HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual T 5.87 Web spoofing

T 5.87 Web spoofing

Web spoofing involves perpetrators "forging" WWW servers, that is to say, they set up their WWW sever to pretend that it is a particular, reliable WWW server. This is done by choosing a WWW address in such a way that many users assume they are connected to a particular institution just from the choice of address. Even if the correct computer name is used, Web spoofing is possible if perpetrators use DNS spoofing (see G 5.78 DNS-Spoofing).

Example:

Rather than trying to manipulate or imitate an existing WWW server, perpetrators can also bring their own WWW offer into the Internet and present it in such a way that each visitor has the impression of being connected to an established, serious institution.

Examples:

.
© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
July 1999
home