Netcat – All you need to know
blog.ikuamike.io
blog.ikuamike.io
I still don't understand why such a device/file is not shipped with Unix/Linux by default so it would work with any shell or program.
Bash handles several filenames specially when they are used in redirections, as described in the following table. If the operating system on which bash is running provides these spe‐
cial files, bash will use them; otherwise it will emulate them internally with the behavior described below.
/dev/fd/fd
If fd is a valid integer, file descriptor fd is duplicated.
/dev/stdin
File descriptor 0 is duplicated.
/dev/stdout
File descriptor 1 is duplicated.
/dev/stderr
File descriptor 2 is duplicated.
/dev/tcp/host/port
If host is a valid hostname or Internet address, and port is an integer port number or service name, bash attempts to open the corresponding TCP socket.
/dev/udp/host/port
If host is a valid hostname or Internet address, and port is an integer port number or service name, bash attempts to open the corresponding UDP socket.Are there circumstances where /dev/tcp/host/port might be provided by the operating system and provide the same functionality? Or is that just saying bash will stay out of the way if you are trying to access special files in /dev if they really exist?
Nothing besides bash can see these. They're not really there. It's a mirage created by bash.
uh, what? the original netcat was a Unix program, not linux specefic. I don't think GNU netcat is linux specific either. And the OpenBSD variant, as its name suggests was originally written for OpenBSD, although it was ported to Linux later.
The busybox netcat doesn't set off all the malware alarms on my corporate desktop.
C:\Temp>\bin\busybox64 nc 1.2.3.4 21
220 (vsFTPd 2.0.5)
quit
221 Goodbye.
The Windows port is not very smart compared to the rest of the netcat family (the Linux x86-64 version has more of the common options). C:\Temp>\bin\busybox64 nc
BusyBox v1.32.0-FRP-3445-g10e14d5eb (2020-04-11 10:50:47 BST) multi-call binary
Usage: nc [-l] [-p PORT] [IPADDR PORT]
Open a pipe to IP:PORT
-l Listen mode, for inbound connects
-p PORT Local portOlder makefiles had targets for Ultrix, Nextstep, and even Unixware :)
For younger devs, it's all Linux (vs Windows/MacOS/etc).
UNIX and its variants is some distant history, like Multics or VMS was to 90s devs. Even FreeBSD is some niche thing they'll seldom, if ever, encounter (much less install).
Heck, 20-something year old devs still hadn't reach puberty when SUN still mattered and was a thing.
I don't mean younger devs don't use Macs.
But for younger devs it's Linux that comes to mind when the context is UNIX-like environment, not the Mac (even though the first is not a UNIX, as it doesn't come from the old UNIX code lineage, and the latter is a certified UNIX).
So, they could easily slip and say "netcat or vi was written originally for Linux" (while meaning "for UNIX") versus saying "netcat or vi was written originally for macOS" (which nobody would ever slip and say).
Get it here: https://github.com/xero/figlet-fonts
I wonder what feature this was? The site doesn't elaborate.
Edit: Ah I saw the thing about the -e later on but I didn't think that was it as indeed it's not really a security hole imo. Rather just a tool.
The feature is the -e option, which is used (among other things) for reverse shells.
busybox, a great program, but something about it's netcat will hang at the end of sending data, rather than closing the socket and exiting. Because of that I have to ^C it, and then wonder if it fully sent the last block of data.
For decades now I've used minimal rescue environments and "netcat" to copy data around. A lot of these rescue environments, especially 20 years ago, were pretty minimal. I liked being able to use the RedHat or Fedora install media as rescue, because I always had it handy.
So I fell back to this habit of, I know Python is on this system (RedHat installer), so I made a few versions of a python "netcat" program. A bigger one with more features, in case I was able to "wget" a file. Or smaller "in" and "out" programs that I could comfortably type in by hand.
But I really need to get into the habit of using socat now. I had it in mind that it's hard to remember how to use, so I'd just wget my python version and be done with it. But I need to get in the habit. socat is SO powerful.
Beware, Ubuntu 20.04 has version with a bug in TLS-based "file copy" socat usage. https://bugs.launchpad.net/ubuntu/+source/socat/+bug/1936407
Simple fix is to just "dpkg -i" the 18.04 or 21.04 .deb file, there don't seem to be any strange dependencies.
https://github.com/vi/websocat
Such a useful tool when the need arises, lifesaver.
I mean, netcat as a tool still isn't as known as it deserves to be (at least in the circles I frequent), but socat deserves it even more. Along with a few other unix-y tools (sponge, for example), I really cannot understand why it isn't pre-installed everywhere.
http://web.archive.org/web/20180304190350/https://debian-adm...