dslreports logo
 story category
Blog 'burnfolder' » Wal-Mart's phishing site?
ri-walmart.com

Recently a site has popped up and it's been making the rounds supposedly revealing "secret" holiday specials for Wal-Mart. What struck me immediately though is the domain name - holiday.ri-walmart.com. Anybody who's examined a phish or two would immediately notice ri-walmart.com is not walmart.com.

What's even fishier is the domain itself was just registered late September, and the registrant info doesn't match that of walmart.com. After more digging I decided this is for reals, since browsing to »www.walmart.com/secret redirects you to »holiday.ri-walmart.com/.

I'm just confused why Wal-Mart would apparently register a whole new domain for this little site. You'd think they could simply create a new host on walmart.com. Most astute consumers are likely wise to phishing sites and know how to spot them, so why threaten an already shaky trust by creating an arbitrary domain like this?

And besides, what is ri walmart supposed to mean, anyways?
« back

Burn Folder

the best blog by rjackson on dslr
view:
topics flat nest 
MrBentor
join:2003-02-18
Seattle, WA

MrBentor

Member

Marketing dept. laking net-smarts?

I'd bet that either Wal-Mart knows it's customer's aren't astute enough to know the difference, or Wal-Mart's staff doesn't have a clue about phishing with similar domain names and the risk that using alternate secondary names may pose when trying to tell a real site from a copycat-fraud.

What to stop Joe Phisherman from registering ph-walmart.com and how much time would it take to tell it from a plathera of other xx-walmart.com sites that walmart may use, instead of using only third-level doms like xx.walmart.com only.

humm.....

Joe dot test
@comcast.net

Joe dot test

Anon

Re: Marketing dept. laking net-smarts?

Lacking
Plethora

AnonProxy
Premium Member
join:2001-05-12

AnonProxy

Premium Member

The Why

It's two things:
Core metrics, it allows them to EASILY isolate metrics for shopping habits and "bargain seekers". If you had ever seen the logs of the Wal-mart.com domain, just mining all the metrics for one sale item is a pain in the butt, imagine hundreds.

There is actually a marketing company that is helping run that. As part of the deal they get to track and use the metrics. Wal-mart is not going to let some third party data mine their whole site and sell that information to other companies, it's a competitive advantage, and they are making money with the info themselves...no need to give away the store.
A lot of you are going to have to redefine the way you check out a fishing site as there are more, lots more, of these type of things coming.

nklb
Premium Member
join:2000-11-17
Ann Arbor, MI

nklb

Premium Member

Re: The Why

xx.walmart.com could be made to point to completely different servers than walmart.com. There is no reason to use an alternate domain like this, they'll just end up scaring away some potentially valid business.