Hi Tony,

For obvious security reasons, this really should not work in any
browser that gives a damn about your computer's health. I really
wonder how come it does.

At first, clicking on any of the links when looking at...

http://www.remotely-helpful.com/TiddlyWiki/LaunchApplication.html

...did one of two things:

in Firefox: absolutely nothing
in Internet Explorer: hello bluescreen

But now that I have rebooted, downloaded that wiki and locally
modified the paths in the macro tiddler to the correct locations on my
xp installation ...it actually does start the processes!

Big ouch! I mean, how terrifying is that?!

This is so inviting to anything malicious that it's rather painful to
see it work. At least, thinking that a dynamically loaded library
could run stuff on my machine with this is not what I would call
comforting ...or can it not?

So, topmost priority for any TiddlyWiki that you run locally and which
makes use of this is to NEVER load any javascript from a remote server
into such a TiddlyWiki or to have plugins installed that contact
remote servers to load stuff on demand.

Other than that, if you're 100% certain about what you're
doing ...this is really cool stuff allowing you to mix and match
TiddlyWiki information management with your local files and
applications corresponding to your tiddlers content, esp. in
combination with FileDropPlugin [1].

As for your question, I simply created a windows link that runs a
program with certain parameters and, of course, shudder, it executed.

When it comes to white spaces or other special characters in a path/
filename ...well, don't use them.

Would you mind sharing what specifically you use this for?


Cheers, Tobias.

[1] http://tiddlytools.com/#FileDropPlugin

-- 
You received this message because you are subscribed to the Google Groups 
"TiddlyWiki" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/tiddlywiki?hl=en.

Reply via email to