← Downloads

netcat (OpenBSD) 1.229

Package v1.229 x86_64 TAR.GZ June 1, 2025

Reads and writes arbitrary TCP and UDP connections from the command line, for testing ports, talking to text protocols by hand, and moving files quickly across a trusted network.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
Debian Package Primary Global Download
OpenBSD Source Global Download

netcat opens raw network connections. That sounds too simple to be useful and covers a large amount of everyday debugging.

Which implementation

There are several with incompatible flags, which is the main source of confusion. OpenBSD netcat is the default on Debian and Ubuntu and the one most examples assume. GNU netcat and nmap’s Ncat also exist.

nc -h 2>&1 | head -3

The consequential difference is -N, which the OpenBSD version needs to close the connection after input ends. Without it, transfers hang.

Is the port open

nc -zv example.com 443
nc -zv -w 3 example.com 22      # with a timeout
nc -zvu example.com 53          # UDP

Always use -w in scripts, or a filtered port hangs until the TCP timeout. For more than a couple of ports use nmap.

Talking to a service by hand

nc example.com 80
GET / HTTP/1.1
Host: example.com
Connection: close

The blank line matters. You get the raw response with no client interpreting anything.

Same for SMTP on port 25: the banner and capability list tell you whether the server is reachable and what it offers in about ten seconds.

For TLS-wrapped protocols use openssl s_client instead, since netcat does not speak TLS.

Seeing what a client sends

nc -lk 8080 | tee capture.txt

Point a misbehaving webhook at it and read the raw request. This answers “what is that thing actually sending” definitively.

Moving a file

nc -l 9000 > received.tar.gz          # receiver
nc -N sender-target 9000 < archive.tar.gz    # sender

-N closes the connection when input ends. Forgetting it is the most commonly reported netcat problem.

No encryption, no authentication, no integrity check. Trusted local network only; use rsync over SSH for anything else.

The security note

netcat is a favourite for reverse shells and exfiltration, which is why many hardened images remove it and why finding it on a production server you did not install it on is worth investigating.

Our netcat guide covers the rest.

Verify Your Download

Install from your distribution repository, which is where the OpenBSD port is maintained.