← All cheat sheets

scp

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

BASIC SYNTAX#

scp [options] source destination

BASIC USAGE#

# Local to remote
scp file.txt user@host:/path/                 # Copy file to remote
scp file.txt user@host:/path/newname.txt      # Copy with new name
scp file.txt user@host:~                      # Copy to home directory
scp file.txt user@host:                       # Copy to home (short)

# Remote to local
scp user@host:/path/file.txt .                # Copy to current dir
scp user@host:/path/file.txt /local/path/     # Copy to specific path
scp user@host:~/file.txt .                    # Copy from home dir

# Remote to remote
scp user1@host1:/path/file user2@host2:/path/

DIRECTORY COPYING#

scp -r dir/ user@host:/path/                  # Copy directory recursively
scp -r user@host:/path/dir/ ./                # Copy remote dir locally
scp -rp dir/ user@host:/path/                 # Preserve permissions

COMMON OPTIONS#

-r                                  # Recursive (for directories)
-p                                  # Preserve modification times, modes
-P port                             # Specify port (uppercase P!)
-i keyfile                          # Use identity/private key file
-C                                  # Enable compression
-q                                  # Quiet mode (no progress)
-v                                  # Verbose mode
-l limit                            # Limit bandwidth (Kbit/s)
-o option                           # SSH option
-F configfile                       # SSH config file
-c cipher                           # Specify cipher
-3                                  # Copy through local host

PORT SPECIFICATION#

scp -P 2222 file.txt user@host:/path/         # Custom SSH port
scp -P 2222 user@host:/path/file.txt ./

KEY AUTHENTICATION#

scp -i ~/.ssh/mykey file.txt user@host:/path/
scp -i ~/.ssh/id_rsa -P 2222 file.txt user@host:/path/

COMPRESSION#

scp -C file.txt user@host:/path/              # Compress during transfer
scp -C -r largedir/ user@host:/path/          # Compress directory

BANDWIDTH LIMITING#

scp -l 1000 file.txt user@host:/path/         # Limit to 1000 Kbit/s
scp -l 8000 largefile.iso user@host:/path/    # Limit to ~1 MB/s

MULTIPLE FILES#

scp file1.txt file2.txt user@host:/path/
scp *.txt user@host:/path/
scp file{1,2,3}.txt user@host:/path/
scp user@host:"/path/file1.txt /path/file2.txt" ./
scp user@host:"/path/*.log" ./

USING SSH CONFIG#

# In ~/.ssh/config
Host myserver
    HostName 192.168.1.100
    User admin
    Port 2222
    IdentityFile ~/.ssh/mykey

# Then use:
scp file.txt myserver:/path/
scp myserver:/path/file.txt ./

VERBOSE OUTPUT#

scp -v file.txt user@host:/path/              # Verbose
scp -vv file.txt user@host:/path/             # More verbose
scp -vvv file.txt user@host:/path/            # Debug level

SPECIAL CHARACTERS IN PATHS#

# Spaces in filename
scp "file name.txt" user@host:/path/
scp user@host:"/path/file name.txt" ./

# Escape spaces
scp file\ name.txt user@host:/path/
scp user@host:/path/file\ name.txt ./

# Remote path with spaces
scp user@host:"/path/with spaces/file.txt" ./

COPYING THROUGH JUMP HOST#

# Using ProxyJump (-J)
scp -J jumpuser@jumphost file.txt user@target:/path/

# Using ProxyCommand
scp -o ProxyCommand="ssh -W %h:%p jumphost" file.txt user@target:/path/

# Multiple jumps
scp -J user1@jump1,user2@jump2 file.txt user@target:/path/

SSH OPTIONS#

# Disable strict host key checking
scp -o StrictHostKeyChecking=no file.txt user@host:/path/

# Ignore known hosts
scp -o UserKnownHostsFile=/dev/null file.txt user@host:/path/

# Connection timeout
scp -o ConnectTimeout=10 file.txt user@host:/path/

# Combined options
scp -o "StrictHostKeyChecking=no" -o "UserKnownHostsFile=/dev/null" file.txt user@host:/path/

PRACTICAL EXAMPLES#

# Backup local directory to remote
scp -rp /local/data/ user@host:/backup/

# Download website files
scp -r user@host:/var/www/html/ ./backup/

# Transfer with limited bandwidth
scp -l 5000 -C largefile.tar.gz user@host:/path/

# Copy between two remote hosts via local
scp -3 user1@host1:/path/file user2@host2:/path/

# Sync config file to multiple servers
for host in server1 server2 server3; do
    scp config.conf user@$host:/etc/app/
done

# Download multiple files
scp user@host:"/var/log/*.log" ./logs/

COMPARISON WITH OTHER TOOLS#

# SCP - Simple, one-time transfers
scp file.txt user@host:/path/

# SFTP - Interactive, browsing
sftp user@host
sftp> put file.txt
sftp> get remote.txt

# Rsync - Synchronization, incremental
rsync -avz file.txt user@host:/path/

# When to use what:
# - SCP: Quick one-time transfers
# - SFTP: Interactive file management
# - Rsync: Backups, syncing, large/repeated transfers

ERROR HANDLING#

# Check return code
scp file.txt user@host:/path/
if [ $? -eq 0 ]; then
    echo "Transfer successful"
else
    echo "Transfer failed"
fi

SECURITY NOTES#

- SCP uses SSH for encryption
- Prefer key-based authentication
- Use specific ciphers for performance: -c aes128-ctr
- Avoid disabling host key checking in production
- SCP is being deprecated in favor of SFTP/rsync

TROUBLESHOOTING#

# Verbose output for debugging
scp -vvv file.txt user@host:/path/

# Test SSH connection first
ssh user@host echo "Connection OK"

# Check permissions on remote path
ssh user@host ls -la /path/

# Common issues:
# - Permission denied: Check user permissions, key
# - Connection refused: Check SSH service, port
# - No such file: Verify paths
# - Connection timeout: Check firewall, network

ALTERNATIVES#

sftp                                # SSH File Transfer Protocol
rsync                               # Incremental sync
lftp                                # Advanced FTP/SFTP client
rclone                              # Cloud storage sync