The HTML disabling situation is my fault really
I found out how peeps could execute code on remote computers using scripting.
I was able to do anything javascript could do: including document.location which could be used (and probably was) to redirect a pm's window to a shifty site (cookie stealer). I warned Unixmad and it was disabled.
I happily take the title of 'Killer of <3 on Graal'
