# PayloadsAllTheThings | Swissky | Knowledge Base | Instagit

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

GitHub Stars: 75.6k

Repository: https://github.com/swisskyrepo/PayloadsAllTheThings

---

## Articles

### [Data Exfiltration via Command Injection Using DNS-Based Methods: A Complete Guide](/swisskyrepo/PayloadsAllTheThings/data-exfiltration-via-command-injection-using-dns-based-methods)

Learn data exfiltration via command injection using DNS. Steal data through trusted outbound channels by encoding info into subdomain names and bypassing firewalls. Complete guide.

- Tags: how-to-guide
- Published: 2026-03-01

### [Data Exfiltration via Command Injection Using Time-Based Methods](/swisskyrepo/PayloadsAllTheThings/data-exfiltration-via-command-injection-using-time-based-methods)

Learn time-based data exfiltration using command injection. Discover how attackers exploit response delays to extract secrets bit-by-bit without direct output. Explore techniques from swisskyrepo/PayloadsAllTheThings.

- Tags: how-to-guide
- Published: 2026-03-01

### [Command Injection Filter Bypass Using Character Encoding: Techniques from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/command-injection-filter-bypass-using-character-encoding)

Bypass command injection filters using character encoding techniques. Learn to exploit shell variables hex sequences and Unicode normalization for attacks from PayloadsAllTheThings.

- Tags: how-to-guide
- Published: 2026-03-01

### [Command Injection Filter Bypass Using Brace Expansion: Techniques from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/command-injection-filter-bypass-using-brace-expansion)

Learn command injection filter bypass using brace expansion. Discover techniques to execute shell commands without spaces and evade naive filters.

- Tags: how-to-guide
- Published: 2026-03-01

### [Command Injection Filter Bypass Using Tilde Expansion: Exploiting Bash Path Expansion](/swisskyrepo/PayloadsAllTheThings/command-injection-filter-bypass-using-tilde-expansion)

Bypass command injection filters with Bash tilde expansion. Learn how to exploit path expansion in your security testing and prevent vulnerabilities.

- Tags: how-to-guide
- Published: 2026-03-01

### [Bypassing Command Injection Filters Without Spaces: 6 Shell Evasion Techniques](/swisskyrepo/PayloadsAllTheThings/bypassing-command-injection-filters-without-spaces)

Learn 6 shell evasion techniques for bypassing command injection filters without spaces. Explore IFS variables, brace expansion, redirection, and more to evade detection.

- Tags: deep-dive
- Published: 2026-03-01

### [Exploiting Argument Injection in Command Execution: Techniques from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/exploiting-argument-injection-in-command-execution)

Learn to exploit argument injection for command execution. Discover techniques bypassing sanitization using Unicode and shell variable abuse from PayloadsAllTheThings. Prevent command injection vulnerabilities now.

- Tags: tutorial
- Published: 2026-03-01

### [Command Injection Chaining Techniques: A Complete Guide to Shell Operators](/swisskyrepo/PayloadsAllTheThings/command-injection-chaining-techniques)

Master command injection chaining techniques to execute multiple shell commands with operators like ; && || & and |. Bypass filters and elevate your attack strategy.

- Tags: tutorial
- Published: 2026-03-01

### [Basic Command Injection Payloads: Essential Techniques from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/basic-command-injection-payloads)

Learn basic command injection payloads to execute OS commands by injecting shell metacharacters into vulnerable applications. Essential techniques from PayloadsAllTheThings.

- Tags: tutorial
- Published: 2026-03-01

### [SQLite Specific SQL Injection Payloads: A Complete Guide from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/sqlite-specific-sql-injection-payloads)

Explore SQLite specific SQL injection payloads from PayloadsAllTheThings to extract data or gain remote code execution. Learn techniques for embedded databases.

- Tags: how-to-guide
- Published: 2026-03-01

### [PostgreSQL Specific SQL Injection Payloads: A Complete Cheat Sheet from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/postgresql-specific-sql-injection-payloads)

Discover PostgreSQL specific SQL injection payloads to exploit unique functions for database enumeration, data exfiltration, and remote code execution. A complete cheat sheet.

- Tags: tutorial
- Published: 2026-03-01

### [Oracle SQL Specific SQL Injection Payloads: Techniques and Cheat Sheet](/swisskyrepo/PayloadsAllTheThings/oracle-sql-specific-sql-injection-payloads)

Discover Oracle SQL injection payloads with this cheat sheet covering enumeration, error-based, blind, time-based, OAST, RCE, and file manipulation techniques from Swisskyrepo PayloadsAllTheThings.

- Tags: cheat-sheet
- Published: 2026-03-01

### [MySQL Specific SQL Injection Payloads: Techniques and Examples from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/mysql-specific-sql-injection-payloads)

Discover MySQL specific SQL injection payloads to enumerate databases, extract data, and bypass WAFs. Explore techniques and examples from the PayloadsAllTheThings repository.

- Tags: tutorial
- Published: 2026-03-01

### [MSSQL Specific SQL Injection Payloads: Complete T-SQL Exploitation Guide](/swisskyrepo/PayloadsAllTheThings/mssql-specific-sql-injection-payloads)

Master MSSQL SQL injection with comprehensive T-SQL payloads from swisskyrepo. Explore enumeration, exploitation, and post-exploitation techniques for effective penetration testing.

- Tags: tutorial
- Published: 2026-03-01

### [Generic WAF Bypass for SQL Injection: Techniques from PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/generic-waf-bypass-for-sql-injection)

Learn generic WAF bypass techniques for SQL injection. Discover how to replace filtered characters using whitespace, comments, or operators to evade firewalls and secure your web applications.

- Tags: how-to-guide
- Published: 2026-03-01

### [SQL Injection with PDO Prepared Statements: Security Gaps in PHP Database Access](/swisskyrepo/PayloadsAllTheThings/sql-injection-with-pdo-prepared-statements)

Learn how SQL injection with PDO prepared statements happens in PHP due to identifier injection or identifier emulation. Secure your database access effectively.

- Tags: tutorial
- Published: 2026-03-01

### [Exploiting Stacked-Based SQL Injection: Multi-Statement Attack Techniques](/swisskyrepo/PayloadsAllTheThings/exploiting-stacked-based-sql-injection)

Learn to exploit stacked-based SQL injection with multi-statement attack techniques. Master data manipulation privilege escalation and remote code execution.

- Tags: tutorial
- Published: 2026-03-01

### [Blind SQL Injection Techniques: Boolean-Based and Time-Based Methods](/swisskyrepo/PayloadsAllTheThings/blind-sql-injection-techniques-boolean-based-and-time-based)

Master blind SQL injection techniques. Learn boolean-based and time-based methods to infer and extract data when direct results are hidden. Enhance your security skills today.

- Tags: tutorial
- Published: 2026-03-01

### [Error-Based SQL Injection Exploitation Methods: A Complete Guide](/swisskyrepo/PayloadsAllTheThings/error-based-sql-injection-exploitation-methods)

Master error-based SQL injection exploitation. Learn how to force databases to reveal data through error messages and bypass blind inference for efficient data extraction.

- Tags: how-to-guide
- Published: 2026-03-01

### [Exploiting UNION-based SQL Injection for Data Extraction: A Complete Guide](/swisskyrepo/PayloadsAllTheThings/exploiting-union-based-sql-injection-for-data-extraction)

Master UNION SQL injection to extract sensitive data. This guide explains how to exploit vulnerabilities by crafting malicious SELECT statements to retrieve any database records.

- Tags: how-to-guide
- Published: 2026-03-01

### [SQL Injection Authentication Bypass Techniques: A Complete Guide to PayloadsAllTheThings](/swisskyrepo/PayloadsAllTheThings/sql-injection-authentication-bypass-techniques)

Master SQL injection authentication bypass techniques. Learn to manipulate login queries with crafted payloads to gain unauthorized access. Your complete guide.

- Tags: how-to-guide
- Published: 2026-03-01

### [How to Identify Database Management Systems (DBMS) Using SQL Injection](/swisskyrepo/PayloadsAllTheThings/how-to-identify-database-management-systems-using-sql-injection)

Learn to identify database management systems (DBMS) with SQL injection. Discover vendor-specific functions and error analysis to detect DBMS types during security testing.

- Tags: how-to-guide
- Published: 2026-03-01

### [How to Detect Entry Points for SQL Injection: A Complete Guide to Finding Vulnerable Parameters](/swisskyrepo/PayloadsAllTheThings/how-to-detect-entry-points-for-sql-injection)

Learn to detect entry points for SQL injection. This guide details how to probe input vectors with payloads and analyze responses like errors or timing delays to find vulnerabilities.

- Tags: how-to-guide
- Published: 2026-03-01

