Tested this on several installs of vB 3.8.5 and below, will be testing on vB4 shortly.
If you register with a null ascii character (�) in the name, you gain access to a users emails sent from vB.
For example, if the admin on my forum is "Admin1" and I register for a new account with "Admin1�" the registration is allowed, and all email notices of PM's, subscribed threads, etc will go to both accounts.
The fix for this I have found is simply disallowing &# in the Illegal User Names field under User Registration Options.
__DEFINE_LIKE_SHARE__