From: Henning Bekel Date: 2009-10-08T05:00:06+09:00 Subject: Re: Safe command line execution Zundra Daniel wrote: > Does anyone know of a way to safely execute this command with > these free form parameters without risk of malicious code being > inadvertently executed? The pattern of the command is as > follows: > > /usr/bin/cmd -username #{username} -password #{password} Just avoid any shell expansion. This can be done by passing the arguments to Kernel#system individually: system("/usr/bin/cmd", "-username", username, "-password", password) See the docs for Kernel#system and Kernel#exec. Henning