🔴 PayHere වැඩ පෙන්නයි! 65GB ක දත්ත ලීක් කරගනී!

olu bakka

Well-known member
  • Aug 18, 2011
    22,794
    23,464
    113
    My personal opinion is that Banks should not allow the method Direct Debit. it allow you to access customers account with less secure steps. i think VISA Europe taking steps to step down these transactions. i don't know about the Asia Pacific gateways. but it should happen soon.

    QNB Qatar and 7 Bank completely stopped DD transactions for this reason
    ඕක මාර risky නෙහ් බලන් ගියාම. කොච්චර නන් ලංකාවෙ app වල direct debit යූස් වෙනවද. ෆෝන් කම්පැනි වල ඇප්, රීලෝඩ් ඇප්, koko අරව මේවා, frimi වගේ ඒවා, paypal උනත් එහෙමනෙ.

    පහුගිය කොරෝන කාලේ ලංකාවේ tuition වලට හදපු portal වල gateway එකත් payhere තමයි
    කීපදෙනෙක් කිව්වොත් දර්ශන උකුවෙල, අජන්ත දිසානායක
    ඔය දෙකේ විතරක් ඇති පනස්දාහකට එහා :baffled:
    payhere එකේ 1.5 million යූසර් ඩේටාලු
    ------ Post added on May 3, 2022 at 4:58 PM
     

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    එතකොට මචන් මේ breach එකත් එක්ක banks වලින් හෝ payhere සයිඩ් එකෙන් එහෙම simulate කරන්න බැරිවෙන්න මොකක් හරි step එකක් ගන්නෙ නැද්ද? (අලුත් key එකක් use කරනව හරි මොකක් හරි... I don't know whatever it is)
    These transactions are happening through private networks. what we call Peer-to-Peer channels. as far as i know it also can be simulated
    Yes Bank can cut off Marchant's access and all it's Secure keys.

    ඕක මාර risky නෙහ් බලන් ගියාම. කොච්චර නන් ලංකාවෙ app වල direct debit යූස් වෙනවද. ෆෝන් කම්පැනි වල ඇප්, රීලෝඩ් ඇප්, koko අරව මේවා, frimi වගේ ඒවා, paypal උනත් එහෙමනෙ.


    payhere එකේ 1.5 million යූසර් ඩේටාලු
    ------ Post added on May 3, 2022 at 4:58 PM
    If you use DD you have to secure your side as well. these not true for the Payment Gateway access where bank loads it's own Secure interface.
    ------ Post added on May 3, 2022 at 5:03 PM
     

    olu bakka

    Well-known member
  • Aug 18, 2011
    22,794
    23,464
    113
    These transactions are happening through private networks. what we call Peer-to-Peer channels. as far as i know it also can be simulated
    Yes Bank can cut off Marchant's access and all it's Secure keys.


    If you use DD you have to secure your side as well. these not true for the Payment Gateway access where bank loads it's own Secure interface.
    ------ Post added on May 3, 2022 at 5:03 PM
    Thank you machan
     
    • Like
    Reactions: HAneo

    chami2015

    Well-known member
  • Jul 14, 2015
    7,062
    8,363
    113
    Screenshot 2022-05-03 181604.png
     

    Melon8

    Well-known member
  • Dec 19, 2014
    2,104
    2,344
    113
    මේ දැන් කස්ටර්මර්ස්ලට දාන්ඩ මේල් එකක් මොකක් ලියලද බන්? කවුරුහරි පින්වතෙක් පොඩි කොමන් ලෙටර් එකක් ලියලා දාපන්කෝ කස්ටර්මර්ස්ලට මේල් කරන්ඩ සුදුසු.මට මේක ලියාගන්ඩ බැරුව මම මේ ඉන්නේ.

    බැනුම් අහන්ඩ වෙයිද බන්? ආයේ බඩු ගන්නේ නැති වෙයිද දන්නෙත් නෑ. :(
    අනිත් එක දැන් ඕවා දැම්ම වගේ නෙමේ ප්‍රශ්න වැල වගේ ආපුවහම උත්තර දෙන්ඩ ගිහින් එපා වෙයි මට.:-(
     

    හෙළයෙක්

    Well-known member
  • Apr 26, 2014
    49,403
    100,332
    113
    දැන් මුන්ට ඉක්මනටම කරන්න තියෙන්නෙ හොද security adviser කෙනෙක් හරි firm එකක හරි සපෝට් එක අරගෙන උන් එක්ක ජොයින්ට් නිව්ස් එකක් රිලීස් කරන එක.

    උඹේ නමෙත් හෙළ කෑල්ලක් තියෙනව. උඹ නෙමෙයි නේ මූ
    නෑ නෑ.
    ------ Post added on May 3, 2022 at 8:34 PM

    නූලෙන් ඇහැරිලා 😂
    නැත්තන් ඔච්චර දවසක් කරපු නැති වැඩ ටික දවස් දෙකෙන් විතර සට සට ගාල කරන්නෙ නෑ. එෆ්බී එකේ ඉන්නෙ ටොක්සික් ෆෑන් බේස් එකක් උන්ට කියන්නෙ මොනවද ඒවට හා ගාගෙන ඉන්නව විතරයිනෙ.
    ------ Post added on May 3, 2022 at 8:35 PM
     

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    නැත්තන් ඔච්චර දවසක් කරපු නැති වැඩ ටික දවස් දෙකෙන් විතර සට සට ගාල කරන්නෙ නෑ. එෆ්බී එකේ ඉන්නෙ ටොක්සික් ෆෑන් බේස් එකක් උන්ට කියන්නෙ මොනවද ඒවට හා ගාගෙන ඉන්නව විතරයිනෙ.
    ------ Post added on May 3, 2022 at 8:35 PM
    එහෙම හරි කමක් නැ බන් වරද හදාගන්නවා නම්. මේවා බෙල්ල ගහලා යන වැඩ.
     

    me2cool

    Well-known member
  • Mar 21, 2012
    673
    1,141
    93
    මේ දැන් කස්ටර්මර්ස්ලට දාන්ඩ මේල් එකක් මොකක් ලියලද බන්? කවුරුහරි පින්වතෙක් පොඩි කොමන් ලෙටර් එකක් ලියලා දාපන්කෝ කස්ටර්මර්ස්ලට මේල් කරන්ඩ සුදුසු.මට මේක ලියාගන්ඩ බැරුව මම මේ ඉන්නේ.

    බැනුම් අහන්ඩ වෙයිද බන්? ආයේ බඩු ගන්නේ නැති වෙයිද දන්නෙත් නෑ.
    :(
    අනිත් එක දැන් ඕවා දැම්ම වගේ නෙමේ ප්‍රශ්න වැල වගේ ආපුවහම උත්තර දෙන්ඩ ගිහින් එපා වෙයි මට.:-(
    Here is a small example.

    What is your demography? Old/Young? Male/Female?

    Adapt it according to your demography/business/service/platform. Ask them to enable 2FA if you have that service.
    It's good you thought to inform your customers about this. Certainly, put you miles ahead compared to PayHere who downplayed this until it escalated.

    But first, pls discuss this with other small businesses you know how to handle this.


    Dear XYZ customers,

    We are writing to inform you about a data security issue that may involve your XYZ account information.

    PayHere (pvt) Ltd, our payment gateway partner for online transactions, issued a press release on xx/yy/zzzz informing about a data compromise that occurred from their systems as a result of the cyberattack on PayHere on the 2nd of April 2022. Please read their full incident report here.

    LINK

    Considering the sensitive nature of the compromised data, we recommend all our customers reset their passwords as a precautionary measure. PayHere management has ensured us that they have taken all the necessary steps to tighten their security on multiple levels to prevent any future attacks. The management also communicated that there will not be any financial risk due to the compromised data.

    Rest assured that we will keep you informed about any new developments of this data breach.

    XYZ Customer Service Team
     

    Sonique

    Well-known member
  • Oct 22, 2007
    25,196
    11,220
    113
    Forest
    I don't know why WSO2 or MIT come up with a safe payment platform as they have way more experience than some random tech company :oo:
     

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    Dear XYZ customers,

    We are writing to inform you about a data security issue that may involve your XYZ account information.

    PayHere (pvt) Ltd, our payment gateway partner for online transactions, issued a press release on xx/yy/zzzz informing about a data compromise that occurred from their systems as a result of the cyberattack on PayHere on the 2nd of April 2022. Please read their full incident report here.

    LINK

    Considering the sensitive nature of the compromised data, we recommend all our customers reset their passwords as a precautionary measure. PayHere management has ensured us that they have taken all the necessary steps to tighten their security on multiple levels to prevent any future attacks. The management also communicated that there will not be any financial risk due to the compromised data.

    Rest assured that we will keep you informed about any new developments of this data breach.

    XYZ Customer Service Team
    First question comes from the Customer
    "What about my existing data are they being used in somewhere else? " then you fucked

    communicated that there will not be any financial risk due to the compromised data.
    We talking about someone else money and this statement is not true. why you taking unnecessary risk? this is not your fault. and you don't know the Extend of this attack and either payshere telling the truth

    So i would defiantly send my customers
    "Until we sort things out do not use the payment system"

    I don't know why WSO2 or MIT come up with a safe payment platform as they have way more experience than some random tech company :oo:
    I give you one reason

    Because of the Security involve in this technologies most of the technologies has to learn their self and even get the Dev help from vender by signing some agreements. there is no help in StackOverflow , GitHub or anywhere else when you try to program. so you must have at lest 4-5 years of industry experience on this area in order to successfully implement a Payment system
    ------ Post added on May 3, 2022 at 10:26 PM
     
    • Like
    Reactions: animation

    Sonique

    Well-known member
  • Oct 22, 2007
    25,196
    11,220
    113
    Forest
    First question comes from the Customer
    "What about my existing data are they being used in somewhere else? " then you fucked


    We talking about someone else money and this statement is not true. why you taking unnecessary risk? this is not your fault. and you don't know the Extend of this attack and either payshere telling the truth

    So i would defiantly send my customers
    "Until we sort things out do not use the payment system"


    I give you one reason

    Because of the Security involve in this technologies most of the technologies has to learn their self and even get the Dev help from vender by signing some agreements. there is no help in StackOverflow , GitHub or anywhere else when you try to program. so you must have at lest 4-5 years of industry experience on this area in order to successfully implement a Payment system
    ------ Post added on May 3, 2022 at 10:26 PM
    You think MIT engineers surfed stack overflow to build London stock exchange? Anyway you don't have to hire only Sri Lankan engineers :oo:
     

    HAneo

    Well-known member
  • Jan 30, 2007
    12,970
    29,168
    113
    Homagama
    You think MIT engineers surfed stack overflow to build London stock exchange? Anyway you don't have to hire only Sri Lankan engineers :oo:
    London stock exchange - if I try to comment then it would be a sarcasm
    I personally not mentioning but one the best IPG Architect is from SriLanka. He resigned. but his IPG still works on some 40 or More powerfully bank chains all over the world. Developed Using C++. Can connect to multiple Payment systems. has interface to plug any Payment system yet to come(You cannot find this feature any where else). Can communicate with any Terminal type or device
     
    • Wow
    Reactions: animation