Bypassing Command Injection Filters Without Spaces: 6 Shell Evasion Techniques

You can bypass command injection filters that block literal spaces by using shell constructs like the ${IFS} variable, brace expansion, input redirection, ANSI-C quoting, tab characters, or Windows substring syntax, which the underlying interpreter normalizes into whitespace before execution.

Command injection filters often reject payloads containing space characters under the assumption that removing spaces prevents command chaining and argument injection. The swisskyrepo/PayloadsAllTheThings repository documents reliable techniques for circumventing such filters by leveraging alternative whitespace representations that Bash, cmd.exe, and PowerShell process as valid delimiters.

Using the IFS Variable for Whitespace Substitution

The Internal Field Separator ($IFS) is a shell variable that holds the default whitespace characters—space, tab, and newline. When expanded as ${IFS}, the shell substitutes it with an actual space character, allowing arguments to be passed without literal space bytes in the payload.

According to the source code in Command Injection/README.md, this is one of the most reliable Linux bypass techniques documented in the "Bypass Without Space" section.

Linux Bash:

cat${IFS}/etc/passwd

Windows cmd.exe:

type${IFS}C:\Windows\win.ini

Brace Expansion to Separate Arguments

Brace expansion is a Bash feature where {command,argument} expands into command argument during evaluation. The shell processes the comma-separated content as distinct tokens, effectively inserting a space where none appears in the original payload string.

Linux Bash:

{cat,/etc/passwd}

Windows PowerShell:

{"type","C:\\Windows\\win.ini"}

Input Redirection Operators

The input redirection operator (<) reads a file as standard input for the preceding command. This construct requires no space between the command and the operator, completely avoiding the need for whitespace characters while still passing the filename as an argument.

Linux Bash:

cat</etc/passwd

Windows cmd.exe:

type<%SystemRoot%\win.ini

ANSI-C Quoting for Hexadecimal Spaces

ANSI-C quoting uses the $'…' syntax to enable escape-sequence representation of characters. By specifying \x20 (the hexadecimal value for space), you can inject a literal space character into the command string at runtime without including a raw space in the payload.

Linux Bash:

X=$'cat\x20/etc/passwd'&&$X

Windows PowerShell:

powershell -Command "$x = 'type\x20C:\\Windows\\win.ini'; iex $x"

Tab Characters and URL Encoding

The tab character (0x09) is accepted as whitespace by most Unix shells and can replace spaces in command sequences. When performing HTTP-based command injection, URL-encoding the tab as %09 bypasses filters that only block the space character (0x20).

URL-encoded payload:

;ls%09-al%09/home

Windows cmd.exe:

dir%09C:\\

Windows Variable Substring Splicing

On Windows systems, the substring expansion syntax %VARIABLE:~start,length% can extract a space character from environment variables that contain them. For example, %CommonProgramFiles% contains spaces, and slicing specific indices yields a single space character for command separation.

Windows cmd.exe:

ping%CommonProgramFiles:~10,-18%127.0.0.1

This extracts the space from the CommonProgramFiles environment variable (typically C:\Program Files\Common Files) and inserts it between ping and the IP address.

Key Source Files in PayloadsAllTheThings

The repository organizes these techniques across specific files that security researchers and penetration testers reference directly:

  • Command Injection/README.md – Contains the primary documentation of command-injection vectors, including the dedicated "Bypass Without Space" section that catalogs each technique with syntax examples.
  • Command Injection/Intruder/command_exec.txt – Provides a curated list of raw payload strings ready for direct use in testing tools like Burp Suite Intruder.
  • README.md – Offers the general repository overview and navigation structure to locate specific attack vectors.

Summary

  • ${IFS} – Substitutes the Internal Field Separator variable to generate whitespace without literal spaces.
  • Brace expansion – Uses {cmd,arg} syntax to force the shell to separate tokens with spaces during expansion.
  • Input redirection – Employs the < operator to pass filenames as arguments without requiring whitespace.
  • ANSI-C quoting – Leverages $'\x20' to encode spaces as hexadecimal escape sequences.
  • Tab characters – Replaces spaces with %09 (hexadecimal tab), which shells interpret as valid whitespace.
  • Windows substring – Extracts spaces from environment variables using %VAR:~start,end% syntax.

Frequently Asked Questions

What is the IFS variable in command injection bypasses?

The IFS (Internal Field Separator) is a shell environment variable that stores the characters used to split words into tokens—typically space, tab, and newline. When referenced as ${IFS} in a command injection payload, the shell expands it to a literal space character, allowing command and argument separation without using an actual space byte that filters might block.

How does brace expansion work without spaces?

Brace expansion is a Bash shell feature that expands comma-separated strings inside curly braces into separate arguments. When the shell processes {cat,/etc/passwd}, it internally generates cat /etc/passwd with an actual space between the tokens, even though the original payload contained no space character. This happens during the shell's evaluation phase before command execution.

Can these techniques be combined for stronger evasion?

Yes, combining techniques increases evasion against sophisticated filters. For example, you can nest ${IFS} inside brace expansion like {cat,${IFS}/etc/passwd} or combine ANSI-C quoting with variable assignment to bypass filters that whitelist specific characters. The Command Injection/Intruder/command_exec.txt file in the PayloadsAllTheThings repository contains examples of such combined payloads.

Where are these payloads documented in PayloadsAllTheThings?

All space-bypass techniques are documented in the Command Injection/README.md file under the "Bypass Without Space" section, as implemented in swisskyrepo/PayloadsAllTheThings. This section provides platform-specific examples for Linux Bash, Windows cmd.exe, and PowerShell, along with explanations of why each method works at the shell level.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →