From: Glenn Jackman Date: 2009-10-08T04:55:21+09:00 Subject: Re: Safe command line execution At 2009-10-07 03:15PM, "Zundra Daniel" wrote: > Hi all. I have a application that needs to execute a system call via > command line. However, the problem I'm running into is this particular > command takes a username and password both of which can be any pattern and > combination of special characters. Does anyone know of a way to safely > execute this command with these free form parameters without risk of > malicious code being inadvertently executed? The pattern of the command is > as follows: > > /usr/bin/cmd -username #{username} -password #{password} Call system with more than one argument, and you don't get the shell involved: system "/usr/bin/cmd", "-username", username, "-password", password -- Glenn Jackman Write a wise saying and your name will live forever. -- Anonymous