Yes, the PM system can be hijacked -- I'm a moderator at Silent PC Review, and we had someone register, and then send out a bunch of PM's that included a link to a site that planted a Trojan. Since they never posted to the site, getting their IP was tough. So, it certainly makes sense to limit guest's ability to see profiles.
BTW, did the EM (and ER) server go through a rough patch last evening? I had to log off because both sites were extremely slow...
|