Command Injection Filter Bypass Using Brace Expansion: Techniques from PayloadsAllTheThings

Brace expansion allows attackers to execute shell commands without spaces by using curly braces and commas, bypassing naive filters that block whitespace or rely on simple character whitelists.

The swisskyrepo/PayloadsAllTheThings repository documents comprehensive command injection methodologies, including shell-based filter evasions. One of the most effective techniques documented is brace expansion, which leverages bash and zsh preprocessing to execute commands while appearing as harmless punctuation to input validation filters.

How Brace Expansion Bypasses Filters

Brace expansion is a shell feature that generates multiple text strings from a pattern enclosed in curly braces. When the shell encounters {string1,string2}, it expands this into separate arguments before executing the command. This expansion occurs before word splitting and command execution, making the resulting space characters invisible to input filters that only inspect the raw payload string.

According to the source documentation in Command Injection/README.md (see line 165), the repository specifically catalogs this technique under Filter Bypasses → Bypass With Brace Expansion. The canonical payload format documented is:

{cat,/etc/passwd}

The shell processes this bypass through four distinct phases:

  1. Input Reception: The vulnerable application passes the raw string {cat,/etc/passwd} directly into a shell command.
  2. Brace Expansion: The shell expands the pattern into two separate tokens: cat and /etc/passwd.
  3. Token Assembly: The expanded tokens join the command line, effectively reconstructing cat /etc/passwd internally.
  4. Command Execution: The shell executes the final command, reading sensitive files despite filters that explicitly reject space characters in user input.

Because regex filters checking for [a-zA-Z0-9] or space detection mechanisms see only harmless braces and commas, the payload bypasses common sanitization routines while still achieving arbitrary command execution.

Practical Payload Examples

The following scenarios demonstrate how brace expansion evades different categories of command injection filters. All examples assume vulnerable code uses system(), exec(), or similar functions without proper parameterization.

Reading Files Without Spaces

When web application filters block the space character between a command and its argument, brace expansion provides the necessary separation internally:

<?php
// Vulnerable endpoint concatenating user input
$cmd = $_GET['cmd'];          // Attacker controls this value
system("bash -c '$cmd'");     // Direct shell invocation
?>

Attack payload:

http://example.com/vuln.php?cmd={cat,/etc/passwd}

The shell receives {cat,/etc/passwd}, expands it to cat /etc/passwd, and executes the file read without requiring a literal space in the HTTP parameter.

Injecting Into System Commands

Consider an application executing network diagnostics with user-controlled targets:


# Vulnerable application logic

exec "ping -c 4 $user_input"

Attacker input:

{cat,/etc/passwd}

Bash expands this to ping -c 4 cat /etc/passwd. While ping processes the invalid hostname arguments, the cat command executes successfully, outputting the password file contents after the diagnostic output.

Bypassing Alphanumeric Character Restrictions

Some web application firewalls whitelist only alphanumeric characters plus limited punctuation. Brace expansion requires only braces and commas, avoiding special characters detected by other bypass signatures:

{echo,hello}

This expands to echo hello, executing the command despite filters that might block parentheses, backticks, or dollar signs commonly used in alternative injection techniques.

Chaining with ${IFS} for Complex Commands

When injecting commands that inherently require spaces between multiple arguments, combine brace expansion with the Internal Field Separator variable:


# Payload construction bypassing space filters

payload="${IFS}{cat,/etc/passwd}"

The shell first substitutes ${IFS} with a space character, then performs brace expansion, resulting in the equivalent of cat /etc/passwd. This evades filters that specifically scan for literal space characters while allowing shell variable syntax.

Source Code Reference

The definitive implementation guidance resides in Command Injection/README.md within the PayloadsAllTheThings repository. This file categorizes brace expansion under the Filter Bypasses section and provides syntax variations for different shell environments.

Additional resources in the repository include:

  • Root README.md for navigation to the command injection chapter
  • Wordlist files under Command Injection/Intruder/ containing brace expansion payloads formatted for automated testing tools like Burp Suite

Summary

  • Brace expansion uses curly braces and commas to generate command arguments without literal spaces in the input string.
  • The technique bypasses filters that block whitespace or rely on simple alphanumeric whitelists by exploiting shell preprocessing.
  • As implemented in Command Injection/README.md, payloads like {cat,/etc/passwd} execute as cat /etc/passwd after expansion.
  • The bypass functions on any system using bash, zsh, or compatible shells, including default Linux and macOS environments.
  • Combining brace expansion with ${IFS} enables complex command structures while evading space-based detection mechanisms.

Frequently Asked Questions

What shells support brace expansion for command injection?

Bash and zsh support brace expansion by default, along with most modern Unix-like environments. The technique does not work in POSIX sh unless explicitly enabled, nor in restricted shells that disable expansion features.

Why does brace expansion bypass space filters?

The shell performs brace expansion during the preprocessing phase, before word splitting occurs. Filters inspecting the raw input see only {cat,/etc/passwd} without spaces, while the shell internally generates space-separated tokens during execution, rendering character-based sanitization ineffective.

Can brace expansion work with command substitution or pipes?

Yes, though the syntax requires additional characters. You can nest brace expansions and combine them with $() for command substitution, provided the target filter does not block the parentheses or dollar signs required for those constructs.

How do I detect if an application is vulnerable to this bypass?

Test inputs like {echo,test} or {id,} in potential injection points. If the application returns output containing "test" or user ID information despite filters blocking spaces, the target processes input through a shell with brace expansion enabled.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →