1. Get a signed cert from a recognized CA (fraudulently - not impossible).
2. Hijack the DNS (e.g., get their GoDaddy password, or point them to a DNS server you control)>.
3. The user is directed to the fake server with the fraudulently obtained cert, and does not receive a warning.
1. Get a signed cert from a recognized CA (fraudulently - not impossible).
2. Hijack the DNS (e.g., get their GoDaddy password, or point them to a DNS server you control)>.
3. The user is directed to the fake server with the fraudulently obtained cert, and does not receive a warning.