摘要: Phishing (the act of conning a person into divulging sensitive information) commonly uses legitimate-looking Web sites that mimic the online interface institution attacker is misrepresenting (usually bank, merchant, or ISP). One way users can tell they are viewing false site to check browser's address bar: URL should match actual institution, barring any vulnerabilities permit spoofing bar some types DNS attack. However, recent phishing scams not only spoof an institution's but also and display correct URL.