On 14/02/2012, at 9:30 AM, Gé Weijers wrote: > > > On Mon, Feb 13, 2012 at 1:49 PM, Steve Bennett <[email protected]> wrote: > Joe Mistachkin has recently added support for calling TH1 scripts on certain > actions. > See http://www.fossil-scm.org/index.html/info/0b61e3c019 > > In the jimtcl branch, TH1 is replaced with Jim Tcl, so any of these scripts > has the full power of Jim Tcl, including exec. > > > This sounds a whole lot like mobile code. I was left wondering: would it be > enough to do a 'fossil clone <something>' to download a malware script > onto my system? How is this capability secured?
I'm sure Joe could tell you how it is implemented, but I don't see how it would make any sense to clone these scripts. Aren't some settings transferred with clone and some not? Surely these are in the "not" group. Cheers, Steve -- µWeb: Embedded Web Framework - http://uweb.workware.net.au/ WorkWare Systems Pty Ltd W: www.workware.net.au P: +61 434 921 300 E: [email protected] F: +61 7 3391 6002
_______________________________________________ fossil-users mailing list [email protected] http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

