Interesting read, including a way to protect yourself from these kind of attacks!
Read more here.
security CSRF, security