Skip to main content

Basic Payloads

Inject after shell metacharacters: the app concatenates your input into a system call, so append a second command with a separator.

Blind Detection

When there’s no visible output, use time delays or out-of-band callbacks to confirm execution.

Bypass Filters

Filters often look for specific characters or keywords: use IFS, brace expansion, or string splitting to reconstruct the command without triggering them.
When the target strips literal spaces, substitute each one with an IFS variable, a brace-expanded argument list, a URL-encoded tab, or an ANSI-C quoted space. Note that ${IFS} works in bash and sh but not in fish.
When the injection travels through a URL-encoded form body or HTTP parameter, these characters carry additional meaning that must be escaped before your payload is interpreted by the shell.
Quote-breaking splits a keyword across adjacent empty quote pairs so a naive string-match filter misses it while the shell reassembles the full command.
A real-world example from CozyHosting (HTB): the app reflected the username POST parameter directly into a shell command, and a literal & in the body would split the parameter before the shell saw it. Replacing spaces with ${IFS} and injecting after a ; separator gives a dropper one-liner that passes through both the URL decoder and the filter.