applicationsecurityblog.itprop… — Despite the publicity over “phishing” attacks, people are still vulnerable to spoof e-mails and web sites. In one recent project, we crafted an e-mail with a link to a web page purporting to be a survey on information security hosted by our customer. We used graphics and links from the genuine corporate web site on our own server to ensure the page