From: Ryan Davis Date: 2010-02-09T15:08:36+09:00 Subject: Re: Looking for external program invocations On Feb 8, 2010, at 16:11 , Mark Hobley wrote: > I have some open source software packages that were written in Ruby by a third > party that make use of external programs. For the purposes of security > auditing, and for making appropriate fixes, I need to locate all instances > within the code, where an external program is being called. > > What keywords or functions would I need to locate? There are quite a number of them. Here are some of them: `cmd` or %x"cmd" (arbitrary delimiters for %x) system IO.popen File.open You should also look at IO.fork, IO.pipe, anything using the Process class, and probably a lot of other stuff. Look at "Spawning new processes" in Programming Ruby: "The file-naming convention of many IO methods and Kernel.open will also spawn subprocesses if you put a | as the first character of the filename." Make sure you realize the implications of what you're doing. As others have pointed out, to do a _real_ job of security audit, you need to know the language. If you're just doing a CYA, that's another story.