# Bypassing Command Injection Filters Without Spaces: 6 Shell Evasion Techniques

> Learn 6 shell evasion techniques for bypassing command injection filters without spaces. Explore IFS variables, brace expansion, redirection, and more to evade detection.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: deep-dive
- Published: 2026-03-01

---

**You can bypass command injection filters that block literal spaces by using shell constructs like the `${IFS}` variable, brace expansion, input redirection, ANSI-C quoting, tab characters, or Windows substring syntax, which the underlying interpreter normalizes into whitespace before execution.**

Command injection filters often reject payloads containing space characters under the assumption that removing spaces prevents command chaining and argument injection. The **swisskyrepo/PayloadsAllTheThings** repository documents reliable techniques for circumventing such filters by leveraging alternative whitespace representations that Bash, cmd.exe, and PowerShell process as valid delimiters.

## Using the IFS Variable for Whitespace Substitution

The **Internal Field Separator** (`$IFS`) is a shell variable that holds the default whitespace characters—space, tab, and newline. When expanded as `${IFS}`, the shell substitutes it with an actual space character, allowing arguments to be passed without literal space bytes in the payload.

According to the source code in `Command Injection/README.md`, this is one of the most reliable Linux bypass techniques documented in the "Bypass Without Space" section.

**Linux Bash:**

```bash
cat${IFS}/etc/passwd

```

**Windows cmd.exe:**

```cmd
type${IFS}C:\Windows\win.ini

```

## Brace Expansion to Separate Arguments

**Brace expansion** is a Bash feature where `{command,argument}` expands into `command argument` during evaluation. The shell processes the comma-separated content as distinct tokens, effectively inserting a space where none appears in the original payload string.

**Linux Bash:**

```bash
{cat,/etc/passwd}

```

**Windows PowerShell:**

```powershell
{"type","C:\\Windows\\win.ini"}

```

## Input Redirection Operators

The **input redirection operator** (`<`) reads a file as standard input for the preceding command. This construct requires no space between the command and the operator, completely avoiding the need for whitespace characters while still passing the filename as an argument.

**Linux Bash:**

```bash
cat</etc/passwd

```

**Windows cmd.exe:**

```cmd
type<%SystemRoot%\win.ini

```

## ANSI-C Quoting for Hexadecimal Spaces

**ANSI-C quoting** uses the `$'…'` syntax to enable escape-sequence representation of characters. By specifying `\x20` (the hexadecimal value for space), you can inject a literal space character into the command string at runtime without including a raw space in the payload.

**Linux Bash:**

```bash
X=$'cat\x20/etc/passwd'&&$X

```

**Windows PowerShell:**

```powershell
powershell -Command "$x = 'type\x20C:\\Windows\\win.ini'; iex $x"

```

## Tab Characters and URL Encoding

The **tab character** (`0x09`) is accepted as whitespace by most Unix shells and can replace spaces in command sequences. When performing HTTP-based command injection, URL-encoding the tab as `%09` bypasses filters that only block the space character (`0x20`).

**URL-encoded payload:**

```http
;ls%09-al%09/home

```

**Windows cmd.exe:**

```cmd
dir%09C:\\

```

## Windows Variable Substring Splicing

On Windows systems, the **substring expansion syntax** `%VARIABLE:~start,length%` can extract a space character from environment variables that contain them. For example, `%CommonProgramFiles%` contains spaces, and slicing specific indices yields a single space character for command separation.

**Windows cmd.exe:**

```cmd
ping%CommonProgramFiles:~10,-18%127.0.0.1

```

This extracts the space from the `CommonProgramFiles` environment variable (typically `C:\Program Files\Common Files`) and inserts it between `ping` and the IP address.

## Key Source Files in PayloadsAllTheThings

The repository organizes these techniques across specific files that security researchers and penetration testers reference directly:

- **`Command Injection/README.md`** – Contains the primary documentation of command-injection vectors, including the dedicated "Bypass Without Space" section that catalogs each technique with syntax examples.
- **`Command Injection/Intruder/command_exec.txt`** – Provides a curated list of raw payload strings ready for direct use in testing tools like Burp Suite Intruder.
- **[`README.md`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/README.md)** – Offers the general repository overview and navigation structure to locate specific attack vectors.

## Summary

- **`${IFS}`** – Substitutes the Internal Field Separator variable to generate whitespace without literal spaces.
- **Brace expansion** – Uses `{cmd,arg}` syntax to force the shell to separate tokens with spaces during expansion.
- **Input redirection** – Employs the `<` operator to pass filenames as arguments without requiring whitespace.
- **ANSI-C quoting** – Leverages `$'\x20'` to encode spaces as hexadecimal escape sequences.
- **Tab characters** – Replaces spaces with `%09` (hexadecimal tab), which shells interpret as valid whitespace.
- **Windows substring** – Extracts spaces from environment variables using `%VAR:~start,end%` syntax.

## Frequently Asked Questions

### What is the IFS variable in command injection bypasses?

The **IFS** (Internal Field Separator) is a shell environment variable that stores the characters used to split words into tokens—typically space, tab, and newline. When referenced as `${IFS}` in a command injection payload, the shell expands it to a literal space character, allowing command and argument separation without using an actual space byte that filters might block.

### How does brace expansion work without spaces?

**Brace expansion** is a Bash shell feature that expands comma-separated strings inside curly braces into separate arguments. When the shell processes `{cat,/etc/passwd}`, it internally generates `cat /etc/passwd` with an actual space between the tokens, even though the original payload contained no space character. This happens during the shell's evaluation phase before command execution.

### Can these techniques be combined for stronger evasion?

Yes, combining techniques increases evasion against sophisticated filters. For example, you can nest `${IFS}` inside brace expansion like `{cat,${IFS}/etc/passwd}` or combine ANSI-C quoting with variable assignment to bypass filters that whitelist specific characters. The `Command Injection/Intruder/command_exec.txt` file in the PayloadsAllTheThings repository contains examples of such combined payloads.

### Where are these payloads documented in PayloadsAllTheThings?

All space-bypass techniques are documented in the **`Command Injection/README.md`** file under the "Bypass Without Space" section, as implemented in swisskyrepo/PayloadsAllTheThings. This section provides platform-specific examples for Linux Bash, Windows cmd.exe, and PowerShell, along with explanations of why each method works at the shell level.