A method and system to protect users against potentially fraudulent
activities associated with spoof web sites are described. According to
one aspect of the present invention, the URL of a document downloaded via
a web browser client is compared to the URLs in a list of URLs for known
spoof sites. If the URL for the downloaded document is found in the list
of URLs for known spoof sites, a security indicator is displayed to the
user to indicate to the user that the downloaded document is associated
with a known spoof site. According to another aspect of the invention, a
security server maintains a master black list and periodically
communicates updates of the master black list to the local list of a
client security application.