This post originated from an RSS feed registered with .NET Buzz
by Jeff Key.
Original Post: Your parents will never be safe: Visual Spoofing
Feed Title: Jeff Key
Feed URL: http://www.asp.net/err404.htm?aspxerrorpath=/jkey/Rss.aspx
Feed Description: Topics revolve around .NET and the Windows platform.
The latest thing the internet evildoers are doing to confuse your parents is called Visual Spoofing. Instead of faking URLs, these smart guys are faking the IE toolbars. Here's the deal: They launch a new browser window with all of the toolbars invisible and replace them with, you guessed it, toolbar images that contain a legit URL, SSL lock and so on.
Article is here. More info and an example of Visual Spoofing is on Don Park's blog.
It's worth mentioning that XP SP2 doesn't allow turning off the status bar, but apparently that alone isn't enough. I hope the IE team gets wind of this and disallows any content from the Internet zone from being displayed in a browser without toolbars.