The attacker creates false "copy" of a the entire Web
-
attacker takes selected pages, the rest is available on-line
-
attacker web server is between a victim and the rest of the Web (DNS poisoning, registering false URL in a search engine)
-
if you see http://www.bad.com/http://www.good.com you are under attack; works even with secure connection
-
You can ask for it: http://www.anonymizer.com/
-
he can intercept and modify data
-
capture passwords, credit card information, etc
|