Ahh the old session var stealing external links problem.
Way to fix and protect yourself:
- Remove all shortcuts to Internet Explorer
- Download Firefox
- Close Internet Explorer never to open it again
- Download Safari using Firefox
- Never use / personalise Safari
- Use Firefox for normal browsing
- When someone sends you a link for approval, paste it into Safari
- If it's safe, make sure there is no HTTP GET vars, if there is, generally better to avoid it
- Check the owner of the domain name with the WHOIS Service, Does it belong to a member of "Those who would not be named"?
- If yes, don't approve.
- If no, approve.