You can test by running this ruby file: https://gist.github.com/4499206
$ ruby rails_rce.rb http://localhost:3000 param "User.destroy_all"
You can test by running this ruby file: https://gist.github.com/4499206
Monitor your server and ensure it is disregarding the post parameters.