You are concerned with a compromised server? If I control your server, I can harvest whatever a user types in, even on an HTTPS page.
This doesn't require compromising any servers, and a lot of laptops will configure their DNS settings based on what the local network's DHCP server sends them.
To the end user, it will appear as though nothing is wrong.