breach එකක් නැති නිසා පාස්වර්ඩ් මාරු කරන්න උවමනාවක් නෑ නේද?
    (Dialog app එකේ එහෙමනන් fingerprint එකවත් ඕනෙ නෑ නිකන්ම payment එක වෙනව ටච් කරපු ගමන් :sorry: )
    ------ Post added on May 3, 2022 at 1:53 PM
    හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්
    මේක බලපන්

    හෙළPay වෙත බැංකු ගිණුමක් connect කරන්නේ කොහොමද?
    හෙළPay වෙත බැංකු ගිණුමක් connect කිරීම ඉතාම සරලයි. ඒ සඳහා,
    හෙළකුරු App එක තුළ ඇති හෙළPay icon එක ඔබා, එහි ඉහලින් දිස්වන + සලකුණ ඔබන්න.
    ඉන්පසු "බැංකු ගිණුම connect කරන්න" button එක ඔබා, ඔබේ බැංකුව, හැඳුනුම්පත් අංකය සහ ගිණුම් අංකය ලබාදෙන්න.
    එවිට ඔබේ බැංකුවෙන් ඔබට SMS හරහා ලැබෙන OTP අංකය (JustPay code එක) හෙළPay වෙත ඇතුළත් කරන්න.
    මෙසේ කළ පසු ඔබේ බැංකු ගිණුම හෙළPay වෙත connect වී, ඒ ගැන ඔබට දැනුම්දීමක් ලැබෙනු ඇත.

    මේකට තමා ඩිරෙක්ට් ඩෙබිට් ට්‍රාන්සක්ෂන් කියන්නේ. උබ මර්චන්ට්, උබේ කස්ටමර් ගේ කාඩ් විස්තර අරගෙන උබ එක බෑන්ක් එකට දීලා කටම්ර් වෙනුවෙන් උබ පේ කරනවා කියල බෑන්ක් එක ඔකේ කරගෙන තියෙන්නේ. හැබැයි කටම්ර් ගේ ඔකේ එක ලැබුනාම. එකට තමා ෆින්ගර් ප්‍රින්ට් එක දෙන්නේ. එක හෙලකුරු සයිඩ් එකට ඔකේ එකක් විතරයි. හැක් කල එකා ලග ඕක සිමුලටේ කරන්න පුළුවන් ඔක්කොම තියෙනවා.
     

    IceBear

    Well-known member
  • Jul 25, 2021
    1,659
    2,719
    113
    Alaska

    The owner must be jailed. Very irresponsible.
    It is like this, if you are using CCs now you need to put the cvv number and then if everything is right you have the OTP (even browsers will only save name, cc# and expiry). So the chances of doing shit with stolen CC numbers are quite low unless the figure out some complex scheme. So no need to be too paranoid but would be a good opportunity to penalize fucker like this who are more interested in profits than safety of the data they collect.

    What pissed me off is the arrogance and the lack of transparency (only revealed this because they got their pants pulled down in public)
    There is a way to gain access to iCloud account with partial card details. This issue must not be neglected. The owner should be held accountable for playing with innocent life’s.
     
    Last edited:

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama

    PCI DSS compliant means that they are telling to the world that they are following guide lines. PCI DSS Certified means that Auditing that they are actually following them. as you see there is 100% gap between those two. cus we never know if they did it or not
     

    tharakaf

    Well-known member
  • Oct 19, 2020
    36,522
    75,315
    113
    හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්
    මේක බලපන්



    මේකට තමා ඩිරෙක්ට් ඩෙබිට් ට්‍රාන්සක්ෂන් කියන්නේ. උබ මර්චන්ට්, උබේ කස්ටමර් ගේ කාඩ් විස්තර අරගෙන උබ එක බෑන්ක් එකට දීලා කටම්ර් වෙනුවෙන් උබ පේ කරනවා කියල බෑන්ක් එක ඔකේ කරගෙන තියෙන්නේ. හැබැයි කටම්ර් ගේ ඔකේ එක ලැබුනාම. එකට තමා ෆින්ගර් ප්‍රින්ට් එක දෙන්නේ. එක හෙලකුරු සයිඩ් එකට ඔකේ එකක් විතරයි. හැක් කල එකා ලග ඕක සිමුලටේ කරන්න පුළුවන් ඔක්කොම තියෙනවා.
    To be honest I am not an expert on this shit, nor have I used debit cards or payhere. So not sure how it works. But I also think that there should be regulations on what is stored and how things are handled without just doing whatever you like to make the coding part easy.

    I think banks too are in hot water for working with these guys without proper auditing.
     

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    To be honest I am not an expert on this shit, nor have I used debit cards or payhere. So not sure how it works. But I also think that there should be regulations on what is stored and how things are handled without just doing whatever you like to make the coding part easy.

    I think banks too are in hot water for working with these guys without proper auditing.
    My personal opinion is that Banks should not allow the method Direct Debit. it allow you to access customers account with less secure steps. i think VISA Europe taking steps to step down these transactions. i don't know about the Asia Pacific gateways. but it should happen soon.

    QNB Qatar and 7 Bank completely stopped DD transactions for this reason
     

    olu bakka

    Well-known member
  • Aug 18, 2011
    22,790
    23,463
    113
    හරි උබට පොඩි පැහැදිලි කිරීමක් කරන්නම්
    මේක බලපන්



    මේකට තමා ඩිරෙක්ට් ඩෙබිට් ට්‍රාන්සක්ෂන් කියන්නේ. උබ මර්චන්ට්, උබේ කස්ටමර් ගේ කාඩ් විස්තර අරගෙන උබ එක බෑන්ක් එකට දීලා කටම්ර් වෙනුවෙන් උබ පේ කරනවා කියල බෑන්ක් එක ඔකේ කරගෙන තියෙන්නේ. හැබැයි කටම්ර් ගේ ඔකේ එක ලැබුනාම. එකට තමා ෆින්ගර් ප්‍රින්ට් එක දෙන්නේ. එක හෙලකුරු සයිඩ් එකට ඔකේ එකක් විතරයි. හැක් කල එකා ලග ඕක සිමුලටේ කරන්න පුළුවන් ඔක්කොම තියෙනවා.
    එතකොට මචන් මේ breach එකත් එක්ක banks වලින් හෝ payhere සයිඩ් එකෙන් එහෙම simulate කරන්න බැරිවෙන්න මොකක් හරි step එකක් ගන්නෙ නැද්ද? (අලුත් key එකක් use කරනව හරි මොකක් හරි... I don't know whatever it is)
     

    avjayarathne

    Well-known member
  • Sep 13, 2021
    9,765
    29,993
    113
    Kandy
    පහුගිය කොරෝන කාලේ ලංකාවේ tuition වලට හදපු portal වල gateway එකත් payhere තමයි
    කීපදෙනෙක් කිව්වොත් දර්ශන උකුවෙල, අජන්ත දිසානායක
    ඔය දෙකේ විතරක් ඇති පනස්දාහකට එහා :baffled: