Anarchy,
I simply came up with a set of "rules" for my site's User Pages (No flash, redirects, banner ads, etc). I think you could literally go crazy trying to come up with patches and fixes to prevent malicious content, but it comes down to having proper supervision and reporting in place for your userpages. I use User Pages for 'Premium' members that donate to the website and they are much more likely to 'stay in line' as far as rules go as opposed to the GP (General Public).
I think having the flexibility in the pages is great, but it certainly takes more time on the Admin end of things to make sure they aren't being abused.
Incidently, do you run VMKForums? Many of my site members are members there as well ... (Visionsfantastic.com is my site)
|