Activity

From November 17, 2021 to December 16, 2021

December 16, 2021

20:02 Task #12569 (Internal Testing): Pentest_IBAM - Reflected Cross-Site Scripting (XSS) [LOW]
The x-xss protection header has been implemented and already applied at server configuration.
It can help to preven...
Nurul Hasnieza Bt Mohd Zamri
18:41 Task #12588 (System Integration Test): Pentest_CDB - Missing HTTP "Strict-Transport-Security" Hea...
Nurul Athira Abdul Rahim
18:41 Task #12587 (System Integration Test): Pentest_CDB - Missing "X-Frame-Options" Header [LOW]
Nurul Athira Abdul Rahim
18:41 Task #12586 (System Integration Test): Pentest_CDB - Missing "X-Content-Type-Options" Header [LOW]
Nurul Athira Abdul Rahim
18:41 Task #12584 (System Integration Test): Pentest_CDB - Missing "Content-Security-Policy" Header [LOW]
Nurul Athira Abdul Rahim
18:35 Task #12583 (System Integration Test): Pentest_CDB - No Client-Side Session Timeout [LOW]
Nurul Athira Abdul Rahim
18:30 1. CDB_Phase 2 & 3 Development Bug #12693 (Work Completed-End life cycle): Rentas_IOS - Error message display for Single User at...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Rentas transaction using Single User
Current issue:
1...
Nurul Syahirah Md Nawi
17:55 Task #12564 (System Integration Test): Pentest_IBAM - Multiple Concurrent Session Allowed [LOW]
Nurul Athira Abdul Rahim
17:28 Task #12563 (System Integration Test): Pentest_IBAM - Missing HTTP "Strict-Transport-Security" He...
Nurul Athira Abdul Rahim
17:28 Task #12562 (System Integration Test): Pentest_IBAM - Missing "X-Frame-Options" Header [LOW]
Nurul Athira Abdul Rahim
17:28 Task #12561 (System Integration Test): Pentest_IBAM - Missing "X-Content-Type-Options" Header [LOW]
Nurul Athira Abdul Rahim
13:07 1. CDB_Phase 2 & 3 Development Bug #12679 (Work Completed-End life cycle): Rentas_IOS - Beneficiary ID type of Favourite Rentas ...
Tested & pass Nurul Syahirah Md Nawi
12:15 Task #12560 (System Integration Test): Pentest_IBAM - Missing "Content-Security-Policy" Header [LOW]
Nurul Athira Abdul Rahim
11:53 1. CDB_Phase 2 & 3 Development Bug #12673 (Work Completed-End life cycle): Rentas_IOS - Beneficiary ID check by default is disable
Nurul Syahirah Md Nawi
11:52 1. CDB_Phase 2 & 3 Development Bug #12673: Rentas_IOS - Beneficiary ID check by default is disable
Tested & pass Nurul Syahirah Md Nawi
10:42 Task #12558 (System Integration Test): Pentest_IBAM - Using Components with Known Vulnerabilities...
Nurul Athira Abdul Rahim
10:38 Task #12555 (System Integration Test): Pentest_IBAM - SQL Injection [HIGH]
Nurul Athira Abdul Rahim
10:34 Task #12576 (System Integration Test): Pentest_CDB - Using Components with Known Vulnerabilities ...
Nurul Athira Abdul Rahim
10:29 1. CDB_Phase 2 & 3 Development Feature #12114 (User Acceptance Test): [IOS] - UAT_DuitNow - To include Account Holder Name
Tested & pass Nurul Syahirah Md Nawi
09:55 1. CDB_Phase 2 & 3 Development Feature #12102 (User Acceptance Test): [IOS] - UAT_DuitNow - Recipient Reference to 140 length
Tested & pass Nurul Syahirah Md Nawi
09:52 1. CDB_Phase 2 & 3 Development Feature #12067 (User Acceptance Test): UAT_DuitNow [MOBILE - IOS] - Recipient Reference
Tested & pass Nurul Syahirah Md Nawi
09:41 1. CDB_Phase 2 & 3 Development Task #10424 (Internal Testing): [P1_Extended] IOS - CDB_Push Notification for authorization
Using the vpn penril to connect the client . the client tested able to receive push notification. but if in internal ... Aditya Prathama
09:36 Task #12581 (Internal Testing): Pentest_CDB - Usable Previously Requested OTP [LOW]
BSNeBiz Soft token already have duration set to token valid until 5 mins. Because BSNeBiz soft token is time base cry... Aditya Prathama
09:35 Task #12582 (Internal Testing): Pentest_CDB - OTP Does Not Expire [LOW]
BSNeBiz Soft token already have duration set to token valid until 5 mins. Because BSNeBiz soft token is time base cry... Aditya Prathama
09:30 1. CDB_Phase 2 & 3 Development Task #10161 (Internal Testing): [P1_Extended] : RFP Sect 1.2.3 - To develop RENTAS (Real Time) fo...
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:30 1. CDB_Phase 2 & 3 Development Task #11684 (Internal Testing): [Phase_2] Mobile [iOS]- DuitNow - Instant Transfer
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:29 1. CDB_Phase 2 & 3 Development Task #11687 (Internal Testing): [RFP_1.3.1.3] -Mobile [iOS] Development : Multiple Batch Window
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:28 1. CDB_Phase 2 & 3 Development Feature #12157 (Internal Testing): IOS-Sweeping - To update entry screen
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:27 1. CDB_Phase 2 & 3 Development Feature #12067 (Internal Testing): UAT_DuitNow [MOBILE - IOS] - Recipient Reference
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:27 1. CDB_Phase 2 & 3 Development Feature #12102 (Internal Testing): [IOS] - UAT_DuitNow - Recipient Reference to 140 length
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:26 1. CDB_Phase 2 & 3 Development Feature #12114 (Internal Testing): [IOS] - UAT_DuitNow - To include Account Holder Name
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:25 1. CDB_Phase 2 & 3 Development Bug #12325 (Internal Testing): DuitNow [MOBILE - IOS] - Transfer Mode has duplicate display in co...
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:24 1. CDB_Phase 2 & 3 Development Bug #12162 (Internal Testing): SIT_DuitNow [MOBILE - IOS] - Add to favourite
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:23 1. CDB_Phase 2 & 3 Development Feature #12365 (Internal Testing): DuitNow [MOBILE - IOS] - Update Confirmation and Result page o...
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:23 1. CDB_Phase 2 & 3 Development Task #12370 (Internal Testing): DuitNow [MOBILE - IOS] - Update dropdown Beneficiary ID type & ad...
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:22 1. CDB_Phase 2 & 3 Development Bug #12378 (Internal Testing): DuitNow [MOBILE - IOS] - Remark field in Confirmation page of Veri...
miss out to update redmine, this already fixed on PROD version 3.2.8 build 213 Aditya Prathama
09:19 1. CDB_Phase 2 & 3 Development Bug #12686 (Internal Testing): Rentas_IOS - JID Checking - Error stay Confirmation page without r...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:19 1. CDB_Phase 2 & 3 Development Bug #12686 (Development / Work In Progress): Rentas_IOS - JID Checking - Error stay Confirmation ...
Aditya Prathama
09:19 1. CDB_Phase 2 & 3 Development Bug #12680 (Internal Testing): Rentas_IOS - Error display when click Yes at popup change from IBG...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:18 1. CDB_Phase 2 & 3 Development Bug #12680 (Development / Work In Progress): Rentas_IOS - Error display when click Yes at popup c...
Aditya Prathama
09:18 1. CDB_Phase 2 & 3 Development Bug #12679 (Internal Testing): Rentas_IOS - Beneficiary ID type of Favourite Rentas display diffe...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:17 1. CDB_Phase 2 & 3 Development Bug #12679 (Development / Work In Progress): Rentas_IOS - Beneficiary ID type of Favourite Rentas...
Aditya Prathama
09:17 1. CDB_Phase 2 & 3 Development Bug #12678 (Internal Testing): Rentas_IOS - Cannot add account as Favourite
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:17 1. CDB_Phase 2 & 3 Development Bug #12678 (Development / Work In Progress): Rentas_IOS - Cannot add account as Favourite
Aditya Prathama
09:14 1. CDB_Phase 2 & 3 Development Bug #12677 (Internal Testing): Rentas_IOS - System currently unavailable display when insert spec...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:14 1. CDB_Phase 2 & 3 Development Bug #12677 (Development / Work In Progress): Rentas_IOS - System currently unavailable display wh...
Aditya Prathama
09:13 1. CDB_Phase 2 & 3 Development Bug #12675 (Internal Testing): Rentas_IOS - No validation & error message when left empty Bank Na...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:12 1. CDB_Phase 2 & 3 Development Bug #12675 (Development / Work In Progress): Rentas_IOS - No validation & error message when left...
Aditya Prathama
09:12 1. CDB_Phase 2 & 3 Development Bug #12676 (Internal Testing): Rentas_IOS - No validation & error message when insert special cha...
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:11 1. CDB_Phase 2 & 3 Development Bug #12676 (Development / Work In Progress): Rentas_IOS - No validation & error message when inse...
Aditya Prathama
09:11 1. CDB_Phase 2 & 3 Development Bug #12674 (Internal Testing): Rentas_IOS - Result screen of Single User is freeze
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:10 1. CDB_Phase 2 & 3 Development Bug #12674 (Development / Work In Progress): Rentas_IOS - Result screen of Single User is freeze
Aditya Prathama
09:10 1. CDB_Phase 2 & 3 Development Bug #12673 (Internal Testing): Rentas_IOS - Beneficiary ID check by default is disable
fixes available on Version 3.2.9 build 216 (SIT VPN Penril),Version 3.2.9 build 217 (SIT internal BSN), Version 3.2.9... Aditya Prathama
09:07 1. CDB_Phase 2 & 3 Development Bug #12673 (Development / Work In Progress): Rentas_IOS - Beneficiary ID check by default is disable
Aditya Prathama

December 15, 2021

19:03 1. CDB_Phase 2 & 3 Development Bug #12689 (Internal Testing): Rentas_Web - No option for Rentas at Transaction Type for BSNeBIZ ...
Hi Syahirah,
The testing can be started after next deployment.
Thank you.
----------
Issue:
No option for ...
Lai Wen Hong
17:04 1. CDB_Phase 2 & 3 Development Bug #12690 (Work Completed-End life cycle): Rentas_SIT - Unsuccessful Rentas transaction not disp...
Path:
1. BSNeBIZ Web > Account Summary > Giro/Giro I account > View Details > BSNeBIZ History
2. IBAM > CBE > BSN...
Nurul Syahirah Md Nawi
15:52 1. CDB_Phase 2 & 3 Development Bug #12689 (Work Completed-End life cycle): Rentas_Web - No option for Rentas at Transaction Type...
Path: BSNeBIZ Web > Account Summary > Giro/Giro I account
Scenario:
1. Select related Giro/Giro I account
2. Vie...
Nurul Syahirah Md Nawi

December 14, 2021

17:16 1. CDB_Phase 2 & 3 Development Bug #12666 (Work Completed-End life cycle): Rentas_Android - "null" is displayed at Transfer Mod...
Tested & passed Nurul Syahirah Md Nawi
17:13 1. CDB_Phase 2 & 3 Development Bug #12686 (Work Completed-End life cycle): Rentas_IOS - JID Checking - Error stay Confirmation p...

Current issue:
For approval or Single User Rentas transaction, if error occurs after user click Confirm button, pa...
Nurul Syahirah Md Nawi
14:43 1. CDB_Phase 2 & 3 Development Bug #12665 (Work Completed-End life cycle): Rentas_Android - "null" is displayed at Transfer Mode...
Tested & passed Nurul Syahirah Md Nawi

December 13, 2021

14:29 Task #12558 (Internal Testing): Pentest_IBAM - Using Components with Known Vulnerabilities [MED]
Najmi Pasarudin
14:29 Task #12576 (Internal Testing): Pentest_CDB - Using Components with Known Vulnerabilities [HIGH]
Najmi Pasarudin
14:28 Task #12555 (Internal Testing): Pentest_IBAM - SQL Injection [HIGH]
Najmi Pasarudin
11:38 Task #12568 (Internal Testing): Pentest_IBAM - Insecure Direct Object Reference (IDOR) [LOW]
SIT deploy on 13/12/2021
1. Insert deleted/invalid groupID at url parameter.
2. System will prompt error message....
Nurul Hasnieza Bt Mohd Zamri

December 10, 2021

17:55 1. CDB_Phase 2 & 3 Development Bug #12680 (Work Completed-End life cycle): Rentas_IOS - Error display when click Yes at popup ch...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform IBG transaction & insert amount exceeded IBG limit
2. En...
Nurul Syahirah Md Nawi
17:34 1. CDB_Phase 2 & 3 Development Bug #12679 (Work Completed-End life cycle): Rentas_IOS - Beneficiary ID type of Favourite Rentas ...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Favourite Rentas transaction
2. Check for Beneficiary ID...
Nurul Syahirah Md Nawi
17:28 1. CDB_Phase 2 & 3 Development Bug #12678 (Work Completed-End life cycle): Rentas_IOS - Cannot add account as Favourite
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Initiate Rentas transaction
2. At result screen, click "Add as F...
Nurul Syahirah Md Nawi
17:10 1. CDB_Phase 2 & 3 Development Bug #12677 (Work Completed-End life cycle): Rentas_IOS - System currently unavailable display whe...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Rentas transaction
2. Insert special character to Benefi...
Nurul Syahirah Md Nawi
17:02 Task #12564 (Internal Testing): Pentest_IBAM - Multiple Concurrent Session Allowed [LOW]
Staging allow multiple login. Production already applied Single Sign-On. Najmi Pasarudin
16:54 1. CDB_Phase 2 & 3 Development Bug #12676 (Work Completed-End life cycle): Rentas_IOS - No validation & error message when inser...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Rentas transaction
2. Insert special character to Benefi...
Nurul Syahirah Md Nawi
16:33 1. CDB_Phase 2 & 3 Development Bug #12675 (Work Completed-End life cycle): Rentas_IOS - No validation & error message when left ...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Rentas transaction
2. Leave empty Bank Name
3. Leave em...
Nurul Syahirah Md Nawi
16:12 1. CDB_Phase 2 & 3 Development Bug #12674 (Work Completed-End life cycle): Rentas_IOS - Result screen of Single User is freeze
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Single User for Rentas transaction
2. At Result screen, ...
Nurul Syahirah Md Nawi
16:07 1. CDB_Phase 2 & 3 Development Bug #12673 (Work Completed-End life cycle): Rentas_IOS - Beneficiary ID check by default is disable
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform New Rentas transaction/ Favourite Rentas transaction
2. ...
Nurul Syahirah Md Nawi
15:47 Task #12586 (Internal Testing): Pentest_CDB - Missing "X-Content-Type-Options" Header [LOW]
Please refer sc4.png at Task 12584 Najmi Pasarudin
15:47 Task #12587 (Internal Testing): Pentest_CDB - Missing "X-Frame-Options" Header [LOW]
Please refer sc4.png at Task 12584 Najmi Pasarudin
15:47 Task #12588 (Internal Testing): Pentest_CDB - Missing HTTP "Strict-Transport-Security" Header [LOW]
Please refer sc4.png at Task 12584 Najmi Pasarudin
15:46 Task #12563 (Internal Testing): Pentest_IBAM - Missing HTTP "Strict-Transport-Security" Header [LOW]
Please refer sc4.png at Task 12560 Najmi Pasarudin
15:46 Task #12561 (Internal Testing): Pentest_IBAM - Missing "X-Content-Type-Options" Header [LOW]
Please refer sc4.png at Task 12560 Najmi Pasarudin
15:46 Task #12562 (Internal Testing): Pentest_IBAM - Missing "X-Frame-Options" Header [LOW]
Please refer sc4.png at Task 12560 Najmi Pasarudin
15:44 Task #12560 (Internal Testing): Pentest_IBAM - Missing "Content-Security-Policy" Header [LOW]
Staging and Production web server already applied the header.
Pentest was done in app server instead of web server.
...
Najmi Pasarudin
15:44 Task #12584 (Internal Testing): Pentest_CDB - Missing "Content-Security-Policy" Header [LOW]
Staging and Production web server already applied the header.
Pentest was done in app server instead of web server.
...
Najmi Pasarudin
11:29 Task #12584 (Development / Work In Progress): Pentest_CDB - Missing "Content-Security-Policy" Hea...
Najmi Pasarudin
11:29 Task #12560 (Development / Work In Progress): Pentest_IBAM - Missing "Content-Security-Policy" He...
Najmi Pasarudin
11:07 Task #12555: Pentest_IBAM - SQL Injection [HIGH]
Check the parameter SearchApprovable for boolean instead of injecting the parameter as String.
Refer sc3.png
Najmi Pasarudin
10:01 1. CDB_Phase 2 & 3 Development Bug #12664 (Work Completed-End life cycle): Rentas_Android - Result is Unsuccessful when add acco...
Tested & passed Nurul Syahirah Md Nawi
09:57 Task #12555 (Development / Work In Progress): Pentest_IBAM - SQL Injection [HIGH]
Najmi Pasarudin
09:55 Task #12576: Pentest_CDB - Using Components with Known Vulnerabilities [HIGH]
Updates, refer to sc1.png
Bootstrap 4.1.1 > 4.6.1
ckeditor > removed because not used
JasperReport 6.6.0 > 6.18.1
...
Najmi Pasarudin
09:53 Task #12558: Pentest_IBAM - Using Components with Known Vulnerabilities [MED]
Updates, refer to sc2.png
# Bootstrap 4.1.1 > 4.6.1
# jquery-ui 1.10.3 > 1.13.0
Najmi Pasarudin

December 09, 2021

18:00 Task #12558 (Development / Work In Progress): Pentest_IBAM - Using Components with Known Vulnerab...
Najmi Pasarudin
16:17 1. CDB_Phase 2 & 3 Development Bug #12664 (Internal Testing): Rentas_Android - Result is Unsuccessful when add account number to...
Rahmat Aina Nadia
15:01 1. CDB_Phase 2 & 3 Development Bug #12662 (Work Completed-End life cycle): Rentas_Android - Add validation to Beneficiary ID fie...
Tested & passed Nurul Syahirah Md Nawi
15:00 1. CDB_Phase 2 & 3 Development Bug #12661 (Work Completed-End life cycle): Rentas_Android - Add validation to Recipient Referenc...
Tested & passed Nurul Syahirah Md Nawi
14:56 1. CDB_Phase 2 & 3 Development Bug #12663 (Work Completed-End life cycle): Rentas_Android - Need to click option twice in popup ...
Tested & passed Nurul Syahirah Md Nawi
13:28 1. CDB_Phase 2 & 3 Development Bug #12662 (Internal Testing): Rentas_Android - Add validation to Beneficiary ID field for Busine...
Rahmat Aina Nadia
13:28 1. CDB_Phase 2 & 3 Development Bug #12661 (Internal Testing): Rentas_Android - Add validation to Recipient Reference & Other Tra...
Rahmat Aina Nadia
13:27 1. CDB_Phase 2 & 3 Development Bug #12663 (Internal Testing): Rentas_Android - Need to click option twice in popup message for s...
Rahmat Aina Nadia
13:14 1. CDB_Phase 2 & 3 Development Bug #12660 (Work Completed-End life cycle): Rentas_Web - Add Rentas option at Transfer Type
Tested & passed Nurul Syahirah Md Nawi
13:12 1. CDB_Phase 2 & 3 Development Bug #12538 (Work Completed-End life cycle): Rentas - Changes in IBAM Service Info not reflect in ...
Tested & passed Nurul Syahirah Md Nawi
12:52 Task #12583 (Internal Testing): Pentest_CDB - No Client-Side Session Timeout [LOW]
SIT deploy on 09/12/2021. Kindly retest Nurul Hasnieza Bt Mohd Zamri
10:53 1. CDB_Phase 2 & 3 Development Bug #12666 (Internal Testing): Rentas_Android - "null" is displayed at Transfer Mode field of Ap...
Hi Syahirah,
After the changes are merged to DEBUG branch and restful is deployed, the test can be started.
Thank y...
Lai Wen Hong
10:49 1. CDB_Phase 2 & 3 Development Bug #12665 (Internal Testing): Rentas_Android - "null" is displayed at Transfer Mode field of Ver...
Hi Syahirah,
After the changes are merged to DEBUG branch and restful is deployed, the test can be started.
Thank y...
Lai Wen Hong

December 07, 2021

14:54 1. CDB_Phase 2 & 3 Development Bug #12666 (Work Completed-End life cycle): Rentas_Android - "null" is displayed at Transfer Mod...
Scenario:
1. Make Rentas transaction from Mobile
2.
i. Approve or Reject transaction from Mobile
ii. Approve or R...
Nurul Syahirah Md Nawi
12:25 1. CDB_Phase 2 & 3 Development Bug #12665 (Work Completed-End life cycle): Rentas_Android - "null" is displayed at Transfer Mode...
Scenario:
1. Make Rentas transaction from Mobile
2.
i. Verify or Reject transaction from Mobile
ii. Verify or Re...
Nurul Syahirah Md Nawi
11:31 1. CDB_Phase 2 & 3 Development Bug #12664 (Work Completed-End life cycle): Rentas_Android - Result is Unsuccessful when add acco...
Path: BSNeBIZ Mobile > Payment & Transfer
Scenario:
1. Perform New Rentas transaction
2. At result screen, click...
Nurul Syahirah Md Nawi
10:23 Task #12592 (System Integration Test): Pentest_CDB - TLS/SSL Server Supports The Use of Static Ke...
In WebSphere we had enforced tls1.2 and disable older tls versions. Nurul Athira Abdul Rahim
10:22 Task #12591 (System Integration Test): Pentest_CDB - TLS/SSL Server Is Using Commonly Used Prime ...
No availavle patch form IBM for the latest TLSv1.2 Ciphers. Nurul Athira Abdul Rahim
10:21 Task #12590 (System Integration Test): Pentest_CDB - Diffie-Hellman Group Smaller Than 2048 Bits ...
No availavle patch form IBM for the latest TLSv1.2 Ciphers. Nurul Athira Abdul Rahim
10:21 Task #12589 (System Integration Test): Pentest_CDB - [POTENTIAL] TLS/SSL Timing Side-Channel Atta...
No availavle patch form IBM for the latest TLSv1.2 Ciphers. Nurul Athira Abdul Rahim
10:15 Task #12575 (Development / Work In Progress): Pentest_IBAM - HTTP TRACE Method Enabled[INFO]
Options is not available on current server as it's WebSphere Application Server. Will perform the fix on web server. Nurul Athira Abdul Rahim
10:14 Task #12573 (System Integration Test): Pentest_IBAM - TLS/SSL Server Supports The Use of Static K...
In WebSphere we had enforced tls1.2 and disable older tls versions. Nurul Athira Abdul Rahim
10:14 Task #12572 (System Integration Test): Pentest_IBAM - TLS/SSL Server Is Using Commonly Used Prime...
No availavle patch form IBM for the latest TLSv1.2 Ciphers. Nurul Athira Abdul Rahim
10:13 Task #12571 (System Integration Test): Pentest_IBAM - Diffie-Hellman Group Smaller Than 2048 Bits...
In WebSphere we had enforced tls1.2 and disable older tls versions. Nurul Athira Abdul Rahim
10:12 Task #12570 (System Integration Test): Pentest_IBAM - [POTENTIAL] TLS/SSL Timing Side-Channel Att...
In WebSphere we had enforced tls1.2 and disable older tls versions. Nurul Athira Abdul Rahim
10:06 Task #12557 (System Integration Test): Pentest_IBAM - TLS Cookie Without Secure Flag Set [MED]
Require retest on Authentication server, as currently app server communicate with auth server using http connection. Nurul Athira Abdul Rahim
09:05 1. CDB_Phase 2 & 3 Development Bug #12663 (Development / Work In Progress): Rentas_Android - Need to click option twice in popup...
Rahmat Aina Nadia

December 06, 2021

19:27 Task #12583 (Development / Work In Progress): Pentest_CDB - No Client-Side Session Timeout [LOW]
To standardize the end screen with IBAM Nurul Athira Abdul Rahim
18:59 Task #12579 (System Integration Test): Pentest_CDB - Username Enumeration [LOW]
JTM to justify Nurul Athira Abdul Rahim
18:58 Task #12577 (System Integration Test): Pentest_CDB - Insecure Direct Object Reference (IDOR) [MED]
SIT to verify Nurul Athira Abdul Rahim
18:53 Task #12566 (System Integration Test): Pentest_IBAM - No Client-Side Session Timeout [LOW]
Tested and passed in SIT Nurul Athira Abdul Rahim
18:49 1. CDB_Phase 2 & 3 Development Bug #12663 (Work Completed-End life cycle): Rentas_Android - Need to click option twice in popup ...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform IBG transaction
2. Enter amount which exceeded IBG limit...
Nurul Syahirah Md Nawi
18:26 1. CDB_Phase 2 & 3 Development Bug #12661 (Development / Work In Progress): Rentas_Android - Add validation to Recipient Referen...
Rahmat Aina Nadia
18:26 1. CDB_Phase 2 & 3 Development Bug #12662 (Development / Work In Progress): Rentas_Android - Add validation to Beneficiary ID fi...
Rahmat Aina Nadia
17:47 Task #12559 (System Integration Test): Pentest_IBAM - Username Enumeration [LOW]
Tested and passed on SIT
Nurul Athira Abdul Rahim
16:38 1. CDB_Phase 2 & 3 Development Bug #12662 (Work Completed-End life cycle): Rentas_Android - Add validation to Beneficiary ID fie...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform *New Rentas transaction*/ *Favourite Rentas transaction*
...
Nurul Syahirah Md Nawi
15:32 1. CDB_Phase 2 & 3 Development Bug #12660 (Internal Testing): Rentas_Web - Add Rentas option at Transfer Type
Issue:
Display shows BSN/DuitNow/IBG without RENTAS
Finding:
RENTAS does not added
Solution:
Added RENTAS in...
Lai Wen Hong
15:31 1. CDB_Phase 2 & 3 Development Bug #12661 (Work Completed-End life cycle): Rentas_Android - Add validation to Recipient Referenc...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform New *Rentas transaction*/ *Favourite Rentas transaction*
...
Nurul Syahirah Md Nawi
13:24 1. CDB_Phase 2 & 3 Development Bug #12660 (Work Completed-End life cycle): Rentas_Web - Add Rentas option at Transfer Type
Path: BSNeBIZ > Transfer & Payment
Scenario:
1. Select Transfer Type
Current:
BSN/DuitNow/IBG
Expected:
B...
Nurul Syahirah Md Nawi

December 02, 2021

06:18 1. CDB_Phase 2 & 3 Development Task #12636 (Code Review): Rentas_IBAM - To Add Rentas Daily Report & Rentas Exception Report in ...
Issue:
No option for Rentas Daily Report & Rentas Exception Report
Finding:
No keys and values of Rentas Daily R...
Lai Wen Hong

December 01, 2021

15:23 1. CDB_Phase 2 & 3 Development Bug #12622 (Work Completed-End life cycle): Rentas_Web - Rentas Fees not deducted & display diffe...
Tested & passed Nurul Syahirah Md Nawi
15:02 1. CDB_Phase 2 & 3 Development Bug #12621 (Work Completed-End life cycle): Rentas_Web - System display error message in Approver...
Tested & passed Nurul Syahirah Md Nawi
10:25 1. CDB_Phase 2 & 3 Development Bug #12623 (Work Completed-End life cycle): Rentas_Web - Beneficiary ID type display as number in...
Tested & passed Nurul Syahirah Md Nawi
09:54 1. CDB_Phase 2 & 3 Development Bug #12623 (Internal Testing): Rentas_Web - Beneficiary ID type display as number in confirmation...
Nurul Syahirah Md Nawi
09:54 1. CDB_Phase 2 & 3 Development Bug #12622 (Internal Testing): Rentas_Web - Rentas Fees not deducted & display different from IBA...
Nurul Syahirah Md Nawi
09:47 1. CDB_Phase 2 & 3 Development Bug #12621 (Internal Testing): Rentas_Web - System display error message in Approver screen when ...
Nurul Syahirah Md Nawi
09:47 1. CDB_Phase 2 & 3 Development Bug #12538 (Internal Testing): Rentas - Changes in IBAM Service Info not reflect in BSNeBIZ
Nurul Syahirah Md Nawi

November 30, 2021

16:03 Task #12568 (Finished Development): Pentest_IBAM - Insecure Direct Object Reference (IDOR) [LOW]
Add validation check with deleted group. Add query criteria restriction equals to deleted FALSE filtering to get the ... Nurul Hasnieza Bt Mohd Zamri
14:41 Task #12576 (Development / Work In Progress): Pentest_CDB - Using Components with Known Vulnerabi...
Najmi Pasarudin
13:32 Task #12566 (Internal Testing): Pentest_IBAM - No Client-Side Session Timeout [LOW]
SIT has been deployed. Kindly retest. Nurul Hasnieza Bt Mohd Zamri
13:31 Task #12583 (Internal Testing): Pentest_CDB - No Client-Side Session Timeout [LOW]
SIT has been deployed. Kindly retest. Nurul Hasnieza Bt Mohd Zamri
13:29 Task #12577 (Internal Testing): Pentest_CDB - Insecure Direct Object Reference (IDOR) [MED]
SIT has been deployed. Kindly retest.
Replace url accountNo parameter with invalid account number. Will prompt inv...
Nurul Hasnieza Bt Mohd Zamri
13:26 Task #12559 (Internal Testing): Pentest_IBAM - Username Enumeration [LOW]
SIT has been deployed. Kindly retest. Nurul Hasnieza Bt Mohd Zamri
12:10 Task #12579 (Internal Testing): Pentest_CDB - Username Enumeration [LOW]
Does not need to be fixed because CDB has 2 users and
default page for invalid user is displayed without an OTP.
Nurul Hasnieza Bt Mohd Zamri

November 29, 2021

18:04 1. CDB_Phase 2 & 3 Development Task #12636 (Work Completed-End life cycle): Rentas_IBAM - To Add Rentas Daily Report & Rentas Ex...
Path: IBAM > Corporate Back End > BSNeBIZ Report
Scenario:
1. In Advance Search, select Report Type
Current:
...
Nurul Syahirah Md Nawi

November 25, 2021

16:13 Task #12583 (Finished Development): Pentest_CDB - No Client-Side Session Timeout [LOW]
Nurul Hasnieza Bt Mohd Zamri
10:24 1. CDB_Phase 2 & 3 Development Bug #12621 (Code Review): Rentas_Web - System display error message in Approver screen when using...
Issue:
System display error message in Approver screen when using Organization Specific & Tier Charges
Finding:
...
Lai Wen Hong
09:50 1. CDB_Phase 2 & 3 Development Bug #12392 (Work Completed-End life cycle): Rentas - Popup issue
Follow test steps to set max limit for ibg.
Tested & passed
Nurul Syahirah Md Nawi
09:34 1. CDB_Phase 2 & 3 Development Bug #12392: Rentas - Popup issue
HI Sya, please update the status of this issue. Denks Nurul Athira Abdul Rahim

November 24, 2021

22:50 1. CDB_Phase 2 & 3 Development Bug #12622 (Code Review): Rentas_Web - Rentas Fees not deducted & display different from IBAM set...
Issue:
Rentas Fees not deducted & display different from IBAM setting
Finding:
RENTAS transaction takes values f...
Lai Wen Hong
22:35 1. CDB_Phase 2 & 3 Development Bug #12623 (Code Review): Rentas_Web - Beneficiary ID type display as number in confirmation & re...
Issue:
Beneficiary ID type display as number in confirmation & result page of Verifier & Approver
Finding:
Confi...
Lai Wen Hong
15:27 1. CDB_Phase 2 & 3 Development Bug #12623 (Work Completed-End life cycle): Rentas_Web - Beneficiary ID type display as number in...
Path: BSNeBIZ > Payment & Transfer
Scenario:
1. Perform Rentas transaction
2. Verify & approve Rentas transacti...
Nurul Syahirah Md Nawi
15:10 1. CDB_Phase 2 & 3 Development Bug #12537 (Work Completed-End life cycle): Rentas_Web - Add validation to Beneficiary ID field f...
Tested & pass Nurul Syahirah Md Nawi
14:24 1. CDB_Phase 2 & 3 Development Bug #12622 (Work Completed-End life cycle): Rentas_Web - Rentas Fees not deducted & display diffe...
Path: IBAM > CBE > Organization Setup > Online Payment Charges
Scenario:
1. Select Edit button
2. In Interbank T...
Nurul Syahirah Md Nawi
14:01 1. CDB_Phase 2 & 3 Development Bug #12621 (Work Completed-End life cycle): Rentas_Web - System display error message in Approver...
Path: IBAM > CBE > Organization Setup > Online Payment Charges
Scenario:
1. Select Edit button
2. In Interbank T...
Nurul Syahirah Md Nawi
13:25 Task #12566 (Finished Development): Pentest_IBAM - No Client-Side Session Timeout [LOW]
Nurul Hasnieza Bt Mohd Zamri

November 22, 2021

15:02 1. CDB_Phase 2 & 3 Development Task #12168 (Work Completed-End life cycle): [Phase_2] Mobile [IOS] : RFP 1.6 - SOCSO
Merging issue. Tested and passed by Azyan. Nurul Athira Abdul Rahim

November 18, 2021

15:59 1. CDB_Phase 2 & 3 Development Bug #12537 (Internal Testing): Rentas_Web - Add validation to Beneficiary ID field for new & favo...
SIT has been deployed. Kindly retest. Nurul Hasnieza Bt Mohd Zamri
11:19 Task #12559 (Finished Development): Pentest_IBAM - Username Enumeration [LOW]
Update error message username not found standardized to Invalid username or password. Nurul Hasnieza Bt Mohd Zamri

November 17, 2021

17:36 Task #12577 (Finished Development): Pentest_CDB - Insecure Direct Object Reference (IDOR) [MED]
Add validation check insert other account number with user account number. Nurul Hasnieza Bt Mohd Zamri
 

Also available in: Atom