🔴commercial bank accounts තියෙන අය පරිස්සමින්🔴

sinhawanshaya

Well-known member
  • Jul 28, 2024
    13,878
    11,326
    113
    Cyber security ඉස්කොල වල 9 වසරෙ ඉන්දන් පොඩ්ඩ පොඩ්ඩ ඉගැන්නුවා නම් හරි ප්‍රෙව්සම් වෙන විදි ගැන, ඊට පස්සෙ උන්ගෙ අම්මලා තාත්තාලා ආච්චි සීයාලා ට කියලා දෙන්න බැරියෑ
     

    raman2

    Well-known member
  • Feb 16, 2009
    9,974
    12,059
    113
    iOS ද උඹ කියන්නෙ? Android එකේ නම් කිසිම අවුලක් නෑ.
    Oken wena bank credit card payment ekak karanna puluwan da? Ba..
    Card number eka bank account number eka widiyata dala account pay katannalu ahuwama.. mun yako maru it department

    Google eke welawakata phishing sites "Sponsored" enawa eka click wela yanne

    anith widiha Ukrain un dennek kalin alluwe TV pennuwe Samapath eka widihata fb eke Sponsored ads dala ,
    ko allapu un dennata labuna danduwama mokadda??????????? Thama naduwa yanawada ?



    ohoma neme AliExpress Sponsored ekatath google ad awith search result eke case wela thibba wena rata wala godak ,

    oya serama gana dana ganna thiyenneth Meta,Google deka
    e nisa un haraha , Meta,google sponsored ad haraha duwana scam gana danuwath karana posts trend wenawa aduyi .

    Yako mata giya sathiye awa [email protected] eken account ussana phishing link ekak.. gmail eke inbox deliver una..

    Hithapan ithin youtube, google wage untawath ungema system balaganna ba..
    ------ Post added on Sep 6, 2025 at 9:36 PM


    මොකාද බං website ගාණෙ ලගුල්ලන්ඩ යන්නෙ app එක තියෙද්දි? හුත්ත තමා
    Jeewitheta lankawe kisima app ekak danne na..
    lankawe IT ewun sure karannama bari jathiyak..
    Hack weemath ehemai, Waterboard app eka dapu unge private detail ekka langadi kela une hondawain..
    ------ Post added on Sep 6, 2025 at 9:43 PM
     
    • Like
    Reactions: Hankook

    SpinXO

    Well-known member
  • Jul 6, 2015
    4,246
    5,085
    113
    Loading...
    මොකක්හරි ජිංගි බිරිස් එකක් වෙලා තියෙන හැඩයි. Combankdigital web potral login එක slow.
     

    coder101

    Well-known member
  • Jul 20, 2018
    333
    548
    93
    Esoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.
    meka mchn oya danagatthe kohomada? Meka wennanm ba. Commercial Bank eka kiyanne PCI DSS certified bank ekak. Ekedi check wenawa mewa,
    - What data you store
    - How you store them
    - How you transfer them from client to server
    - How safe is the server remotely and physically
    Thawa godak dewal. Owayedi directlyma check wenawa Passwords store wena widiya.

    Oi widiyata bn text passwords store wela kohenhri access unanm loweth me weddi hena case godak gihin. Saralawama bank ekakata pattama hacking attempts godak enawa dawasakata.
    Ape company ekaka incidents 200 ganak awa ekaparak including DDOS, ape service down una winadi ganakata. E nisa owa run kranne babala newei. Man danne na lankawe banks kochcharak owata invest kranawada kiyalanm. Habai lankawe devops side eke inna senior godak un pattama wadakarayo. Mata set wechcha godak un ehemai. Unta henama reputation ekak tiyenawa. And I have a respect for them too.

    Man awrudu ganak fintech industry eke wada karanne foreign country ekaka. Habai danna, dakapu widiyata Lankawe serama wage banks wala security side eka hodai. Pattama nam na, habai godak hoda level ekaka tiyenawa.
    Lankawe Fintech system wala lokuma vulnerability eka minissu. Munta therenne na OTP ekak katawath denna hoda na kiyaneka, website ekaka URL eka mokadda kiyalawath. E nisa banks walin awareness kiyala ewana msgs wala meaning ekawath godak aya danne na. Oi salli nathi una, kapuna kiyala bank ekata banina godak unge case investigate kran giyama anthimata kohehri user krapu gon wadak thamai tiyenne, most of the times ekko OTP eka dila, nathnm mokakhri link ekak click krala. Rarely key loggers ehema tiwila phone eke. Oi wage ekakma thamai set unema.

    Anika karima thanhawak tiyenne.
    Man danna ekek pyramid ekakata ahuwenna yaddi man epaama qwa uuta ekata salli danna. Man A-Z pyramid wala wena hati seramath ekka kiyala dunna. Habai anthimata muu mtath hora salli daala uge laga tibba savings tika. anthimata kelama una, uge laga tibba wahane wikunala thamai uu daapu unta salli gewwe. thamath bike eke yanne dan awrudu 2ka witara indan. Oi tharam moda minissu thamai meke inne.
     

    හෙළයෙක්

    Well-known member
  • Apr 26, 2014
    49,373
    100,262
    113
    උන් ගෙ ආරාක්ශාව වැඩියි ඒකයි. FD එකෙන් ක්‍රෙඩිට් කාඩ් එකක් දෙන්න කිව්වම නිකන් ගන්න ඒවටත් වඩා Document ඉල්ලුව.
     

    ruchira55

    Well-known member
  • Mar 23, 2012
    39,939
    40,778
    113
    ලංකාවේ ඉන්න මෝඩ හුකන්නලගෙ වස්සැප් එකට යූසර්නේම් පාස්වර්ඩ් දුන්නොත් තෑග්ගක් දෙනවා කිව්වොත් ඒක උනත් ගන්න පුළුවන්. මහ අඩු කුලේ මෝඩයො ඉන්නෙ. මේ ජාන නවත්තන්න නම් ඕකුන්ව අල්ලලා බලෙන් වඳ කරන්න ඕනේ.
     

    nppcheguevara

    Well-known member
  • Feb 13, 2023
    8,780
    9,016
    113
    ulan bator
    Google eke welawakata phishing sites "Sponsored" enawa eka click wela yanne

    anith widiha Ukrain un dennek kalin alluwe TV pennuwe Samapath eka widihata fb eke Sponsored ads dala ,
    ko allapu un dennata labuna danduwama mokadda??????????? Thama naduwa yanawada ?



    ohoma neme AliExpress Sponsored ekatath google ad awith search result eke case wela thibba wena rata wala godak ,

    oya serama gana dana ganna thiyenneth Meta,Google deka
    e nisa un haraha , Meta,google sponsored ad haraha duwana scam gana danuwath karana posts trend wenawa aduyi .

    mewa karanne google eke wada karana un wenna barida ban. godak indian pakeyo oke wada karanawa!
     
    • Haha
    Reactions: FALL3N

    shenat

    Well-known member
  • May 13, 2007
    58,542
    86,820
    113
    ආශ්චර්යමත් රටක
    කලින් සම්පත් බැංකුවෙ ඔහොම හොර වෙබ්සයිට් එකක් මට අහුවෙලා මම ඒක බෑන්ක් එකට දැනුම් දුන්නා උන්ගෙ කන්ටැක්ට් ෆෝම් එකකින්ද කොහෙද. ඇත්ත එක වගේමයි address එකත්. Google එකෙත් උඩින්ම ආවා. නිකමට වගේ address එක හොඳට බලලා අල්ලගත්තෙ.

    නිකමටවත් මුකුත් එව්වෙ නෑ reply යවන්න තියන් ඉන්න email එකක් අපි මේක බලන්නං කියලවත්. Tech ගැන බේසික් දේවල් වත් දන්නෙ නැති මිනිස්සු එහෙම අහුවෙන්න ඇති.

    ලංකාවෙ ගොබ්බයො හිතන් ඉන්නෙ අලි පුකෙන්. මහලොකුවට ටෝක් දුන්නට තාමත් බේසික් දේවල් වත් හදාගන්න බැරිවෙලා. හරි ඇප් එකක් නෑ. හරිහමන් සිස්ටම් එකක් නෑ.
     

    ozykolla

    Well-known member
  • Jun 20, 2022
    9,804
    16,701
    113
    Esoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.

    මේක ඇත්ත සීන් එකක්
    Plain text තියාගන්නවා මදිවට බැංකු වැඩකරන උන්ට බලන්න ඇක්සස් තියනවා
     

    Nadun26

    Well-known member
  • Apr 27, 2015
    14,145
    12,690
    113
    38
    OTP එනවා නේ කිසිම ගනුදෙනුවක් කරන්න බෑ එකේ OTP එක දෙන්නේ නැතුව එතකොට කොහොමද වංචා කරේ ?
     
    • Like
    Reactions: coder101

    coder101

    Well-known member
  • Jul 20, 2018
    333
    548
    93
    මේක ඇත්ත සීන් එකක්
    Plain text තියාගන්නවා මදිවට බැංකු වැඩකරන උන්ට බලන්න ඇක්සස් තියනවා
    meka kohomada mchn verify karagatthe? check kranna widiyak tiyenawada?
     

    ITGuy25

    Well-known member
  • Oct 19, 2020
    1,662
    3,981
    113
    Esoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.
    මේක සිරා, මම කලින් එළකිරි එකේම දාලා තියෙනවා. මම auto generated password එකක් දැම්මා characters 20ක් විතර තියෙන. මුන්ගේ උපරිම 12ක් හරි 16ක් හරි ගන්නේ. හරිනම් error message එකක් පෙන්නන ඕනේ. මුන් එක error එකක් පෙන්නනේ නැතුවම characters 16කට අඩු කරලා save කරලා. මම characters 20 ම දාලා බලනවා, password එක වැරදියි කියනවා. customer support කතා කලාම password එකේ මුල characters ටික support හිටපු බුවා කිව්වා
     
    • Wow
    Reactions: coder101

    tarson

    Well-known member
  • Feb 25, 2009
    8,683
    5,894
    113
    https://www.combank.lk/digitalbanking/

    methanama domain 3k thiyenwa

    combank.lk ekai
    combankdigital.com ekai
    commercialbk.com ekai

    subdomain hadanna danne nadda mnda mun.

    ඔය හොදයි යකෝ, ඔස්ට්‍රේලියන් රජයත් වෙලාවකට .com ඒව යූස් කරනව උන් එක එක සර්විසස් 3rd පාටි දුන්නම. 10 පාරක් චෙක් කරල සමහර දේවල් කරන්නෙ. මාර ඇනයක් ලෙජිට් ද කියල හොයන්න බෑ සමහර වෙලාවට, රජයේ වෙබ්සයිට් වලම තියෙන ලින්ක් නිසා 50% ශුවර්. ලන්කාවෙ රජය ඒ අතින් හොදයි. ගොඩක් ම වෙරිෆිකේශන් සර්විසස් වගේ ඒව එක්කො මොනා හරි දේවල් වලට ඇප්ලයි කරනකොට. පිස්සු තමයි.
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    com bank uses .com domain so it is very easy to do a homoglyph attack.
    attacker get a look alike domain and clone the actual combank online website, even a cautious person could fall for this type of attack.
    attacker get the username and password and as soon as a user try to login, the the attcker gets credentials and the he tries them in the actual site, then the user gets the otp and enters it on the fake site, then attacker get the otp and enters it on the actual site.
    since com bank uses a .com domain, this is so easy to pull off.
    attacker has to do this real time, but it is technically possible to automate the whole thing.
     

    tharakaf

    Well-known member
  • Oct 19, 2020
    36,445
    75,169
    113
    com bank uses .com domain so it is very easy to do a homoglyph attack.
    attacker get a look alike domain and clone the actual combank online website, even a cautious person could fall for this type of attack.
    attacker get the username and password and as soon as a user try to login, the the attcker gets credentials and the he tries them in the actual site, then the user gets the otp and enters it on the fake site, then attacker get the otp and enters it on the actual site.
    since com bank uses a .com domain, this is so easy to pull off.
    attacker has to do this real time, but it is technically possible to automate the whole thing.
    So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?
    Either way the above attack works. Because the user’s session is always with the fake site and attacker’s session is with the com bank site. Fake site is just to transfer data to the attacker.
    There is no session between the user and actual website.
     

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,171
    6,655
    113
    East Blue (Goa Kingdom)
    ලංකාවෙ cybercrime prosecute කරන්න knowledge/skills නෑ බන්. ඒවා කතා කරලා වැඩක් නෑ. ඔහොම industry එක දියුනුවෙන්න තරම් කාලයක් ලංකාවෙ මිනිස්සු තියන් ඉන්න බෑ.

    ඔහොම sponsored එනවා කියන්නෙ පට්ට අවුල්නෙ බන්.
    oka aluth deyak neme awurudu ganak parana prashanayak google results & gmail eke udama ena sponsored ad patalenawa athhta results or emails wage enne. owa nisa una scams gana articles posts dakala athi,

    eth ewa search karala hoyanna lesi naha

    search eka handle karanne scam ad dana ungen salli gaththa google ekenma :P unta ona naha unge mistakes gana search eke udata ewanna

    So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?
    session based unath ,

    phishing site eke unge server eke real site ekata sign in wenawa athi victim enter karana credentials & otp walin,

    victim ta pennawa real site eken details aragena,

    victim phishing site eke logout dunnma , log out una wage penawa, adala normal logout unama ena page ekath watenawa athi.

    aththata logout wenne naha.

    com bank uses .com domain so it is very easy to do a homoglyph attack.
    attacker get a look alike domain and clone the actual combank online website, even a cautious person could fall for this type of attack.
    attacker get the username and password and as soon as a user try to login, the the attcker gets credentials and the he tries them in the actual site, then the user gets the otp and enters it on the fake site, then attacker get the otp and enters it on the actual site.
    since com bank uses a .com domain, this is so easy to pull off.
    attacker has to do this real time, but it is technically possible to automate the whole thing.
    issara combank online google karama mulata awe australia wage rataka same name thiyena bank ekaka site ekak.
    danuth unge .lk site eken digital bank select karala giyath .com sites dekakata yanna thiyenne
    e yanan sites dekath online banking kiyana ekata wenama ekak digital bank kiyana ekata wenama ekak,
    dekama mathaka hitina widihe ewath neme ona kenekta waradenna puluwan lesiyenma.

    bank kiyana eka bk widihata short karala sammana denna ona url eka mokadda kiyana eka decide karapu unta
     
    Last edited:

    tharakaf

    Well-known member
  • Oct 19, 2020
    36,445
    75,169
    113
    oka aluth deyak neme awurudu ganak parana prashanayak google results & gmail eke udama ena sponsored ad patalenawa athhta results or emails wage enne. owa nisa una scams gana articles posts dakala athi,

    eth ewa search karala hoyanna lesi naha

    search eka handle karanne scam ad dana ungen salli gaththa google ekenma :P unta ona naha unge mistakes gana search eke udata ewanna


    session based unath ,

    phishing site eke unge server eke real site ekata sign in wenawa athi victim enter karana credentials & otp walin,

    victim ta pennawa real site eken details aragena,

    victim phishing site eke logout dunnma , log out una wage penawa, adala normal logout unama ena page ekath watenawa athi.

    aththata logout wenne naha.


    issara combank online google karama mulata awe australia wage rataka same name thiyena bank ekaka site ekak.
    danuth unge .lk site eken digital bank select karala giyath .com sites dekakata yanna thiyenne
    e yanan sites dekath online banking kiyana ekata wenama ekak digital bank kiyana ekata wenama ekak,
    dekama mathaka hitina widihe ewath neme ona kenekta waradenna puluwan lesiyenma.

    bank kiyana eka bk widihata short karala sammana denna ona url eka mokadda kiyana eka decide karapu unta
    Either way the above attack works. Because the user’s session is always with the fake site and attacker’s session is with the com bank site. Fake site is just to transfer data to the attacker.
    There is no session between the user and actual website.


    User goes to the fake site --> Enters username/password --> This triggers the attacker to login to the real site with these credentials and initiates a transaction which sends OTP to customer --> Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.

    So the above is the most probably mode of attack right?
     

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,171
    6,655
    113
    East Blue (Goa Kingdom)
    User goes to the fake site --> Enters username/password --> This triggers the attacker to login to the real site with these credentials and initiates a transaction which sends OTP to customer --> Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.

    So the above is the most probably mode of attack right?
    oka thamayi godak phishing sites wada karana widiha.
    user danne naha hack wela kiyana eka mokak hari suspicious deyak wenakan.
    un credentials save kara gannawa otp ahanne nathi site wala nam + cookies - cookies thibbama otp ahana ida aduyi gmail wage ekaka unath kalin log una cookies etc & sitedata thiyena nisa
    Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.


    original site eke otp ahana step ekata dala athi mama combank use karala naha 7 years walin.
    kohomath un aniwa original site eke otp ahana thanak saka nohithenna ganna set karagena athi.

    samahara bank wala otp ahanne naha lankawe sign in weddi & transaction eka karaddi ahanneth naha ,
    eth transactions karanna kalin adala recipient register karanna ona ethanadi otp ekak ahanawa.