Skip to content

Netcat

Read and write network connections from the terminal

VerifiedNetworking· Connectivity & TransferBeginnerBSD-3-Clause (OpenBSD variant)Open sourceEntry revised 8 Jan 2026
  • Linux
  • macOS
  • Windows
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Docker

Overview

5 commands documented

Netcat opens a TCP or UDP socket and connects it to standard input and output. That single idea covers banner reading, port reachability checks, ad-hoc file transfer between two lab hosts, and a quick listener to see what a client sends.

Two lineages exist — OpenBSD netcat and GNU netcat — with different flags. Check `nc -h` on your system rather than trusting a blog post, and note that the `-e` execution option is deliberately absent from hardened builds.

Supported platforms

8

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

tcp, udp, listener, transfer, diagnostics

Dataset entry

netcat.ts

Reviewed 2026-01-08

Installation

Grouped by platform. Elevation requirements are marked per method.

Ships with macOS

Recommendedsystem
nc -h

Package availability follows your distribution and enabled repositories. Entry revised 8 Jan 2026 — confirm the current release on the project's own download page.

Commands

5 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Read a service banner

bash

Opens a connection and prints what the remote side says first.

nc -nv 192.0.2.10 25

Example output

Illustrative only — real output depends on the target, version and your position on the network.

220 mail.internal ESMTP Postfix

02Check reachability without sending data

bash

The `-z` scan reports whether a connection succeeds, which answers firewall questions faster than a full port scan.

nc -zvu 192.0.2.10 53

Notes

  • UDP with `-z` reports success even when nothing is listening on many stacks; treat UDP results as inconclusive.

03Listener for a controlled test

bash

Accepts one connection and prints what arrives — used to confirm a client's outbound path in a lab.

nc -nlvp 9001
  • A listening socket accepts anything, including other people's traffic. Bind to loopback or a lab interface, and close it when the test ends.

Notes

  • Some builds use `-l -p 9001`; `-v` and `-k` (keep listening) also differ between variants.

04Transfer a file between two lab hosts

bash

The classic single-stream copy: no daemon, no scp dependency, useful on minimal images.

nc -l 9000 > received.bin

Example

sender: cat payload.bin | nc 192.0.2.20 9000

  • There is no authentication and no encryption. Only use it on an isolated network, and prefer scp or rsync over SSH anywhere real data moves.

05Relay traffic through a jump host

bash

Forwards a local port so a tool that only speaks to localhost can reach a lab service.

nc -L -p 8080 -r 192.0.2.10:80

Notes

  • `-L` (listen and forward once) and `-l -w0 -F` patterns are build-specific; Ncat's `-k` gives a repeating relay.

What it is used for

  • Firewall rule verification

    Confirm a specific port is reachable from a specific source.

  • Client behaviour inspection

    See exactly what a device sends when it connects.

  • Minimal-container debugging

    Move a small file when no package manager is available.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"Error: Permission denied" when bindingCause 1/2

Possible causes

  • Port below 1024 requires elevated privileges.

Usual fix

Use a high port (1024+) or run with sudo on a lab machine.

Flag combinations work on your laptop but not on the serverCause 2/2

Possible causes

  • Different netcat variants (OpenBSD vs GNU vs traditional vs Ncat).

Usual fix

Check `nc -h` and `readlink -f $(which nc)`; write scripts against one named binary (for example `ncat`) instead of `nc`.

Tips

  • Add `-q 1` (OpenBSD) or `-N` (traditional) so the connection closes cleanly when input ends — otherwise scripts hang.
  • For anything carrying credentials or personal data, use SSH-based transfer instead.

Alternatives & comparisons

Not documented yet: socat, ncat, openssl s_client. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking