This story is mostly funsec, if you can't handle funsec stop reading :) You have just developed you brand new application, it's name is EVIL.EXE. It's a very good application but nobody will install it without good partners.. You need somebody trusted from users that is willing to distribuite it. So.. Let's go! Find out some good partners.
OpenOffice will greet users and invite them to download the package, when the user click Proceed he will get the stuff. Only the italian localization has this nice feature, i suppose we (italian people) are a step forward because this :) Anyway point your browser to http://native-lang.openoffice.org/ and let's see if there are other localized subdomains with this feature.
Alexa will display stats about the destination site, when the user click on the site name he will be redirected to the url below.
The url will bring the user directly to the executable, you could use this for direct linking.
A9 will do mutch more, you can fully personalize the frame on the top. In the bottom one the package will load.
Google will do the same as A9, very similar url, similar parameters. It could be the same appliance. I dunno and don't care.
Now it's better to stop, also because the aim of this article is not to give you the top 1000 phishing urls but to show that big web players don't care your safety and let (bed) people abuse their sities and the trust costumers have in the brand.
It's time for some speculation: why this happen? These aren't strictly bugs (of course they are, they can be abused in phishing attacks) but mostly design error, at last from a security standpoint. I'll explain better: it's a resource problem, or a non-problem if you want, basically they are giving away your safety to save few buks.
Why? Because giving a page all the data it needs by POST or GET is cheaper than give just an ID, wow, you saved a SELECT! Somebody could argue: but we have a 2Tb database and a SELECT is not cheap!
Response: keys, de-normalization, sessions, and if this is not enough consider that you are making big bucks from your 2Tb database, you should care. I know you are not evil but but sometimes i think i'm wrong.