OK, no attack this time, but it could have been some evil page with a java script on it that did anything to your machine.

If so, then sorry it's too late now, by clicking on the [Sandbox] link you just invited in a TrojanHorse? to do whatever it liked.

Possible responses to the risk

Not everything inside [square] brackets gets transformed into a link. Only things that match a predefined set of protocols. Javascript isn't one of them.

To clarify the first person's objections--it is possible to write a link like [Some Nice Site] which leads you to a remote site. The destination (some.evil.site.example.org/badscript) could then use Javascript or do other nasty things. This possibility is the reason why I display the [] characters around the description. --CliffordAdams

Last edited July 26, 2008 12:29 pm by MarkusLude (diff)