I Hacked News.YC
classbug.com
classbug.com
I am sure that when they created the website they did not want to take a ton of security precautions in order to prevent things like this.
I am sure that you can create a hack that will start 1 million threads, post 1 million comments, and create 1 million users.
Shawn Presser
To protect a site, you must include an unguessable parameter in all side-effecting requests.
And if you're going to be putting the session id somewhere, it should be in a POST request, not a GET request, otherwise it can be hijacked.
To fix the problem, PG needs to check that the userid that clicked the fnid is the same as the userid for which it was created.
BTW, browser bugs actually make the problem even more complex than this because it is sometimes possible to steal content off of other pages.
"If you use GET for interactions with side-effects, your make your system insecure."
(from http://www.w3.org/2001/tag/doc/whenToUseGet.html#safe)