netcat (OpenBSD) 1.229
Reads and writes arbitrary TCP and UDP connections from the command line, for testing ports, talking to text protocols by hand, and moving files quickly across a trusted network.
Download TAR.GZ Project website ↗Download Mirrors
netcat opens raw network connections. That sounds too simple to be useful and covers a large amount of everyday debugging.
Which implementation
There are several with incompatible flags, which is the main source of confusion. OpenBSD netcat is the default on Debian and Ubuntu and the one most examples assume. GNU netcat and nmap’s Ncat also exist.
nc -h 2>&1 | head -3
The consequential difference is -N, which the OpenBSD version needs to close the connection after input ends. Without it, transfers hang.
Is the port open
nc -zv example.com 443
nc -zv -w 3 example.com 22 # with a timeout
nc -zvu example.com 53 # UDP
Always use -w in scripts, or a filtered port hangs until the TCP timeout. For more than a couple of ports use nmap.
Talking to a service by hand
nc example.com 80
GET / HTTP/1.1
Host: example.com
Connection: close
The blank line matters. You get the raw response with no client interpreting anything.
Same for SMTP on port 25: the banner and capability list tell you whether the server is reachable and what it offers in about ten seconds.
For TLS-wrapped protocols use openssl s_client instead, since netcat does not speak TLS.
Seeing what a client sends
nc -lk 8080 | tee capture.txt
Point a misbehaving webhook at it and read the raw request. This answers “what is that thing actually sending” definitively.
Moving a file
nc -l 9000 > received.tar.gz # receiver
nc -N sender-target 9000 < archive.tar.gz # sender
-N closes the connection when input ends. Forgetting it is the most commonly reported netcat problem.
No encryption, no authentication, no integrity check. Trusted local network only; use rsync over SSH for anything else.
The security note
netcat is a favourite for reverse shells and exfiltration, which is why many hardened images remove it and why finding it on a production server you did not install it on is worth investigating.
Our netcat guide covers the rest.
Verify Your Download
Install from your distribution repository, which is where the OpenBSD port is maintained.