Now that even "client-server" applications like the one at
[url]http://www.lamborghini.com[/url] are made with shockwave rather than Java,
i wonder if there isn't a security problem.

Can a schockwave applet e.g. open a "trojan" TCP-port and listen for
incoming requests, using it for spam etc.?
Or worse, can it access files from the computer, run a Key-Logger, send
recorded data to some eMail-address etc.?

Java applets could be granted and denied a large variety of security
privileges, including domain-dependent grants for TCP-connections. I
wonder how [url]http://www.lamborghini.com[/url] would have turned out as a
Java-Applet - several MBs larger, for sure.