PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

23 articles 75.6k View on GitHub ↗
23 articles
Data Exfiltration via Command Injection Using DNS-Based Methods: A Complete Guide

Learn data exfiltration via command injection using DNS. Steal data through trusted outbound channels by encoding info into subdomain names and bypassing firewalls. Complete guide.

how-to-guide
Mar 1, 2026
Data Exfiltration via Command Injection Using Time-Based Methods

Learn time-based data exfiltration using command injection. Discover how attackers exploit response delays to extract secrets bit-by-bit without direct output. Explore techniques from swisskyrepo/PayloadsAllTheThings.

how-to-guide
Mar 1, 2026
Command Injection Filter Bypass Using Character Encoding: Techniques from PayloadsAllTheThings

Bypass command injection filters using character encoding techniques. Learn to exploit shell variables hex sequences and Unicode normalization for attacks from PayloadsAllTheThings.

how-to-guide
Mar 1, 2026
Command Injection Filter Bypass Using Brace Expansion: Techniques from PayloadsAllTheThings

Learn command injection filter bypass using brace expansion. Discover techniques to execute shell commands without spaces and evade naive filters.

how-to-guide
Mar 1, 2026
Command Injection Filter Bypass Using Tilde Expansion: Exploiting Bash Path Expansion

Bypass command injection filters with Bash tilde expansion. Learn how to exploit path expansion in your security testing and prevent vulnerabilities.

how-to-guide
Mar 1, 2026
Bypassing Command Injection Filters Without Spaces: 6 Shell Evasion Techniques

Learn 6 shell evasion techniques for bypassing command injection filters without spaces. Explore IFS variables, brace expansion, redirection, and more to evade detection.

deep-dive
Mar 1, 2026
Exploiting Argument Injection in Command Execution: Techniques from PayloadsAllTheThings

Learn to exploit argument injection for command execution. Discover techniques bypassing sanitization using Unicode and shell variable abuse from PayloadsAllTheThings. Prevent command injection vulnerabilities now.

tutorial
Mar 1, 2026
Command Injection Chaining Techniques: A Complete Guide to Shell Operators

Master command injection chaining techniques to execute multiple shell commands with operators like ; && || & and |. Bypass filters and elevate your attack strategy.

tutorial
Mar 1, 2026
Basic Command Injection Payloads: Essential Techniques from PayloadsAllTheThings

Learn basic command injection payloads to execute OS commands by injecting shell metacharacters into vulnerable applications. Essential techniques from PayloadsAllTheThings.

tutorial
Mar 1, 2026
SQLite Specific SQL Injection Payloads: A Complete Guide from PayloadsAllTheThings

Explore SQLite specific SQL injection payloads from PayloadsAllTheThings to extract data or gain remote code execution. Learn techniques for embedded databases.

how-to-guide
Mar 1, 2026
PostgreSQL Specific SQL Injection Payloads: A Complete Cheat Sheet from PayloadsAllTheThings

Discover PostgreSQL specific SQL injection payloads to exploit unique functions for database enumeration, data exfiltration, and remote code execution. A complete cheat sheet.

tutorial
Mar 1, 2026
Oracle SQL Specific SQL Injection Payloads: Techniques and Cheat Sheet

Discover Oracle SQL injection payloads with this cheat sheet covering enumeration, error-based, blind, time-based, OAST, RCE, and file manipulation techniques from Swisskyrepo PayloadsAllTheThings.

cheat-sheet
Mar 1, 2026

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →