Also, I found this slightly amusing:
At its peak, the script was being loaded from a few hundred websites and receiving about 100k loads per day. Some of my friends were in a band and they were participating in a local battle-of-the-bands competition for a radio station that featured weekly online votes to move to the next round. Their voting system did nothing to defend against XSRF attacks, but did limit votes to 1 per IP address.
So naturally, my friends won by a landslide of votes, most of which originated in Latin America.
** chuckles **