Fannie Mae PWND by website prank

Fannie Mae has been pwnd by a fake website by an unknown third party.

Here is a direct link to the press release:
http://fanniernae.com/portal/about-us/media/corporate-news/2012/5820.html

Yes, the URL is weirdly misspelled at “f a n n i e r n a e” instead of “f a n n i e m a e.”  Odd, but the correct spelling seems to pull a 404 error which leads me to believe that Fannie Mae did not produce the website.

While most companies will play some kind of URL tweaking in anticipation of server overloads due to vast numbers of overly excited and thrilled people crowding a page, they do so in an open and easy-to-see manner.  The “rn” and “m” are just too slick.

The unknown third-party culprit has yet to be properly identified, someone called the number and posted their findings here: http://afscatlanta.blogspot.com/2012/09/fannie-mae-makes-major-announcement.html

Fannie Mae’s legal team is now hot on the trail of the suspect.  See the Legal Team mention here: http://www.housingwire.com/rewired/fake-press-release-celebrates-gse-principal-reduction-program

HERE is the data from GoDaddy WHOIS.

fanniernae.com, Secret Registration Customer ID 238852 fanniernae.com@secretregistration.com
Dyn Inc
c/o fanniernae.com
816 Elm Street
Box 606
Manchester, NH 03101
US

Domain name: FANNIERNAE.COM

Administrative Contact, Technical Contact:
fanniernae.com, Secret Registration Customer ID 238852 fanniernae.com@secretregistration.com
Dyn Inc
c/o fanniernae.com
816 Elm Street
Box 606
Manchester, NH 03101
US
+1.6037124016

Registration Service Provider:
(Dyn) Dynamic Network Services, Inc. support@dyn.com
Login to your account at https://account.dyn.com/+domains/ to manage
nameservers and contacts for your domain name.

Record last updated on 05-Sep-2012 13:32:30 UTC.
Record expires on 05-Sep-2013.
Record created on 05-Sep-2012.

This domain is delegated to Dyn Standard DNS:
NS1.MYDYNDNS.ORG
NS5.MYDYNDNS.ORG
NS4.MYDYNDNS.ORG
NS2.MYDYNDNS.ORG
NS3.MYDYNDNS.ORG
Industry leading uptime since 2001! ** Learn more here: http://dyn.com/ **

Domain status: clientDeleteProhibited
clientTransferProhibited
clientUpdateProhibited

Registrar: DYNAMIC NETWORK SERVICES, INC
Whois Server: whois.dyndns.com
Creation Date: 05-SEP-2012
Updated Date: 05-SEP-2012
Expiration Date: 05-SEP-2013

Have you been pranked?  Here are some indicators of a hoax:
1.  Clever little tricks with spelling of web addresses
2.  It’s your dream come true!  If it is really too good to be true, it likely is.
3.  The WHOIS data leads to a PO Box with contact info hidden.
4.  The site takes a while to load, which could indicate a third party intervening or a re-routing through a hidden frame designed to capture your data passing through.
5.  The DNS tables route to a different IP address than the normal “main” page’s IP.

Comments that are not SPAM are welcome.
###

Advertisements

About Amy Barnes

Author has extensive experience in Retail, including two years as a supervisor. Educated in Psychology, Financial Accounting, Criminal Justice, and Programming. Work experience in Law Enforcement, Security (IT), Programming (REALBasic, SQL, VB, JAVA), Retail.
This entry was posted in Artists, Atlanta, Atlanta GA, Businesses, Civil & Human Rights, Commentary, Cultures, Customs, Finance, How to Get Money, How to Save Money, Locations, Politics, Technology, the Retail Detail and tagged , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , . Bookmark the permalink.

This site uses Akismet to reduce spam. Learn how your comment data is processed.