Don't use the -server or -daemon switch or run bitcoind on a machine where you use a web browser. It opens port 8332 on 127.0.0.1, the local loopback address, and you wouldn't think that web browsers could cross-site access it, but it is possible.
We're working on a release soon that puts a password on the JSON-RPC interface, but until then, avoid using the -server switch, and don't web browse on the same machine where bitcoind is running.
Update:
The JSON-RPC HTTP authentication feature in 0.3.3 solves this problem.
satoshi:you are a right topic in our bitcoin forum,If you want to say that any earnings will be used on their computer, then the account will be banned. If I say that the server or the Doodle switch is not good to use on the computer.If anybody else wants to use another account on the same computer, then he must make a mistake. A new action, you are working in the release soon, that keeps a password on the JSON-RPC interface,And then we must avoid the problem.It is necessary to overcome the problem,0.3.3 soves this problem.