It's potentially easy to hijack blogs through mendacious JavaScript code, a posting on one Web log (kasia in a nutshell) notes. So the message is to double check referrers to make sure they link to a valid site, with links back to the blogger's site (if you will).