I remember reading about an attack where the "location bar" in a user's browser displays a valid URL (e.g. https://www.paypal.com/
), but the traffic is really being directed to or intercepted by an attacker. How can this be accomplished, and what can end-users do to ensure a URL they are visiting is what it claims to be?
Edit: I don't remember if the attack was talking about HTTP or HTTPS, so my question applies to both.