Sure, a hacker can fake-GET or fake-POST and guess at the credentials.  
But in a CSRF, the hacker causes the user's browser to do a GET WITH  
the user's own cookies, which may mean the user is authenticated.  
Correct me if I'm wrong, but the hacker cannot force the browser to do  
a POST, WITH the users cookies for that domain, without user  

