Yep. I didn't realise that. Luckily it wasn't a major attack we had, but it left us scratching our heads for a while.
The attack had a prompt which wasn't the most pleasant of prompts

)
But, you learn from your mistakes i suppose.
I've also found the value of MD5 encryption for any data in the GET headers.