I think this tip is more worth than all of the others combined:
Do not use your forum password to register on other websites, especially not those run by other members
There is no way (that I know of) to make sure that the passwords stored on the server are encrypted and thus protected from potential hackers, or more importantly, the website owner. For all you know (s)he could be sorting through the registered users list, trying their passwords on their respective forum accounts. This is probably how a majority of the current victims got hijacked.