This paper describes malicious applets that use Java’s sophisticated graphic features to rectify the browser’s padlock area
and cover the address bar with a false https domain name. The attack was successfully tested on Netscape’s Navigator and Microsoft’s
Internet Explorer; we consequently recommend to neutralize Java whenever funds or private data transit via these browsers and patch the flaw in the coming releases. The degree of novelty of our attack is unclear since similar (yet
nonidentical) results can be achieved by spoofing as described in [6]