Nice post.
If we take this a little further with Address bar Spoofing with LTR characters, the attacker can make the URL in address bar look like legitimate website like Google over HTTPS. So to be safe, the users need to check for '://' after https and confirm it is not a single slash':/'.
Thanks for the post.
RE: Social Engineering Chronicles - #2