The most suttle attack we have seen thus far is a redirection attack of major e-commerce sites via simple cgi scripting. Run from a client, the web-site is polluted, using a redirection to a hoax site, which displays the graphics of choice - usually of the major e-commerce site.
Your personal information is then gleaned accordingly.
Only paying attention to the status line, in the address box or
URL will you see this slight deviation.
I'll see if I can post the examples in the AM.
Patches were know to have solved this, but a lot of web masters just did not do it....
Not pretty.
-Mike Z. /forums/images/graemlins/blush.gif