# Command Injection Filter Bypass Using Brace Expansion: Techniques from PayloadsAllTheThings

> Learn command injection filter bypass using brace expansion. Discover techniques to execute shell commands without spaces and evade naive filters.

- Repository: [Swissky/PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)
- Tags: how-to-guide
- Published: 2026-03-01

---

**Brace expansion allows attackers to execute shell commands without spaces by using curly braces and commas, bypassing naive filters that block whitespace or rely on simple character whitelists.**

The swisskyrepo/PayloadsAllTheThings repository documents comprehensive command injection methodologies, including shell-based filter evasions. One of the most effective techniques documented is **brace expansion**, which leverages bash and zsh preprocessing to execute commands while appearing as harmless punctuation to input validation filters.

## How Brace Expansion Bypasses Filters

Brace expansion is a shell feature that generates multiple text strings from a pattern enclosed in curly braces. When the shell encounters `{string1,string2}`, it expands this into separate arguments before executing the command. This expansion occurs **before** word splitting and command execution, making the resulting space characters invisible to input filters that only inspect the raw payload string.

According to the source documentation in `Command Injection/README.md` (see line 165), the repository specifically catalogs this technique under *Filter Bypasses → Bypass With Brace Expansion*. The canonical payload format documented is:

```bash
{cat,/etc/passwd}

```

The shell processes this bypass through four distinct phases:

1. **Input Reception**: The vulnerable application passes the raw string `{cat,/etc/passwd}` directly into a shell command.
2. **Brace Expansion**: The shell expands the pattern into two separate tokens: `cat` and `/etc/passwd`.
3. **Token Assembly**: The expanded tokens join the command line, effectively reconstructing `cat /etc/passwd` internally.
4. **Command Execution**: The shell executes the final command, reading sensitive files despite filters that explicitly reject space characters in user input.

Because regex filters checking for `[a-zA-Z0-9]` or space detection mechanisms see only harmless braces and commas, the payload bypasses common sanitization routines while still achieving arbitrary command execution.

## Practical Payload Examples

The following scenarios demonstrate how brace expansion evades different categories of command injection filters. All examples assume vulnerable code uses `system()`, `exec()`, or similar functions without proper parameterization.

### Reading Files Without Spaces

When web application filters block the space character between a command and its argument, brace expansion provides the necessary separation internally:

```php
<?php
// Vulnerable endpoint concatenating user input
$cmd = $_GET['cmd'];          // Attacker controls this value
system("bash -c '$cmd'");     // Direct shell invocation
?>

```

**Attack payload:**

```http
http://example.com/vuln.php?cmd={cat,/etc/passwd}

```

The shell receives `{cat,/etc/passwd}`, expands it to `cat /etc/passwd`, and executes the file read without requiring a literal space in the HTTP parameter.

### Injecting Into System Commands

Consider an application executing network diagnostics with user-controlled targets:

```bash

# Vulnerable application logic

exec "ping -c 4 $user_input"

```

**Attacker input:**

```bash
{cat,/etc/passwd}

```

Bash expands this to `ping -c 4 cat /etc/passwd`. While `ping` processes the invalid hostname arguments, the `cat` command executes successfully, outputting the password file contents after the diagnostic output.

### Bypassing Alphanumeric Character Restrictions

Some web application firewalls whitelist only alphanumeric characters plus limited punctuation. Brace expansion requires only braces and commas, avoiding special characters detected by other bypass signatures:

```bash
{echo,hello}

```

This expands to `echo hello`, executing the command despite filters that might block parentheses, backticks, or dollar signs commonly used in alternative injection techniques.

### Chaining with ${IFS} for Complex Commands

When injecting commands that inherently require spaces between multiple arguments, combine brace expansion with the Internal Field Separator variable:

```bash

# Payload construction bypassing space filters

payload="${IFS}{cat,/etc/passwd}"

```

The shell first substitutes `${IFS}` with a space character, then performs brace expansion, resulting in the equivalent of `cat /etc/passwd`. This evades filters that specifically scan for literal space characters while allowing shell variable syntax.

## Source Code Reference

The definitive implementation guidance resides in `Command Injection/README.md` within the PayloadsAllTheThings repository. This file categorizes brace expansion under the *Filter Bypasses* section and provides syntax variations for different shell environments.

Additional resources in the repository include:
- Root [`README.md`](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/main/README.md) for navigation to the command injection chapter
- Wordlist files under `Command Injection/Intruder/` containing brace expansion payloads formatted for automated testing tools like Burp Suite

## Summary

- **Brace expansion** uses curly braces and commas to generate command arguments without literal spaces in the input string.
- The technique bypasses filters that block whitespace or rely on simple alphanumeric whitelists by exploiting shell preprocessing.
- As implemented in `Command Injection/README.md`, payloads like `{cat,/etc/passwd}` execute as `cat /etc/passwd` after expansion.
- The bypass functions on any system using bash, zsh, or compatible shells, including default Linux and macOS environments.
- Combining brace expansion with `${IFS}` enables complex command structures while evading space-based detection mechanisms.

## Frequently Asked Questions

### What shells support brace expansion for command injection?

Bash and zsh support brace expansion by default, along with most modern Unix-like environments. The technique does not work in POSIX sh unless explicitly enabled, nor in restricted shells that disable expansion features.

### Why does brace expansion bypass space filters?

The shell performs brace expansion during the preprocessing phase, before word splitting occurs. Filters inspecting the raw input see only `{cat,/etc/passwd}` without spaces, while the shell internally generates space-separated tokens during execution, rendering character-based sanitization ineffective.

### Can brace expansion work with command substitution or pipes?

Yes, though the syntax requires additional characters. You can nest brace expansions and combine them with `$()` for command substitution, provided the target filter does not block the parentheses or dollar signs required for those constructs.

### How do I detect if an application is vulnerable to this bypass?

Test inputs like `{echo,test}` or `{id,}` in potential injection points. If the application returns output containing "test" or user ID information despite filters blocking spaces, the target processes input through a shell with brace expansion enabled.