This is certainly becoming more and more common and the majority of performers are now aware of being able to do it. I've even seen iframes being compromised through some very creative graphics.
It's an interesting idea that there is some clever fucker doing hacked profile pages, but I would have my doubts about that as I see other forms of this all the time.
The real solution is to control outgoing links from performer pages.
|