One drastic solution if your web site has lots of IE users: Simply don't answer the phone on port 80.
[Edit] Duh. As agentS points out, this won't work.
[Edit] Duh. As agentS points out, this won't work.
(It sounds like this attack depends on a complete version of the website being available over port 80)
No, it doesn't. An attacker can always connect to the website over HTTPS and proxy the content to the victim over port 80.