From: Simon Krahnke Date: 2007-08-28T10:05:04+09:00 Subject: Re: Substitution within system quoted string * Matthias W�chter (23:41) schrieb: > On 27.08.2007 23:35, Felix Windt wrote: >> It's generally a very bad idea to give a password on the command line. I'm >> not sure if Windows keeps a command line history, but all it would take is >> for the DOS Prompt to still be open, and for someone to arrow up. > > Sure, but the problem is not limited to passwords. Any input you > cannot control or carefully check is bad if it is used in shell > expansion like the above. So better not start with it at the first > place, neither for passwords, nor for something like username@host > or other thought-to-be-friendly parameters. You are talking about two different things. Felix is about sensitive data, you seem to be about injection. The latter is only a problem, when the program is executed with other rights than its user, which is normally not the case with command line programs. mfg, simon .... l